One Hotmail Password Could Unlock a Chain of Accounts
HEROIC detected a stealer log titled "Hotmail TXTVALID" on Telegram that contains 149 verified, compromised Hotmail account credentials. The "TXTVALID" designation indicates these credentials have been tested and confirmed as working, making them even more dangerous than unverified dumps. Each record includes a plaintext password, an email address, and the URL where the credential was captured.
Verified Plaintext Passwords: Maximum Risk
Not only are these 149 passwords stored in plaintext—readable and unencrypted—but they have been validated as active. This means attackers do not need to guess which credentials still work. Every entry in this dump has been confirmed functional, eliminating the trial-and-error phase that typically slows down account takeover campaigns.
What Was Exposed
- Email Addresses – Hotmail/Outlook accounts that often serve as Microsoft ecosystem gateways
- Plaintext Passwords – Verified, working credentials in fully readable form
- URLs – Login endpoints confirming the targeted service
A Hotmail Password Is More Than Just Email Access
Hotmail accounts are linked to the broader Microsoft ecosystem—OneDrive, Outlook, Xbox, Skype, and potentially Microsoft 365 business subscriptions. A single compromised Hotmail password can give attackers access to cloud files, stored documents, contacts, and calendar data. If the same password is used on non-Microsoft services, credential stuffing extends the breach even further.
How Validated Credential Dumps Are Created
TXTVALID collections are curated from larger stealer log datasets. After infostealer malware like Redline or Lumma harvests credentials from infected devices, criminals run automated checkers against live login endpoints to verify which credentials still work. The verified subset is then repackaged and distributed as a premium product on Telegram channels, commanding higher value because every entry is confirmed exploitable.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner covers more than 400 billion compromised records. If you use a Hotmail or Outlook email address, search it now to determine whether your credentials were included in this TXTVALID dump or any other known breach. Change your Microsoft password immediately if affected, enable multi-factor authentication, and review your account's recent activity for unauthorized access.
Breach Breakdown
149 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds