The X597 Hotmail Leak: 597 Passwords Exposed. Yours Might Be One.
In June 2026, HEROIC analysts identified a combolist named "X597 HOTMAIL" uploaded to Telegram. The file contained 597 records pairing Hotmail email addresses with plaintext passwords and the URLs those credentials were used on.
Why This Is Dangerous
This is a small, focused file, and that makes it easier for an attacker to work through methodically. Because the passwords are already plaintext and matched to a URL, there is nothing to crack. Anyone with the file can start testing logins right away.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs
Why This Matters
A Hotmail account is often the recovery email for other accounts, including banking, shopping, and social media. If your credentials are among the 597 in this file and you have reused that password elsewhere, an attacker who gets into your Hotmail account can use it to reset passwords on other services, opening the door to account takeover, financial fraud, or identity theft.
How This Combolist Was Built
A combolist like "X597 HOTMAIL" is typically built by filtering a larger pool of stolen credentials down to accounts tied to one email provider, in this case Hotmail. Sorting credentials this way makes them easier to sell and test quickly. Files like this are commonly traded on Telegram channels focused on stolen account data.
Check If You Are Affected
With 597 records in this combolist, it only takes a moment to check whether you were included. HEROIC's free breach scanner searches your email against a database of more than 400 billion leaked records, including this one, and tells you in seconds if you were affected. If you find a match, change that password right away and anywhere else you have reused it.
Breach Breakdown
597 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds