The Outlook.es Dump: 2,666 Stolen Login Credentials Surface
HEROIC analysts found a combolist tied to outlook.es circulating on a Telegram channel in June 2026. The file contained 2,666 records pairing email addresses with plaintext passwords and the URLs each credential was used on. Why this is dangerous: because the passwords in this file are stored in plaintext, anyone who obtains it can attempt to log in right away, without needing to crack or decrypt anything. That makes the data immediately usable by anyone who gets a copy of it. What was exposed: email addresses, plaintext passwords, and associated URLs indicating where each credential was originally used. Why this matters: email accounts like these are often used to reset passwords for other services, so a compromised account can open the door to a person's other accounts. If any of these 2,666 people reused their password elsewhere, attackers can use the same credentials for credential stuffing attacks, which can lead to account takeover and identity theft. How combolists like this one work: a combolist bundles usernames or email addresses with passwords, typically gathered from earlier breaches, malware infections, or manual scraping, then labeled by source and shared or sold on Telegram channels and dark web forums. Because the credentials are already matched and organized, combolists let attackers automate large batches of login attempts across many services at once. Check if you are affected: if you use an outlook.es email account, it's worth checking whether your information appears in this leak. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records so you can quickly find out and take action if needed.
Breach Breakdown
2,666 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds