If You Reuse Passwords, the Outlook 28.09 Leak Should Worry You
HEROIC analysts identified a stealer log collection labeled "Outlook 28.09" that was distributed through a Telegram channel in May 2023. The dataset targets email account credentials and contains 7,593 compromised records, each consisting of email addresses, plaintext passwords, and the URLs of services where these credentials were stored. The name suggests the data was harvested with a focus on Microsoft Outlook users.
Why Plaintext Email Passwords Are Uniquely Dangerous
The credentials in the Outlook 28.09 dump are stored in plaintext, meaning they are fully readable without any decryption or cracking. For email accounts specifically, this represents an elevated threat. An attacker who gains access to your email account holds the master key to your entire digital identity — password reset links, two-factor codes, financial statements, and private correspondence all flow through email.
Unlike a compromised social media account, a breached email account allows attackers to silently intercept password reset confirmations for other services. They can take over banking, shopping, and cloud storage accounts without the victim receiving any notification, because the notifications themselves are being captured.
What Was Exposed in the Outlook 28.09 Dump
- Email Addresses — Microsoft Outlook and other email addresses that serve as both login identifiers and communication channels, making them dual-purpose targets for account takeover and phishing.
- Plaintext Passwords — Unencrypted passwords captured from infected devices, ready for immediate use without any cracking or processing required.
- URLs — The login pages and web services where these credentials were saved, revealing the full scope of each victim's online activity.
Why 7,593 Exposed Email Credentials Have Outsized Impact
While 7,593 records may seem modest compared to larger dumps, email credentials carry disproportionate value. Each compromised email account can serve as a launchpad for accessing dozens of connected services. Attackers routinely use a single breached email login to initiate password resets across banking platforms, e-commerce accounts, cloud storage services, and corporate systems.
Password reuse compounds the problem dramatically. Security surveys consistently find that more than half of users maintain identical passwords across multiple platforms. For the 7,593 individuals in this dump, the exposure likely extends far beyond their email accounts to every service where they used the same credentials.
How Stealer Logs Target Email Credentials
Infostealer malware is designed to extract every saved credential from an infected device, but email accounts are among the highest-value targets. Malware like RedLine and Raccoon Stealer scans browsers, email clients, and password managers for stored login data. When a victim has their Outlook credentials saved in a browser or desktop application, the malware captures them instantly.
After collection, these credentials are packaged into structured log files and uploaded to Telegram channels or underground marketplaces. Collections like Outlook 28.09 are often organized by service type, making it easy for attackers to locate and exploit specific kinds of accounts. The "28.09" likely references a harvest date, suggesting this batch was collected and distributed as a time-stamped package of fresh credentials.
Check If Your Credentials Were Exposed
If you use Microsoft Outlook or any email service and have ever saved your password in a browser or application, your credentials could appear in this or related stealer log collections. Email accounts deserve the highest priority for security because they control access to nearly everything else.
Use HEROIC's free breach scanner to check whether your email or passwords appear in the Outlook 28.09 dump or across our database of 400B+ compromised records. If you find a match, change your email password immediately, enable two-factor authentication, and review your account for any unauthorized access or forwarding rules.
Breach Breakdown
7,593 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds