MrAwexx Hotmail Leak: 693 Accounts Are Ready to Steal
HEROIC flagged a second stealer log file from the threat actor "MrAwexx" appearing on Telegram in December 2025. This batch contains 693 validated Hotmail credentials, representing another wave of pre-verified account data from the same operator. The repeated releases from MrAwexx indicate an ongoing operation that continuously harvests and validates stolen Hotmail credentials for distribution.
Pre-Verified Plaintext Passwords Demand Urgent Action
Each of the 693 passwords in this dataset has been stored in plaintext and individually tested to confirm it grants access to the associated Hotmail account. This pre-verification eliminates the uncertainty that typically exists in raw stealer log dumps. Every entry in this file is a live, working credential at the time of release. For the 693 affected users, the threat is not theoretical. Their accounts can be accessed right now by anyone who obtains this file.
What Was Exposed
- Email Addresses — active Hotmail accounts that have been confirmed accessible by the threat actor
- Plaintext Passwords — verified working credentials with no encryption or hashing
- URLs — the websites and services where each credential pair was originally stolen
693 Verified Credentials Are a Direct Path to Account Takeover
Pre-validated credential lists eliminate the most time-consuming step in credential stuffing attacks. Instead of testing thousands of potentially expired passwords, attackers using this MrAwexx dump know every entry works. They will target Microsoft services first, including Outlook email, OneDrive cloud storage, and Microsoft 365 subscriptions. From there, they pivot to any third-party account linked to the victim's Hotmail address, resetting passwords through email recovery flows to gain access to banking, shopping, and social media accounts.
An Ongoing Stealer Operation Feeding Repeated Leaks
This is not an isolated incident. MrAwexx operates what appears to be a sustained credential harvesting pipeline. Infostealer malware deployed through phishing campaigns and malicious downloads continuously feeds new credentials into the system. The operator filters the raw data for Hotmail accounts, validates them against Microsoft's authentication systems, and releases verified batches on a regular cadence. Each release represents fresh victims whose devices were recently compromised, meaning the affected accounts are likely still using the stolen passwords.
Check If Your Credentials Were Exposed
With over 400 billion records indexed from breaches, stealer logs, and dark web sources, HEROIC's breach intelligence database provides thorough coverage of credential exposures worldwide. Use the HEROIC breach scanner to check whether your Hotmail account appears in this MrAwexx batch or any other known compromise. Given the validated nature of these credentials, changing your password immediately upon finding a match is essential to preventing account takeover.
Breach Breakdown
693 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds