Credential Theft Surges: 1.7B Logins Stolen in Six Months

▼ Summary
– Infostealers accounted for the theft of 1.7 billion credentials during the first half of 2026, according to Flashpoint data.
– The stolen credentials were primarily harvested through infostealer malware infections.
– The scale of credential theft highlights the growing threat posed by infostealer malware in cyberattacks.
– Flashpoint’s findings underscore the need for stronger security measures to protect against credential theft.
– The data emphasizes the increasing volume and impact of infostealer-based cybercrime in the observed period.
Cybercriminals are siphoning login data at an alarming clip. New research from Flashpoint shows that infostealer malware accounted for the theft of 1.7 billion credentials during the first six months of 2026.
The figure, drawn from Flashpoint’s threat intelligence telemetry, underscores how attackers have shifted their focus toward harvesting valid usernames and passwords rather than relying solely on phishing or brute force. These stolen logins are frequently sold on underground markets, where buyers use them for account takeover, corporate network intrusion, and ransomware deployment.
According to the report, the volume of compromised credentials represents a significant escalation compared to previous periods. The data suggests that malware-as-a-service operations have made it easier for lower-skilled actors to deploy infostealers at scale. Common variants observed in the wild include those targeting browser-stored passwords, cookies, and autofill data, giving attackers a broad swath of access points.
Flashpoint analysts note that the stolen credentials often come from both consumer and enterprise environments. In many cases, the same login pairs are reused across multiple platforms, amplifying the damage when a single breach occurs. The firm recommends organizations enforce multi-factor authentication and deploy credential monitoring to detect compromised accounts before they are exploited.
The report also highlights regional variations in attack activity, with certain geographic clusters showing higher infection rates. While the researchers did not attribute the campaigns to specific groups, they emphasized that the infrastructure supporting these operations is increasingly professionalized.
For security teams, the takeaway is clear: password-based defenses alone are no longer sufficient. With billions of credentials already in circulation, proactive threat hunting and rapid response protocols are critical to staying ahead of adversaries.
(Source: Infosecurity Magazine)