How This Stealer Log Led to 67,428 Stolen Logins: 72 000 SMTP
HEROIC analysts identified this stealer log on 22-Aug-2025. The breach exposed 67,428 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as 72 000 SMTP uploaded by a Telegram User.
Why This Is Dangerous
This breach specifically targets SMTP email server credentials. SMTP is the protocol used to send email, so stolen SMTP credentials allow attackers to send email directly from a victim's account. This can be used to run phishing campaigns, send spam, or impersonate the victim in communications with banks, employers, and family members.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
When SMTP credentials are stolen, attackers gain the ability to send email as you. They can use your account to trick your contacts, bypass spam filters, and conduct fraud. The plaintext passwords also mean these credentials can be tested against other services where you may reuse the same password, leading to wider account compromise, identity theft, and financial fraud.
How Stealer Logs Work
Stealer logs are produced by infostealer malware that infects a victim's computer through phishing emails, fake software downloads, or compromised websites. Once installed, the malware captures email account settings, saved browser passwords, and login credentials in real time. All of this data is packaged into a log file and shared by criminals through private Telegram channels and dark web forums.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to find out if your credentials appear in this breach or others. Free, takes seconds.
Breach Breakdown
67,428 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds