Someone Has Your Outlook Password: 780 Credentials Leaked
HEROIC discovered a targeted stealer log collection labeled Hotmail Microsoft Outlook being shared on Telegram in July 2026. This dump contains 780 compromised credential records specifically targeting Microsoft email services, including Hotmail and Outlook accounts. Because these credentials unlock access to the entire Microsoft ecosystem, the potential damage extends far beyond a single compromised inbox.
Plaintext Microsoft Passwords Are Especially Dangerous
Every password in this dump is stored in plaintext, giving attackers instant access to victims' Microsoft accounts. What makes this particularly alarming is that a single Microsoft credential often unlocks Outlook email, OneDrive storage, Office 365 applications, Teams, and any third-party service connected through Microsoft single sign-on. The plaintext format means there is no delay between obtaining the credential and accessing everything connected to it.
What Was Exposed
- Email Addresses — Hotmail and Outlook accounts that serve as gateways to the entire Microsoft ecosystem
- Plaintext Passwords — unencrypted Microsoft account credentials ready for immediate use
- URLs — Microsoft login endpoints and associated services confirming these are active Microsoft accounts
Microsoft Accounts Are High-Value Targets for Credential Stuffing
Compromised Microsoft credentials are among the most valuable in the criminal underground because they often serve as the recovery email for other services. Attackers who gain access to a victim's Outlook inbox can reset passwords for banking, social media, and shopping accounts linked to that email. Even 780 records can lead to cascading compromises across dozens of connected platforms for each affected individual.
How Infostealers Harvest Microsoft Credentials
The credentials in this collection were extracted by infostealer malware that targets browser-saved passwords and autofill data on infected devices. The malware silently captures Microsoft login credentials when users access Outlook, Hotmail, or other Microsoft services through their browsers. These stolen credentials are then compiled into targeted collections organized by service type and shared through Telegram, where they attract attackers specifically seeking Microsoft account access.
Check If Your Credentials Were Exposed
If you use Hotmail or Outlook, this dump may include your credentials. HEROIC's breach scanner indexes over 400 billion records and can check your email or password against this collection and thousands of other breaches. Search now and immediately enable two-factor authentication on your Microsoft account if your credentials appear in the results.
Breach Breakdown
780 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds