What about an actual user fat-fingering their username but entering their password correctly? Would this publish that attempt publicly?
> No legitimate services are offered on the addresses receiving these attempts, so there is no chance of a real user accidently submitting their credentials.