Breach Intelligence Report 15 Jul 2026

Someone Has Your Office 365 Password: 142 SMTP Logins Leaked

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs RDHQ_Office365_SMTPs uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 142
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts flagged a stealer log labeled "RDHQ_Office365_SMTPs" that was uploaded to a Telegram channel on June 4, 2026. The file exposes 142 records consisting of email addresses, plaintext passwords, and URLs tied to Microsoft Office 365 SMTP authentication. These are not ordinary user credentials — they are specifically SMTP login details, which grant the ability to send email through compromised Office 365 accounts.

The presence of SMTP credentials in this dump elevates the threat significantly. An attacker with valid SMTP authentication can send emails that appear to originate from the victim's legitimate business address, making phishing campaigns, business email compromise schemes, and invoice fraud dramatically more convincing. The 142 accounts in this leak are primed for abuse the moment the file is accessed.


Why Plaintext SMTP Passwords Create an Urgent Business Threat

Every password in this stealer log is stored in plaintext, meaning attackers can authenticate to Office 365 SMTP servers immediately. There is no hashing to reverse, no encryption to break. The credentials work as-is, and SMTP access can often be exploited without triggering the multi-factor authentication prompts that protect web-based logins.

This gap in protection makes SMTP credentials particularly prized among threat actors. While an organization may have robust MFA on its Outlook Web Access, the SMTP protocol often relies solely on username and password authentication. A single compromised SMTP credential can enable an attacker to send thousands of phishing emails from a trusted corporate domain before the breach is detected.


What Was Exposed in the RDHQ Office 365 Dump

  • Email Addresses — Office 365 email addresses, typically tied to business domains, that identify both the victim and their organization, enabling targeted attacks against colleagues, clients, and vendors.
  • Plaintext Passwords — Unencrypted SMTP authentication credentials extracted by infostealer malware, providing direct access to send email as the victim without any decryption or technical expertise required.
  • URLs — SMTP server endpoints and authentication URLs associated with Office 365, confirming the exact service infrastructure these credentials unlock.

Why 142 Corporate Email Accounts Represent Outsized Risk

In the context of business email compromise, even a handful of legitimate corporate email accounts can generate millions of dollars in fraudulent transactions. Attackers use compromised email accounts to impersonate executives, redirect wire transfers, send fake invoices, and trick employees into revealing additional credentials. The FBI reported that business email compromise caused over $2.9 billion in losses in a single year.

Each of the 142 accounts in this dump is a potential launchpad for such attacks. Because these are Office 365 accounts, they carry the sender reputation of established business domains. Emails sent through these accounts will pass SPF, DKIM, and DMARC authentication checks, landing in recipients' inboxes rather than spam folders. This technical legitimacy makes the fraud far harder to detect.


How Stealer Logs Capture Corporate Email Credentials

The credentials in this dataset were harvested by infostealer malware running on the victims' devices. These infections commonly occur when employees download trojanized software, open malicious email attachments, or visit compromised websites. The malware then scans the device for stored credentials, including email client configurations that contain SMTP server settings and passwords.

Unlike attacks that target an organization's email server, infostealer infections happen at the individual endpoint level. This means the victim's IT department may have no visibility into the compromise until the credentials appear in a stealer log on Telegram. The RDHQ dataset represents exactly this scenario — SMTP credentials silently extracted from infected workstations and packaged for distribution to threat actors worldwide.


Check If Your Office 365 Credentials Were Exposed

If your organization uses Microsoft Office 365, verify whether any of your accounts appear in this leak. HEROIC provides a free breach scanner that searches more than 400 billion compromised records, including SMTP credential datasets like the RDHQ Office 365 dump.

Search your business email address to check your exposure. If your credentials are found, change your Office 365 password immediately, ensure MFA is enforced on all authentication protocols including SMTP, review your email sending logs for unauthorized activity, alert your IT security team, and scan affected devices for active malware infections.

Breach Breakdown

Domain RDHQ_Office365_SMTPs uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 15 Jul 2026
Check in 5 seconds

142 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,254 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $1.0K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance