The X2198 HQ Hotmail Dump Put 2,196 Logins on the Dark Web
HEROIC analysts identified a combolist labeled "X2198 HQ H0TMAIL" shared by a Telegram user in July 2026. The file contained 2,196 records pairing email addresses with plaintext passwords and the URLs each credential was used on, primarily tied to Hotmail accounts. Why this is dangerous: because the passwords are stored in plaintext, anyone who obtains this file can attempt to log in to the affected Hotmail accounts right away, with no cracking or decryption needed. This makes the data immediately usable by attackers of any skill level. What was exposed: email addresses, plaintext passwords, and associated URLs showing where each set of credentials was used. Why this matters: email accounts like these are often the gateway to a person's other online accounts, since they are commonly used to reset passwords elsewhere. If any of these 2,196 people reused their password on other sites, attackers could use the same credentials for credential stuffing attacks, leading to account takeover or identity theft across multiple services. How combolists like this one work: a combolist bundles usernames or email addresses with passwords, typically gathered from earlier breaches, malware infections, or manual scraping, then labeled with a name like "HQ H0TMAIL" to indicate its focus and shared or sold on Telegram channels and dark web forums. Because the credentials are already organized and ready to use, combolists let attackers automate large-scale login attempts quickly. Check if you are affected: if you use a Hotmail account, it's worth checking whether your email appears in this leak. HEROIC's free breach scanner checks against a database of more than 400 billion leaked records so you can quickly find out and take action if needed.
Breach Breakdown
2,196 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds