Inside the Outlook.es Logs: How Malware Harvested 420 Passwords
HEROIC Analysts Examine the Outlook.es Stealer Log
On December 6, 2024, HEROIC's threat intelligence team identified a stealer log labeled "outlook.es" uploaded to Telegram by an anonymous user. The file contained 420 records, each combining an email address, a plaintext password, and the URL of the login page the credentials belonged to, with a focus on Outlook and related webmail accounts.
Why a Webmail-Focused Log Like Outlook.es Is Dangerous
Email accounts are the master key to a person's online life. Anyone holding a working email password can reset the passwords on banking, shopping, and social media accounts linked to that inbox. Because this log specifically targets Outlook-style webmail credentials, an attacker working through it isn't just stealing an email login, they're potentially gaining a path into everything else tied to that address.
What Was Exposed in the Outlook.es Log
- Email addresses used as account logins
- Plaintext passwords tied to those addresses
- The website URLs the credentials were used to access
Why This Matters for the 420 People Affected
If any of the 420 people in this log reused their email password elsewhere, they face compounding risk: an attacker who reads their inbox can find password reset emails, personal details, and account activity across dozens of other services. This is exactly the kind of data that fuels account takeover and identity theft.
Inside the Outlook.es Logs: How Malware Harvested 420 Passwords
Stealer logs like this one come from infostealer malware, which infects a device through phishing emails, cracked software, or fake downloads, then scans the browser for saved logins and autofill data. Once collected, the stolen credentials are exported into a text file and shared or sold on Telegram, often grouped by the type of account they unlock, which is why this batch was labeled specifically around outlook.es webmail logins.
Check If You Are Affected
If you use Outlook, Hotmail, or any similar webmail service, it's worth checking whether your credentials appear in this or another stealer log. HEROIC's free breach scanner searches a database of more than 400 billion compromised records, so you can quickly see if your information has been exposed and change your password before someone else does.
Breach Breakdown
420 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds