U.S. Hotmail Users Hit: 73,851 Passwords Exposed in Leak
HEROIC discovered a stealer log file titled HOTMAIL 2 being distributed on Telegram targeting American Hotmail users. The dataset contains 73,851 compromised credential records, each consisting of an email address, a plaintext password, and the URL where the login was intercepted. This breach primarily affects users in the United States and represents a significant exposure of Microsoft email account credentials.
Plaintext Passwords: An Open Invitation for Attackers
None of the 73,851 passwords in this leak have any form of cryptographic protection. They appear exactly as the account holders typed them, stored in raw plaintext. This is the most dangerous form of password exposure because it removes every technical safeguard. Attackers who download this file gain immediate, no-effort access to try every credential against live login pages.
What Was Exposed
- Email Addresses — Hotmail and Microsoft-linked accounts predominantly belonging to U.S. users
- Plaintext Passwords — fully exposed credentials stored without any encryption or hashing
- URLs — the websites and portals where login credentials were captured by malware
Why Hotmail Accounts Are High-Value Targets
Hotmail accounts connect to the broader Microsoft ecosystem, including Outlook, OneDrive, Xbox, and Microsoft 365. Compromising a Hotmail password often means gaining access to cloud documents, personal photos, saved contacts, and linked subscriptions. Attackers also use compromised Hotmail accounts as launchpads for credential stuffing, testing the same password against banking sites, shopping platforms, and corporate tools where the victim may have reused it.
The Infostealer Origin of This Data
HOTMAIL 2 is a stealer log compiled from data harvested by infostealer malware. These malware variants infect computers through deceptive downloads, phishing campaigns, and trojanized browser extensions. Once running on a victim's machine, the malware scans browser databases for saved usernames and passwords, extracts session cookies, and collects autofill information. All of this data is packaged into log files and sent to attacker-controlled infrastructure for sorting and resale.
Check If Your Credentials Were Exposed
The complete HOTMAIL 2 dataset has been loaded into HEROIC's breach intelligence database, which spans over 400 billion compromised records. Use HEROIC's free breach scanner to determine if your Hotmail credentials appear in this leak or any other indexed breach. If you find a match, update your password immediately and activate two-factor authentication across all linked Microsoft services.
Breach Breakdown
73,851 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds