Live.com Webmail Accounts Exposed in the mxlogsfox Leak: 38,609 Logins
HEROIC analysts identified a combolist file named live.com.mxlogsfox uploaded to a Telegram channel, first leaked on 28 August 2025. The file targets webmail accounts and contains 38,609 records made up of email addresses, plaintext passwords, and the URLs where each login was captured. Why This Is Dangerous: A webmail inbox is often the master key to a person's entire online life, password reset links, account notifications, and personal correspondence all pass through it. Because the passwords in this file are stored in plaintext, anyone holding the file can log into an affected inbox immediately and use it to reset passwords on other services. What Was Exposed: - Email addresses linked to live.com and related webmail accounts - Plaintext passwords - URLs showing where each credential pair was captured Why This Matters: Webmail accounts are a favorite target because compromising one often unlocks many others through password reset emails. Once an attacker controls an inbox from this list, they can attempt credential stuffing against banking, shopping, and social media accounts, or use the mailbox itself to launch phishing attacks against the victim's contacts. How a Telegram Combolist Like This Works: Combolists focused on a single webmail provider, like this mxlogsfox file, are typically assembled from phishing pages or stealer malware that specifically harvests webmail logins, then bundled and shared in Telegram channels dedicated to trading stolen credentials. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this live.com combolist. Scan now to confirm whether your webmail credentials are exposed, and change your password if they are.
Breach Breakdown
38,609 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds