Inside the Smtp.Office365 Combolist: How 73,967 Logins Got Compiled
On 04-Aug-2026, HEROIC analysts identified a combolist titled Smtp.Office365 shared on Telegram. The file contains 73,967 email and plaintext password pairs tied to Office 365 SMTP mail logins, along with the URLs for each account.
Why This Is Dangerous
SMTP credentials control the ability to send email through an account, which means an attacker with a valid pair from this list can send messages, including phishing emails, that appear to come from a real, trusted mailbox. Combined with the plaintext password, an attacker can also log into the underlying account directly.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs and server details for each affected login
Why This Matters
A leak of nearly 74,000 Office 365 SMTP credentials is significant because email accounts are the gateway to almost everything else online. If your email and password are among these records, an attacker could read your mail, reset passwords on other accounts tied to that inbox, or use your account to send convincing phishing messages to your contacts.
How Combolists Work
A combolist is built by gathering email and password pairs from older breaches and stealer logs, then filtering them down to a specific target, in this case Office 365 SMTP accounts. Criminals test each pair with automated checker tools to confirm the login still works before packaging the validated list for sale or trade on Telegram.
Check If You Are Affected
If you use an Office 365 email account, check your exposure now. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this combolist, so you can confirm whether you're affected and secure your inbox.
Breach Breakdown
73,967 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds