Inside the Vuln_SMTP Combolist: How 5,496 Logins Ended Up for Sale
HEROIC analysts identified a combolist called Vuln_SMTP that a Telegram user uploaded on July 15, 2026. The file contains 5,496 records, each pairing an email address with a plaintext password and the URL tied to that login. The name suggests these credentials were harvested by exploiting vulnerable or misconfigured SMTP mail servers, a common technique for building this kind of file. Why This Is Dangerous: Each of these 5,496 records is a complete, ready-to-use login. The attacker does not need to guess or crack anything, the email, its exact password, and the site it unlocks are already paired. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each credential pair Why This Matters: SMTP-linked credentials often provide access to email accounts, which attackers can then use to reset passwords on other services. With 5,496 login pairs circulating, the risk extends beyond the original mail accounts into credential stuffing against banking, shopping, and social media sites, and potential identity theft for anyone who reused a password. How a Vulnerable-SMTP Combolist Like This Works: Attackers scan for mail servers with weak security or exposed configurations, extract stored or intercepted login credentials, and compile them into a combolist organized by domain or URL. These files are then sold or shared cheaply on Telegram, where buyers run them through automated login tools to find working accounts. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this Vuln_SMTP leak. Run a free scan now to see if your credentials are part of it.
Breach Breakdown
5,496 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds