The Outlook.de AnonymousRichard Leak Quietly Exposed 4,930 Logins
In mid-June 2026, HEROIC threat intelligence analysts identified a stealer log file quietly uploaded to Telegram under the name "outlook.de AnonymousRichard," containing 4,930 records. The file targets Outlook.de accounts, the German version of Microsoft's email service, and was posted under an uploader handle rather than a company or product name. It includes email addresses, plaintext passwords, and the URLs of the login pages each credential belongs to.
Why a Quiet Upload Like This One Is Still a Serious Threat
Files like this rarely make headlines. They surface on Telegram, get downloaded by anyone paying attention, and circulate without ever being reported publicly. That quiet spread is exactly what makes them dangerous: the 4,930 people in this file may have no idea their Outlook.de login has been sitting in a stranger's hands since mid-June.
What Was Exposed in the Outlook.de AnonymousRichard File
- Email addresses
- Plaintext passwords
- URLs of the login pages tied to each credential
Why This Matters for Outlook.de Users
Because the passwords are stored in plain, readable text, an attacker can log into an affected Outlook.de account immediately. From there, they can reset passwords on other services linked to that inbox, leading to account takeover. If a password from this batch was reused elsewhere, the risk extends to credential stuffing across banking, shopping, or social media accounts, and ultimately to financial fraud or identity theft.
How Stealer Logs Circulate Quietly Under Uploader Handles
Infostealer malware harvests saved usernames, passwords, and login URLs from an infected device, and the person distributing the results often uploads the file under a personal handle rather than a public brand name. That makes the leak harder to trace and easier to overlook, since there's no company name attached to prompt a public warning. This 4,930-record batch, tied to Outlook.de and posted under the handle "AnonymousRichard," is a clear example of that low-profile distribution.
Check If Your Outlook.de Account Was Exposed
Because leaks like this one rarely come with a public announcement, checking your own exposure directly is the only reliable way to know. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, so you can confirm whether your email was included and change your password before someone else logs in first.
Breach Breakdown
4,930 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds