Inside the X591 HOTMAIL Combolist: How 591 Passwords Got Collected
A combolist doesn't appear out of nowhere. X591 HOTMAIL, posted to Telegram in August 2026, is the result of someone gathering 591 Hotmail email and password pairs from various sources and packaging them into one file, passwords included in plain text. Understanding how a file like this gets built helps explain why scanning your email matters, so start there to check whether you're one of the 591.
Why the Building Process Makes This Dangerous
Every entry in this file has already been sorted and, in many cases, tested to confirm the password still works. That filtering step is what turns a random pile of old data into a genuinely usable attack list.
What Was Exposed
- Email addresses: mark the exact Hotmail account each password is tied to.
- Plaintext passwords: stored in readable form, ready to use without cracking.
- URLs: show precisely where each credential was collected from.
What Happens After the List Is Built
Once assembled, a combolist gets shared, resold, or run through automated tools that try each login on dozens of other websites, hoping the same password was reused somewhere with more value, like a bank or shopping account.
How Combolists Like X591 HOTMAIL Are Made
Builders typically combine leftover credentials from older leaks and stealer logs, filter them down to one email provider, and verify which ones are still active before releasing the finished file.
See if You're Part of the X591 HOTMAIL File
Scan your email to check. If your Hotmail address is listed, change its password right away and everywhere else you used the same one, from a device you trust. Treat a work Hotmail account with the same care as a personal one.
Breach Breakdown
591 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds