Someone Has Your Office 365 Password: 142 SMTP Logins Leaked
HEROIC analysts flagged a stealer log labeled "RDHQ_Office365_SMTPs" that was uploaded to a Telegram channel on June 4, 2026. The file exposes 142 records consisting of email addresses, plaintext passwords, and URLs tied to Microsoft Office 365 SMTP authentication. These are not ordinary user credentials — they are specifically SMTP login details, which grant the ability to send email through compromised Office 365 accounts.
The presence of SMTP credentials in this dump elevates the threat significantly. An attacker with valid SMTP authentication can send emails that appear to originate from the victim's legitimate business address, making phishing campaigns, business email compromise schemes, and invoice fraud dramatically more convincing. The 142 accounts in this leak are primed for abuse the moment the file is accessed.
Why Plaintext SMTP Passwords Create an Urgent Business Threat
Every password in this stealer log is stored in plaintext, meaning attackers can authenticate to Office 365 SMTP servers immediately. There is no hashing to reverse, no encryption to break. The credentials work as-is, and SMTP access can often be exploited without triggering the multi-factor authentication prompts that protect web-based logins.
This gap in protection makes SMTP credentials particularly prized among threat actors. While an organization may have robust MFA on its Outlook Web Access, the SMTP protocol often relies solely on username and password authentication. A single compromised SMTP credential can enable an attacker to send thousands of phishing emails from a trusted corporate domain before the breach is detected.
What Was Exposed in the RDHQ Office 365 Dump
- Email Addresses — Office 365 email addresses, typically tied to business domains, that identify both the victim and their organization, enabling targeted attacks against colleagues, clients, and vendors.
- Plaintext Passwords — Unencrypted SMTP authentication credentials extracted by infostealer malware, providing direct access to send email as the victim without any decryption or technical expertise required.
- URLs — SMTP server endpoints and authentication URLs associated with Office 365, confirming the exact service infrastructure these credentials unlock.
Why 142 Corporate Email Accounts Represent Outsized Risk
In the context of business email compromise, even a handful of legitimate corporate email accounts can generate millions of dollars in fraudulent transactions. Attackers use compromised email accounts to impersonate executives, redirect wire transfers, send fake invoices, and trick employees into revealing additional credentials. The FBI reported that business email compromise caused over $2.9 billion in losses in a single year.
Each of the 142 accounts in this dump is a potential launchpad for such attacks. Because these are Office 365 accounts, they carry the sender reputation of established business domains. Emails sent through these accounts will pass SPF, DKIM, and DMARC authentication checks, landing in recipients' inboxes rather than spam folders. This technical legitimacy makes the fraud far harder to detect.
How Stealer Logs Capture Corporate Email Credentials
The credentials in this dataset were harvested by infostealer malware running on the victims' devices. These infections commonly occur when employees download trojanized software, open malicious email attachments, or visit compromised websites. The malware then scans the device for stored credentials, including email client configurations that contain SMTP server settings and passwords.
Unlike attacks that target an organization's email server, infostealer infections happen at the individual endpoint level. This means the victim's IT department may have no visibility into the compromise until the credentials appear in a stealer log on Telegram. The RDHQ dataset represents exactly this scenario — SMTP credentials silently extracted from infected workstations and packaged for distribution to threat actors worldwide.
Check If Your Office 365 Credentials Were Exposed
If your organization uses Microsoft Office 365, verify whether any of your accounts appear in this leak. HEROIC provides a free breach scanner that searches more than 400 billion compromised records, including SMTP credential datasets like the RDHQ Office 365 dump.
Search your business email address to check your exposure. If your credentials are found, change your Office 365 password immediately, ensure MFA is enforced on all authentication protocols including SMTP, review your email sending logs for unauthorized activity, alert your IT security team, and scan affected devices for active malware infections.
Breach Breakdown
142 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds