100k Hq Mail Access Base By Old_deep 02-03-2023... -
Typically shared as a "combo list" (email:password). Threat Analysis
In mail providers like Microsoft 365 , administrators can use MailItemsAccessed logs to see exactly which messages a threat actor viewed. Use MailItemsAccessed to investigate compromised accounts 100K HQ MAIL ACCESS BASE BY Old_Deep 02-03-2023...
Adding MFA is the most effective way to prevent unauthorized access even if the password is leaked. Typically shared as a "combo list" (email:password)
The subject line refers to a specific data leak posted on a cybercrime forum by a threat actor known as Old_Deep . This specific leak was distributed on February 3, 2023, and contains approximately 100,000 sets of compromised email credentials, designed for "mail access"—meaning the credentials allow direct login to the mailboxes themselves. Incident Overview Source: A cybercrime forum or "dark web" marketplace. Leak Name: 100K HQ MAIL ACCESS BASE. Threat Actor: Old_Deep. Release Date: February 3, 2023. The subject line refers to a specific data
Once inside a mailbox, attackers can use the "Forgot Password" feature on other services to intercept reset codes and take over secondary accounts.