X983 HQ H0TMAIL Combolist Exposes 983 Stolen Logins Online
On 6 August 2026, a combolist titled "X983 HQ H0TMAIL" appeared on Telegram. HEROIC confirmed the file contains 983 records of email addresses, plaintext passwords, and associated URLs. The "HQ," or high quality, tag in the name is a label sellers use to market credentials they claim are more reliable than average.
Why This Is Dangerous
Labeling a combolist "HQ" is a sales pitch aimed at other criminals, it signals the credentials are believed to still work and are worth paying for. Combined with plaintext passwords, that means the 983 accounts in this file are more likely to be actively exploited than a random, unverified dump.
What Was Exposed
The "X983 HQ H0TMAIL" combolist contains:
- Email addresses (Hotmail-associated)
- Plaintext passwords
- Associated URLs
Why This Matters
Hotmail and Outlook accounts often serve as the recovery email for banking, shopping, and social media logins. If an attacker uses one of these 983 credentials to get into a victim's inbox, they can reset passwords elsewhere and pivot into account takeover, financial fraud, or identity theft.
How This Combolist Was Built
Sellers build "HQ" combolists by filtering larger batches of stolen credentials down to the ones they've verified as valid, then relabeling the leftover file to appear more premium. The stylized spelling "H0TMAIL," swapping a zero for the letter O, is a common trick uploaders use to dodge simple keyword filters on Telegram and forums.
Check If You Are Affected
If you have a Hotmail or Outlook account, it's worth checking now rather than later. HEROIC's free breach scanner searches more than 400 billion leaked records, including this combolist, to tell you if your credentials have been exposed.
Breach Breakdown
983 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds