Reused a Password? The HOTMAIL Combolist Exposed 935 Logins
In July 2025, HEROIC analysts identified a combolist simply titled "HOTMAIL" uploaded to a Telegram channel. The file contains 935 records, each pairing a Hotmail email address with a plaintext password and a linked URL. Why This Is Dangerous Every password in this file is stored in plaintext, so no cracking or technical effort is required to use it. Because the list focuses exclusively on Hotmail accounts, a working password can give an attacker access not just to email, but to any other Microsoft service tied to that same login. What Was Exposed in the HOTMAIL File Email addresses (Hotmail) Plaintext passwords URLs linked to each login Why This Matters A Microsoft email account often doubles as a recovery method for other accounts, so a compromised Hotmail login can quickly cascade into access to banking, shopping, or social media accounts through password reset links. With 935 credentials in this file, attackers have enough volume to run a credential stuffing pass and expect at least some accounts to still be reachable. How Simple, Unlabeled Combolists Like This Get Made A file with a plain name like "HOTMAIL" typically means the uploader filtered a larger, mixed breach dump or stealer log collection down to just the addresses matching one email provider. It's a quick, low-effort way to package data for buyers who focus specifically on attacking Microsoft accounts. Check If You Are Affected If you use a Hotmail account, it's worth checking whether your login shows up in this leak. HEROIC's free breach scanner searches more than 400 billion leaked records and tells you instantly if your email address has been exposed, so you can update your password before someone else does.
Breach Breakdown
935 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds