United States Stealer Log Leaks Hotmail Fresh B4_Jx Emails, Passwords
In late March 2026, HEROIC analysts identified a stealer log dump, publicly labeled "Hotmail Fresh B4_Jx," that had been uploaded to a Telegram channel by an anonymous user. The file contained 154 individual records tied primarily to United States based accounts, including email addresses, plaintext passwords, and the URLs of the websites those credentials were used on.
Why This Is Dangerous
Unlike encrypted or hashed breach data, this dump stores passwords in plaintext, meaning anyone who obtains the file can read and use the credentials immediately without needing to crack anything. Because stealer logs pair a username or email with the exact site the password was used on, attackers can go straight to the matching login page and attempt to sign in, skipping the guesswork that slows down other kinds of attacks.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the associated login sites
Why This Matters
Because the passwords were stored in plaintext and matched to specific URLs, anyone affected faces a heightened risk of account takeover on the exact services listed in the log. If any of those 154 passwords were reused elsewhere, such as on email, banking, or social media accounts, attackers can attempt credential stuffing across those platforms too. Given that email addresses are involved, a successful login could also open the door to further identity theft, password resets on other services, or financial fraud.
How Stealer Logs Work
Stealer logs come from malware, often called an "infostealer," that quietly installs itself on a victim's computer, frequently through a pirated download, cracked software, or malicious attachment. Once running, the malware harvests saved usernames, passwords, and browsing URLs directly from the victim's web browser and any password managers on the device, then bundles everything into a single log file. These logs are routinely sold or given away for free on Telegram channels and dark web forums, exactly as happened in this case, giving criminals a ready-made list of working logins to test against other sites.
Check If You Are Affected
HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer log dumps like this one. Run a quick search to find out if your credentials were part of this leak or any other breach, and get guidance on securing your accounts before someone else uses your data.
Breach Breakdown
154 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds