Researchers Link the Login.live.com Leak to 5,800 Stolen Logins
Researchers Link a New Combolist to Login.live.com Accounts HEROIC analysts identified a combolist referencing "login.live.com," the Microsoft account sign-in domain, uploaded to Telegram on July 19, 2026. The file contains 5,800 records pairing email addresses with plaintext passwords and associated URLs. Why This Is Dangerous Microsoft accounts often connect to email, cloud storage, and Office documents, which means a single compromised login can expose far more than just an inbox. With passwords stored in plaintext, attackers can use these credentials immediately without needing to crack anything. What Was Exposed Email addressesPlaintext passwordsAssociated URLs Why This Matters Because Microsoft accounts are often linked to other services through single sign-on, a compromised login here can cascade into access to email, files, and connected apps. Anyone among the 5,800 affected accounts who reused their password elsewhere risks account takeover, financial fraud, or identity theft. How a Combolist Works A combolist gathers login pairs, an email or username combined with a password, from earlier breaches or malware infections and organizes them for reuse. Lists targeting a specific login portal, like login.live.com, are popular because attackers can point automated tools directly at one service instead of testing many sites at once. Check If You Are Affected If you use a Microsoft account or think your credentials might be part of this combolist, HEROIC's free breach scanner checks against more than 400 billion leaked records. Run a free scan and update your password if it appears.
Breach Breakdown
5,800 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds