What Is a Stealer Log? Inside the Hotmail AnonymousRichard Leak
In June 2026, HEROIC analysts identified a stealer log named "Hotmail AnonymousRichard" uploaded to a Telegram channel by a user sharing malware harvested credentials under that handle. The file contained 1,349 records, each combining a login URL, an email address, and a plaintext password tied to Hotmail accounts.
What a Stealer Log Actually Is
Unlike a typical corporate data breach, where hackers break into a company's servers, a stealer log comes from malware that infects individual computers one at a time. Once installed, it quietly copies whatever passwords the browser has saved and sends them back to whoever controls the malware. This "AnonymousRichard" file is the result of that process across 1,349 separate logins.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Associated Login URLs
Why This Matters
Because these passwords were saved and stolen in plaintext, they can be used immediately for credential stuffing and account takeover attempts, and anyone whose Hotmail password was reused on other sites faces a wider risk of identity theft or financial fraud.
How Stealer Logs Work
Information stealing malware typically arrives through a fake software crack, pirated download, or malicious email attachment. Once running, it scans the browser's saved password vault and autofill history, packages the results into a text file, and uploads it automatically to the attacker's server, where it is later sold or shared under a handle like "AnonymousRichard."
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one. Check your email address now to see if it appears among the 1,349 records exposed here.
Breach Breakdown
1,349 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds