A hotmail address I don't even have access to has been hacked and was found on the dark web.

Shelia Hendrex 0 Reputation points
2026-06-10T01:24:07.4266667+00:00

I, too, was locked out of my hotmail a couple years ago because I did not pay for the additional Cloud they said I needed. I have since lost even viewing new emails that I was unable to even open or read.

Now my Security Program just informed me this old hotmail showed up on the dark web connected to Credential Complilation 113 and they show a password. I have never had any affiliation with this site. How can I delete that hotmail completely, or should I not worry about it?

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Alice-N 11,915 Reputation points Microsoft External Staff Moderator
    2026-06-24T06:53:59.6766667+00:00

    Please note that this is a user-to-user community. As moderators, I have limited access to internal development details. My role is to direct users to the appropriate support channels and resources. While I cannot provide backend analysis, I will do my best to assist you within my responsibilities.


    Hi

    I understand why that would be concerning, especially since you no longer have access to that old Hotmail account.

    One important point is that a “dark web” alert usually means the email address and/or an old password appeared in a leaked credential list. It does not always mean someone currently has access to the mailbox, but it should still be treated seriously.

    Since you cannot sign in to the account, you generally cannot delete or close it yourself, because closing a Microsoft/Outlook.com account requires signing in first. Microsoft support also cannot simply give access to an account or change its security information unless account ownership can be verified.

    Additional to the given solutions by AI answer, you can also try these:

    • Try the Microsoft account recovery form one more time using as much old account information as possible.
    • If recovery is not possible, focus on protecting your current accounts such as: Changing the password anywhere you may have reused the same or similar password. Turn on two-step verification for your current email, banking, shopping, and social accounts and also watch for phishing emails that mention the old Hotmail address.
    • If that old account has been inactive for a long time, it may eventually be closed under Microsoft’s inactivity rules, but there is no forum-side method to manually delete it without access.

    You do not need to panic, but you should treat the exposed password as unsafe and make sure it is not being used anywhere else. The most important protection is securing your active accounts, since information already included in a credential compilation cannot usually be removed from third-party dark web lists.

    I hope this helps. Thank you for your understanding and time!

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-10T01:24:30.2233333+00:00

    If the Hotmail (Outlook.com) address is no longer accessible and may be compromised, treat it as a hacked Microsoft account and focus on limiting risk rather than trying to delete data already exposed on the dark web.

    1. Try to recover or close the account
    • Use the hacked/compromised account guidance to attempt recovery: see How to recover a hacked or compromised Microsoft account and the Sign-in Helper at Start.
    • If access is regained, immediately:
      • Change the password to a strong, unique one.
      • Review and remove any unknown security info (alternate email, phone) and add trusted ones.
      • Consider closing the Outlook.com/Microsoft account if it is no longer needed, using the guidance in How to close your Microsoft account and Close your Outlook.com account.
    1. If recovery fails
    1. Protect other accounts and data
    • Assume the exposed password is compromised:
      • Immediately change passwords on any other sites where the same or similar password was used.
      • Enable two-step verification (2FA) wherever possible.
    • Check recent activity and security info on any still-accessible Microsoft accounts via the Advanced security options page and recent activity page at https://account.live.com/activity.
    • Add alternate email and phone security info so recovery is easier in the future.
    1. Ongoing monitoring
    • Watch for phishing emails or messages referencing the old Hotmail address.
    • Inform contacts (if relevant) that the old address was compromised so they treat any messages from it as suspicious.

    Even if the Hotmail address is deleted or closed now, credentials already copied into a “credential compilation” on the dark web cannot be removed from those third-party lists. The key mitigation is to ensure that password is not usable anywhere and that current accounts are secured with updated passwords and 2FA.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.