One Combolist File. 1,485 Hotmail Logins. The HOTMAILS Telegram Leak.
HEROIC analysts identified a combolist simply titled "HOTMAILS," uploaded to Telegram in November 2024. The file contains 1,485 records pairing Hotmail email addresses with plaintext passwords, along with the URLs each credential set was used on. Why This Is Dangerous: despite its generic name, this file behaves like any other credential dump, readable passwords sitting next to the email address they belong to. Anyone who downloads it can start testing logins immediately, with no cracking or guessing needed. What Was Exposed: Hotmail email addresses, plaintext passwords, and URLs tied to each login. Why This Matters for These 1,485 Accounts: because Hotmail addresses are frequently used to sign up for other services, a compromised inbox from this leak can be used to request password resets across banking, shopping, and social media sites. Even a list this size is enough to fuel targeted credential stuffing attempts against every account tied to these emails. How Basic Combolists Like This Spread: simple, plainly named files like HOTMAILS are common on Telegram, where users upload smaller lists for free to build credibility before offering larger paid collections. These files are usually assembled from older breaches or phishing campaigns rather than freshly captured malware output, but the credentials can still be valid years later if the victim never changed their password. Check If You Are Affected: the only way to know if your Hotmail address is one of the 1,485 in this file is to check. HEROIC's free breach scanner searches a database of more than 400 billion leaked records so you can find out immediately and update your password if needed.
Breach Breakdown
1,485 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds