U.S. Hotmail Users Hit: 10,684 Deduplicated Passwords Exposed
HEROIC's threat intelligence systems detected a stealer log file titled "10770x Hotmail Removed Duplicates Sorted AZ" that surfaced in October 2025. This dump contains 10,684 records that have been specifically processed to remove duplicate entries and sorted alphabetically, creating a clean, deduplicated dataset of Hotmail credentials. Each record pairs an email address with a plaintext password and the URL where it was harvested, making this a professionally curated collection designed for maximum attack efficiency.
Plaintext Passwords in a Cleaned Dataset
The 10,684 passwords in this dump are in plaintext and have been deduplicated, meaning every entry is unique. Attackers do not need to waste time filtering out duplicate records — the processing has already been done for them. This level of data curation indicates a sophisticated operation that treats stolen credentials as a product, refining them for downstream consumers who want clean, actionable data.
What Was Exposed
- Email Addresses — unique Hotmail accounts, deduplicated and sorted for easy lookup
- Plaintext Passwords — unencrypted credentials with no duplicates to filter
- URLs — the websites and platforms where each credential was captured during active use
Deduplicated Data Is More Dangerous Than Raw Dumps
Raw stealer log dumps often contain many duplicates, which reduces their effective size. A deduplicated and sorted collection like this one means every single entry is a unique target. Attackers running credential stuffing operations get 10,684 distinct Hotmail email-password combinations to test against other services. The sorted format also enables efficient lookups, allowing threat actors to quickly search for specific domains or usernames within the dataset.
From Malware Infection to Sorted Credential File
This data started as raw output from infostealer malware infections across multiple devices. The malware extracted saved credentials from web browsers, captured active login sessions, and sent the data back to attacker-controlled servers. The raw logs were then processed through deduplication scripts that removed repeated entries, and the results were sorted alphabetically for distribution. This pipeline — from malware to processed, ready-to-use credential file — represents the industrialization of credential theft.
Check If Your Credentials Were Exposed
HEROIC has indexed over 400 billion records from data breaches, stealer logs, and dark web sources. Use HEROIC's breach scanner to search your Hotmail email address and determine if your credentials were included in this deduplicated collection or any other known compromise. If your account is found, change your password immediately and enable two-factor authentication to prevent unauthorized access.
Breach Breakdown
10,684 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds