Breach Intelligence Report 14 Jul 2026

Outlook.com Leak Means 20,156 Accounts Are Ready to Steal

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs outlook.com 22k 1 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 20,156
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts uncovered a stealer log file titled "Outlook.com 22K" distributed through a Telegram channel in May 2026. The dataset exposes 20,156 compromised records, each containing an Outlook.com email address paired with its plaintext password and the URL where the credential was harvested. The affected accounts are primarily associated with users in the United States.


Why Plaintext Outlook Passwords Are a Gateway to Everything

The passwords in this leak are stored in plaintext, meaning they can be used immediately without any decryption. Outlook.com accounts are particularly high-value targets because they integrate with Microsoft's entire ecosystem, including OneDrive, Office 365, Teams, and Skype. A single compromised Outlook password can grant access to an entire suite of productivity tools and stored files.

Because many users rely on their Outlook address as the recovery email for other accounts, a compromised Outlook password does not just expose one inbox. It provides a pathway to reset passwords on banking sites, social media platforms, and cloud services linked to that email address.


What Was Exposed in the Outlook.com 22K Dump

  • Email Addresses — Outlook.com accounts serving as both login and recovery identifiers
  • Plaintext Passwords — Completely unencrypted, exploitable without any tools
  • URLs — The exact websites and services where credentials were captured from browsers

Why 20,156 Exposed Credentials Represent a Serious Threat

With over 20,000 credential pairs available, attackers have a substantial dataset to weaponize through credential stuffing campaigns. Automated tools can cycle through every email-password combination against popular services like Amazon, PayPal, Netflix, and banking portals in a matter of hours.

The scale of this dump increases the likelihood that high-value accounts are included. Among 20,156 records, there are likely corporate email accounts, administrative credentials, and accounts tied to financial services. Each successful login gives attackers a foothold for further exploitation, from identity theft to business email compromise.

The bundled URLs add precision to these attacks. Instead of guessing where credentials might work, attackers can see exactly which services each victim used, allowing them to target the most valuable accounts first.


How Stealer Logs Strip Outlook Accounts of Their Security

This dataset originated from infostealer malware installed on victims' devices without their knowledge. These programs typically arrive as email attachments disguised as invoices, software activation tools, or game modifications. Once executed, they embed themselves in the operating system and begin extracting data.

The malware targets browser password stores with surgical precision, pulling saved credentials for email providers, e-commerce sites, and financial institutions. It also captures cookies and session tokens that can bypass two-factor authentication in some cases, making the stolen data even more dangerous than a simple username-password pair.

After extraction, the credentials are compiled into log files and transmitted to attacker-controlled servers. These logs are then sold in bulk on dark web marketplaces or shared freely on Telegram channels, where they spread rapidly across criminal networks.


Check If Your Outlook Credentials Were Exposed

If you use an Outlook.com email address for personal or professional purposes, your credentials could be part of this or similar stealer log distributions. HEROIC maintains a breach scanner that searches more than 400 billion compromised records to help you determine your exposure.

Use the HEROIC breach scanner to check whether your Outlook email appears in any known data leak. If it does, change your Microsoft account password immediately, enable multi-factor authentication through the Microsoft Authenticator app, and review your account's recent sign-in activity for any unauthorized access.

Breach Breakdown

Domain outlook.com 22k 1 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

20,156 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,702 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $145.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance