Inside “Working SMTPs”: How a Combolist Exposed 6,768 Logins
HEROIC analysts found a combolist titled "8520_working_smtps" uploaded to Telegram on April 20, 2026. The name advertises 8,520 working SMTP logins, but the verified count is 6,768 records, each pairing an email address with a plaintext password and a login URL. Why This Is Dangerous: SMTP access lets someone send email through a legitimate account, which attackers use to send convincing phishing and spam messages that appear to come from a real, trusted address. Combined with plaintext passwords, this file gives attackers both the login and a way to abuse it. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each login Why This Matters: If your email credentials are in this file, an attacker could use your account to send fraudulent messages to your contacts, in addition to the standard risks of credential stuffing and account takeover if you've reused that password elsewhere. How a Combolist Like This Works: Files advertised as "working SMTPs" are typically built by testing stolen email credentials against mail servers to confirm they can still send messages, then packaging only the confirmed logins for buyers who want to send spam or phishing email through legitimate-looking accounts. Check If You Are Affected: Check your email against this leak and HEROIC's database of more than 400 billion exposed records using HEROIC's free breach scanner, and change your password immediately if it turns up, especially if you use that email to send or receive sensitive messages.
Breach Breakdown
6,768 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds