Dark Web Alert: ‘SMTP AnonymousRichard’ Log Leaks 71 Logins
On June 2, 2026, dark web monitoring picked up a stealer log labeled "SMTP AnonymousRichard" circulating on a Telegram channel. The file contains 71 records, each pairing an email address with a plaintext password and the URL it was used on, most tied to SMTP and email-sending services rather than a single company or brand.
Why This SMTP-Focused Leak Is Dangerous
The "SMTP" label on this log is a signal worth paying attention to. SMTP credentials control outgoing email, the servers that actually send mail on behalf of an account or business. A criminal holding 71 working SMTP logins and passwords does not just gain access to inboxes; they gain the ability to send convincing phishing emails, spam, or fraud attempts that look like they are coming from a legitimate, already-trusted source.
What Was Exposed in the AnonymousRichard Log
- Email addresses
- Plaintext passwords
- URLs tied to SMTP and mail-server endpoints
Why This Matters
Even at 71 records, SMTP credentials carry outsized risk. Attackers who buy or trade logs like this one can use working email-sending access to launch phishing campaigns, distribute malware, or impersonate the account owner's business. If any of these passwords were reused on other platforms, credential stuffing extends the damage into personal email, banking, or shopping accounts, opening the door to account takeover and identity theft.
How Dark Web Traders Package Logs Like This One
Threat actors monitoring dark web forums and Telegram channels routinely repackage raw stealer malware output into themed batches, grouping credentials by the type of service they unlock, in this case SMTP and mail-related URLs, and labeling the file with whatever name or handle the uploader chooses, such as "AnonymousRichard." These curated batches are more valuable to buyers than raw logs because they are pre-sorted for a specific kind of attack, like sending spam or phishing mail from compromised accounts.
Check If You Are Affected
If you manage any email or business accounts, it is worth checking whether your credentials have surfaced in a log like this. HEROIC's free breach scanner searches your email against more than 400 billion breached and leaked records, including dark web stealer logs, and tells you right away if you are exposed.
Breach Breakdown
71 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds