The HOTMAIL TEST Dump Put 3,718 Webmail Logins on the Dark Web
HEROIC analysts found a combolist called HOTMAIL TEST that a Telegram user uploaded on May 19, 2026. It contains 3,718 records, each one pairing an email address, largely tied to Hotmail and other webmail accounts, with a plaintext password and the URL that login was used on. Why This Is Dangerous: Webmail logins are often the master key to a person's digital life. Each of these 3,718 records hands an attacker a working email address, its exact plaintext password, and the site it opens, no guessing required. What Was Exposed: - Email addresses, largely Hotmail and other webmail accounts - Plaintext passwords - URLs tied to each credential pair Why This Matters: Webmail accounts are frequently used to reset passwords on banking, shopping, and social media accounts. If an attacker gains access to one of these 3,718 email accounts, they can often use it to take over other accounts entirely, making this kind of leak a stepping stone to broader identity theft and financial fraud. How This Combolist Was Built: A combolist compiles stolen or leaked email and password pairs, often gathered from older breaches, phishing campaigns, or malware infections targeting webmail users specifically. Files like HOTMAIL TEST are traded on Telegram because webmail credentials are especially valuable for unlocking other accounts downstream. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this HOTMAIL TEST leak. Run a free scan now to see if your webmail credentials are part of it.
Breach Breakdown
3,718 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds