U.S. Users Hit: Outlook 01.09 Exposes 11,586 Passwords
HEROIC's Dark Web monitoring identified a stealer log file titled "Outlook 01.09" that was shared in March 2023. The dump contains 11,586 records targeting Outlook email users, with each entry exposing an email address, a plaintext password, and the URL of the service where the credential was intercepted. This collection puts affected Outlook users at direct risk of account takeover and identity theft.
Plaintext Passwords: No Time to React
All 11,586 passwords in the Outlook 01.09 dump are stored in plaintext, giving attackers immediate, unrestricted access. There are no hashes to crack and no encryption layers to penetrate. The moment this file reaches a threat actor, every credential inside it becomes a working key to someone's account. For Outlook users, this is especially concerning since many rely on Outlook for both personal and professional email.
What Was Exposed
- Email Addresses — Outlook accounts that serve as primary identifiers for Microsoft services
- Plaintext Passwords — unencrypted passwords that work immediately without modification
- URLs — the specific services and platforms where these credentials were captured in use
Why Outlook Credential Leaks Are Especially Dangerous
An exposed Outlook password does not just compromise email. Microsoft accounts often connect to OneDrive, Office 365, Teams, and other enterprise services. Attackers who gain access through credential stuffing can read confidential emails, access shared documents, and impersonate the account owner. With 11,586 credential pairs to work with, automated attacks can test every combination across Microsoft and third-party services in a matter of minutes.
Infostealer Malware: The Source of This Leak
The Outlook 01.09 data was harvested by infostealer malware that infected victims' devices. These malicious programs silently extract credentials from browser password stores, email clients, and autofill databases. They also capture active login sessions and authentication tokens. The stolen data is then compiled into dated log files — the "01.09" likely refers to the collection date — and distributed through underground channels where they are purchased or freely shared.
Check If Your Credentials Were Exposed
With over 400 billion records in its breach intelligence database, HEROIC offers comprehensive coverage of known data leaks and stealer log collections. Enter your Outlook email address into HEROIC's breach scanner to check whether your credentials were included in the Outlook 01.09 dump or any other breach, and take immediate steps to change your password and enable two-factor authentication.
Breach Breakdown
11,586 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds