Breach Intelligence Report 14 Jul 2026

If You Reuse Passwords, the Outlook 28.09 Leak Should Worry You

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Outlook 28.09 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 7,593
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts identified a stealer log collection labeled "Outlook 28.09" that was distributed through a Telegram channel in May 2023. The dataset targets email account credentials and contains 7,593 compromised records, each consisting of email addresses, plaintext passwords, and the URLs of services where these credentials were stored. The name suggests the data was harvested with a focus on Microsoft Outlook users.


Why Plaintext Email Passwords Are Uniquely Dangerous

The credentials in the Outlook 28.09 dump are stored in plaintext, meaning they are fully readable without any decryption or cracking. For email accounts specifically, this represents an elevated threat. An attacker who gains access to your email account holds the master key to your entire digital identity — password reset links, two-factor codes, financial statements, and private correspondence all flow through email.

Unlike a compromised social media account, a breached email account allows attackers to silently intercept password reset confirmations for other services. They can take over banking, shopping, and cloud storage accounts without the victim receiving any notification, because the notifications themselves are being captured.


What Was Exposed in the Outlook 28.09 Dump

  • Email Addresses — Microsoft Outlook and other email addresses that serve as both login identifiers and communication channels, making them dual-purpose targets for account takeover and phishing.
  • Plaintext Passwords — Unencrypted passwords captured from infected devices, ready for immediate use without any cracking or processing required.
  • URLs — The login pages and web services where these credentials were saved, revealing the full scope of each victim's online activity.

Why 7,593 Exposed Email Credentials Have Outsized Impact

While 7,593 records may seem modest compared to larger dumps, email credentials carry disproportionate value. Each compromised email account can serve as a launchpad for accessing dozens of connected services. Attackers routinely use a single breached email login to initiate password resets across banking platforms, e-commerce accounts, cloud storage services, and corporate systems.

Password reuse compounds the problem dramatically. Security surveys consistently find that more than half of users maintain identical passwords across multiple platforms. For the 7,593 individuals in this dump, the exposure likely extends far beyond their email accounts to every service where they used the same credentials.


How Stealer Logs Target Email Credentials

Infostealer malware is designed to extract every saved credential from an infected device, but email accounts are among the highest-value targets. Malware like RedLine and Raccoon Stealer scans browsers, email clients, and password managers for stored login data. When a victim has their Outlook credentials saved in a browser or desktop application, the malware captures them instantly.

After collection, these credentials are packaged into structured log files and uploaded to Telegram channels or underground marketplaces. Collections like Outlook 28.09 are often organized by service type, making it easy for attackers to locate and exploit specific kinds of accounts. The "28.09" likely references a harvest date, suggesting this batch was collected and distributed as a time-stamped package of fresh credentials.


Check If Your Credentials Were Exposed

If you use Microsoft Outlook or any email service and have ever saved your password in a browser or application, your credentials could appear in this or related stealer log collections. Email accounts deserve the highest priority for security because they control access to nearly everything else.

Use HEROIC's free breach scanner to check whether your email or passwords appear in the Outlook 28.09 dump or across our database of 400B+ compromised records. If you find a match, change your email password immediately, enable two-factor authentication, and review your account for any unauthorized access or forwarding rules.

Breach Breakdown

Domain Outlook 28.09 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

7,593 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,702 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $54.9K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance