The Zoho_SMTPs Combolist Quietly Surfaced on the Dark Web
In February 2026, HEROIC analysts spotted a combolist named "Zoho_SMTPs" posted to Telegram by an individual user. The file holds 691 records combining email addresses with plaintext passwords and the URLs tied to each login, apparently focused on SMTP mail-sending accounts.
Why This Is Dangerous
SMTP credentials are used to send email through a mail server. In the wrong hands, a working SMTP login lets an attacker send messages that appear to come from a legitimate account, which is a favorite tool for phishing and spam campaigns. Because these 691 passwords are stored in plaintext, no cracking is needed before an attacker can start testing them.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs associated with each login
Why This Matters
Anyone whose email and password appear in this file faces two risks: their mail-sending account could be hijacked to send spam or phishing under their name, and if the same password was reused elsewhere, attackers can attempt credential stuffing against other accounts the person owns.
How a Combolist Like Zoho_SMTPs Gets Built
Combolists are assembled over time, not stolen in one event. Criminals gather login pairs from old breaches, stealer malware, and phishing kits, then filter and label them by theme, in this case SMTP-related logins, before sharing the finished file on Telegram for other threat actors to use.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including combolists like this one. Search your address for free, and change your password anywhere you have reused it.
Breach Breakdown
691 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds