Why is Credential Exposure Now the Default Entry
Table of contents
There are 1.95 billion malware-sourced credentials currently indexed from criminal markets, and 276 million of them include an active session cookie that lets an attacker into an account without ever triggering multi-factor authentication, according to reported tracking.
That single number explains most of what follows in this piece: credential theft isn’t a side effect of attacks anymore, it’s the primary access method, and the data below shows exactly how that shift happened and what it costs.
Modern cybercrime operates less like a break-in and more like a simple sign-in. Threat intelligence databases currently index 1.95 billion compromised credentials—including 276 million active session cookies capable of bypassing multi-factor authentication on import. Fueled by infostealer malware that compromised over 16 million devices last year, 82% of modern security intrusions are now entirely malware-free, relying instead on valid access. In fact, 54% of ransomware victims had domain credentials exposed in stealer logs prior to being attacked, contributing to a 33% year-over-year surge in FBI-reported cybercrime losses, reaching $16.6 billion.
Why credentials replaced malware as the default entry point
Buying a working credential is now cheaper and more reliable than developing an exploit. A verified corporate password sells for $25 to $75 on markets like Russian Market and 2easy; a working VPN or identity-provider credential goes for $100 to $500, as covered in this blog’s breakdown of the infostealer economy. Lumma Stealer, currently one of the most prevalent infostealer families, runs a subscription model starting at $250 a month specifically to serve buyers who want a steady supply of fresh logs rather than a one-off purchase.
This is also the mechanism behind the Com-linked attacks covered in this blog’s piece on Discord’s recruitment pipeline: the social-engineering step (a convincing help-desk call) only works because the attacker already has enough real, specific detail, an employee name, a department, sometimes an active session, to sound legitimate. That detail comes from exactly this market.
Where the credentials actually come from
| Family | Notes | Source |
|---|---|---|
| Lumma Stealer | Currently one of the most prevalent families; disrupted by a multi-vendor takedown in May 2025; new logs continued appearing within weeks | Microsoft Digital Defense Report 2025; ESET H1 2025 Threat Report |
| RedLine | Long-standing top-five family by dark-web listing volume; disrupted in a late-2024 law enforcement operation alongside Meta Stealer | IBM X-Force |
| Vidar | Consistently ranks in the top five by listing volume across multiple reporting periods | IBM X-Force |
| Stealc | Newer entrant that has climbed into the top five by volume | IBM X-Force |
| RisePro | Rounds out the current top five by dark-web listing volume | IBM X-Force |
The pattern across every takedown listed above is the same: disrupting the dominant family doesn’t shrink the market, it redistributes it. A gap opens for a few weeks, and a new or existing family fills it. This is the same dynamic covered in this blog’s piece on breach forums, law enforcement action changes who’s operating, not whether the underlying activity continues.
What this actually costs, and how long it takes to find
| Breach type | Average cost | Average time to identify and contain |
|---|---|---|
| Global average, all breach types | $4.44 million | 241 days |
| Credential-based breaches specifically | $4.67 million | 246 days |
| Healthcare (the costliest industry, consistently) | Highest of any sector | Longer than the cross-industry average |
Credential-based breaches cost more and take longer to catch than the average, for a straightforward reason: a valid login doesn’t trip the alarms a malware infection does. Nobody’s antivirus flags a real password being used correctly. The exposure sits invisible until the credential gets used for something that does look wrong, which by definition happens after the damage is already underway.
What happens after the credential gets used
Stolen access doesn’t stop at the initial login. It’s frequently the opening move in a ransomware operation:
| Metric | Figure | Source |
|---|---|---|
| Ransomware victims in 2025 | 7,874 (+50% YoY) | NCC Group |
| Leading group by volume | Qilin, 1,022 attacks (13% share) | NCC Group |
| Ransom payment rate, Q4 2025 | 20% (a historic low) | Coveware |
| Median ransom payment, Q4 2025 | $325,000 (+132% YoY) | Coveware |
Read those last two rows together and the trend is clear: fewer victims are paying, but the ones who do are paying far more. That’s consistent with credential-driven access becoming the default entry point, it’s cheaper for an attacker to acquire, which means the ransom demand isn’t offsetting an expensive intrusion effort; it’s pure margin on a foothold that cost $25 to $500 to buy.
What this data means for your monitoring
None of the numbers above are catchable by scanning your own network. They describe activity that happens entirely outside your perimeter, on markets, in logs, in channels you don’t have visibility into by default. That’s the specific gap continuous credential monitoring is built to close, and it’s also exactly the evaluation criteria worth applying before choosing a vendor for it: source coverage, how fast a credential gets flagged after it’s listed, and what happens between detection and actual remediation. CybelAngel’s buyer’s guide for evaluating Credential Intelligence tools walks through exactly that evaluation, using the numbers in this piece as the starting evidence for why the category matters at all.
FAQs
1.95 billion, according to Recorded Future’s tracking, and that’s just what’s currently indexed. 276 million of those carry an active session cookie, which means MFA isn’t even in the equation for whoever’s holding one.
Stolen credentials, and it isn’t close. CrowdStrike’s 2026 Global Threat Report found 82% of 2025 intrusions never touched a dropped file: no malware signature, just a login that worked.
Because nothing goes off. IBM’s data puts credential-based breaches at $4.67 million and 246 days to identify and contain, both worse than the cross-industry average, for the simple reason that a valid password doesn’t trip an alarm the way a malware infection does.
Not for long. Lumma, RedLine, and other dominant families have all been hit by law enforcement action. None of it shrank the market. A gap opens, and a new or existing family fills it within weeks.
Pure margin economics. Coveware’s Q4 2025 data shows the payment rate at 20%, a historic low, while the median payment jumped 132% to $325,000 in the same quarter. When the entry point costs $25 to $500, a ransom demand isn’t offsetting an expensive intrusion, it’s profit on a cheap foothold, which is why the number keeps climbing even as fewer victims agree to pay.
A stolen password. $25 to $75 buys a verified corporate credential on markets like Russian Market and 2easy; $100 to $500 gets a working VPN or identity-provider login. Compare that to the cost of developing or buying a working exploit, and the economics explain most of what’s in this piece.
Not the exposure itself, no. Everything in this piece happens on markets, in logs, and in channels outside your perimeter, which is exactly what internal network monitoring isn’t built to see. Catching it means having visibility into where a credential gets listed, not just watching for what happens after it’s already been used
