Someone Has Your Password: 851 Hotmail Credentials Leaked
HEROIC's monitoring detected a stealer log file called "Hotmails 3" uploaded to Telegram in January 2025. This is the third installment in a series, indicating a persistent threat actor who is systematically collecting and releasing Hotmail credentials. The file contains 851 records, each pairing an email address with a plaintext password and the URL of the service where the login was captured. If your Hotmail account is among them, someone already has your password.
Plaintext Passwords Are Already in Someone's Hands
Every single password in Hotmails 3 is stored as readable, unencrypted text. There is no algorithm protecting these credentials, no mathematical puzzle an attacker must solve. The passwords are ready to use the instant the file is opened. For 851 Hotmail account holders, this means the question is not whether their password could be compromised — it already is. Someone has it, and they can log in at any time.
What Was Exposed
- Email Addresses — Hotmail and Outlook accounts that serve as keys to the broader Microsoft ecosystem
- Plaintext Passwords — stored in cleartext, requiring zero effort to exploit
- URLs — the specific websites and login portals where each credential was intercepted
Your Hotmail Inbox Is the Gateway to Everything
A compromised Hotmail account gives an attacker far more than access to your email. It gives them the ability to reset passwords on every service linked to that address — banking, social media, cloud storage, shopping, and workplace accounts. They can read password reset confirmation emails, intercept two-factor authentication codes, and systematically lock you out of your own digital identity. The 851 credentials in Hotmails 3 represent 851 gateways to this kind of total account takeover.
A Serial Threat Actor Behind the Hotmails Series
The "3" in the filename is not arbitrary. It indicates this is at least the third batch from the same source, meaning the threat actor behind the Hotmails series is running an ongoing operation. The underlying data comes from infostealer malware — programs like Lumma, RedLine, or Vidar that silently extract saved passwords from victims' browsers. This actor specifically filters for Hotmail and Outlook credentials, curates them into numbered batches, and distributes each new collection on Telegram to maximize reach among other cybercriminals.
Check If Your Credentials Were Exposed
Do not wait to find out the hard way that your password has been leaked. HEROIC's data breach scanner searches across more than 400 billion compromised records to determine if your Hotmail email or password appears in Hotmails 3 or any other known breach. A few seconds of checking can prevent weeks of recovering from identity theft, account lockouts, and financial fraud.
Breach Breakdown
851 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds