Hi
I hope you are well.
We have recently received a report of a brute force attempt using an email address on your server as a username at a “honeypot” server on the internet. I will be forwarding this to you shortly.
The report contains the first 5 letters of the SHA1 hash of the password that was used along with the email address as the username.
As we do not know your email password for this account we are not able to verify whether the real password has been compromised. You are able to check this on your side by checking the true password for the indicated email account and if the first 5 letters of the output SHA1 hash match that shown in the report, the account password should be considered compromised.
We have checked the server for signs of compromise on this email address and have not seen any unusual activity.
If you have any further questions or queries regarding this, please do let us know and we will attempt to clarify.
The original report will be forwarded to you after this email.
#signature
#cut