Why is Credential Exposure Now the Default Entry

There are 1.95 billion malware-sourced credentials currently indexed from criminal markets, and 276 million of them include an active session cookie that lets an attacker into an account without ever triggering multi-factor authentication, according to reported tracking.

That single number explains most of what follows in this piece: credential theft isn’t a side effect of attacks anymore, it’s the primary access method, and the data below shows exactly how that shift happened and what it costs.

Modern cybercrime operates less like a break-in and more like a simple sign-in. Threat intelligence databases currently index 1.95 billion compromised credentials—including 276 million active session cookies capable of bypassing multi-factor authentication on import. Fueled by infostealer malware that compromised over 16 million devices last year, 82% of modern security intrusions are now entirely malware-free, relying instead on valid access. In fact, 54% of ransomware victims had domain credentials exposed in stealer logs prior to being attacked, contributing to a 33% year-over-year surge in FBI-reported cybercrime losses, reaching $16.6 billion.

Why credentials replaced malware as the default entry point

Buying a working credential is now cheaper and more reliable than developing an exploit. A verified corporate password sells for $25 to $75 on markets like Russian Market and 2easy; a working VPN or identity-provider credential goes for $100 to $500, as covered in this blog’s breakdown of the infostealer economy. Lumma Stealer, currently one of the most prevalent infostealer families, runs a subscription model starting at $250 a month specifically to serve buyers who want a steady supply of fresh logs rather than a one-off purchase.

This is also the mechanism behind the Com-linked attacks covered in this blog’s piece on Discord’s recruitment pipeline: the social-engineering step (a convincing help-desk call) only works because the attacker already has enough real, specific detail, an employee name, a department, sometimes an active session, to sound legitimate. That detail comes from exactly this market.

Where the credentials actually come from

FamilyNotesFuente
Lumma StealerCurrently one of the most prevalent families; disrupted by a multi-vendor takedown in May 2025; new logs continued appearing within weeksMicrosoft Digital Defense Report 2025; ESET H1 2025 Threat Report
RedLineLong-standing top-five family by dark-web listing volume; disrupted in a late-2024 law enforcement operation alongside Meta StealerIBM X-Force
VidarConsistently ranks in the top five by listing volume across multiple reporting periodsIBM X-Force
StealcNewer entrant that has climbed into the top five by volumeIBM X-Force
RiseProRounds out the current top five by dark-web listing volumeIBM X-Force

The pattern across every takedown listed above is the same: disrupting the dominant family doesn’t shrink the market, it redistributes it. A gap opens for a few weeks, and a new or existing family fills it. This is the same dynamic covered in this blog’s piece on breach forums, law enforcement action changes who’s operating, not whether the underlying activity continues.

What this actually costs, and how long it takes to find

Breach typeAverage costAverage time to identify and contain
Global average, all breach types$4.44 million241 days
Credential-based breaches specifically$4.67 million246 days
Healthcare (the costliest industry, consistently)Highest of any sectorLonger than the cross-industry average

Credential-based breaches cost more and take longer to catch than the average, for a straightforward reason: a valid login doesn’t trip the alarms a malware infection does. Nobody’s antivirus flags a real password being used correctly. The exposure sits invisible until the credential gets used for something that does look wrong, which by definition happens after the damage is already underway.

What happens after the credential gets used

Stolen access doesn’t stop at the initial login. It’s frequently the opening move in a ransomware operation:

MetricFigureFuente
Ransomware victims in 20257,874 (+50% YoY)NCC Group
Leading group by volumeQilin, 1,022 attacks (13% share)NCC Group
Ransom payment rate, Q4 202520% (a historic low)Coveware
Median ransom payment, Q4 2025$325,000 (+132% YoY)Coveware

Read those last two rows together and the trend is clear: fewer victims are paying, but the ones who do are paying far more. That’s consistent with credential-driven access becoming the default entry point, it’s cheaper for an attacker to acquire, which means the ransom demand isn’t offsetting an expensive intrusion effort; it’s pure margin on a foothold that cost $25 to $500 to buy.

What this data means for your monitoring

None of the numbers above are catchable by scanning your own network. They describe activity that happens entirely outside your perimeter, on markets, in logs, in channels you don’t have visibility into by default. That’s the specific gap continuous credential monitoring is built to close, and it’s also exactly the evaluation criteria worth applying before choosing a vendor for it: source coverage, how fast a credential gets flagged after it’s listed, and what happens between detection and actual remediation. CybelAngel’s buyer’s guide for evaluating Credential Intelligence tools walks through exactly that evaluation, using the numbers in this piece as the starting evidence for why the category matters at all.

Preguntas frecuentes

1.95 billion, according to Recorded Future’s tracking, and that’s just what’s currently indexed. 276 million of those carry an active session cookie, which means MFA isn’t even in the equation for whoever’s holding one.

Stolen credentials, and it isn’t close. CrowdStrike’s 2026 Global Threat Report found 82% of 2025 intrusions never touched a dropped file: no malware signature, just a login that worked.

Because nothing goes off. IBM’s data puts credential-based breaches at $4.67 million and 246 days to identify and contain, both worse than the cross-industry average, for the simple reason that a valid password doesn’t trip an alarm the way a malware infection does.

Not for long. Lumma, RedLine, and other dominant families have all been hit by law enforcement action. None of it shrank the market. A gap opens, and a new or existing family fills it within weeks.

Pure margin economics. Coveware’s Q4 2025 data shows the payment rate at 20%, a historic low, while the median payment jumped 132% to $325,000 in the same quarter. When the entry point costs $25 to $500, a ransom demand isn’t offsetting an expensive intrusion, it’s profit on a cheap foothold, which is why the number keeps climbing even as fewer victims agree to pay.

A stolen password. $25 to $75 buys a verified corporate credential on markets like Russian Market and 2easy; $100 to $500 gets a working VPN or identity-provider login. Compare that to the cost of developing or buying a working exploit, and the economics explain most of what’s in this piece.

Not the exposure itself, no. Everything in this piece happens on markets, in logs, and in channels outside your perimeter, which is exactly what internal network monitoring isn’t built to see. Catching it means having visibility into where a credential gets listed, not just watching for what happens after it’s already been used

Sobre el autor