Credential leaks and infostealer exposure

15 briefings

The credential leak threat operates differently from most cyber-security risks: the compromised credential is often old, the exposed person is often unaware, and the window between acquisition and exploitation can span years. Infostealer malware harvests credentials, session cookies, and stored authentication tokens from compromised endpoints, then routes the logs to a tiered resale market where corporate access credentials trade for thousands of dollars a session.

The scale is documented: SpyCloud's 2026 Identity Exposure Report recaptured 8.6 billion stolen session cookies from underground circulation across 2025. Ransomware operators and account-takeover groups routinely confirm that victim credentials had already circulated in prior breach corpora — the attack was possible because the entry point existed undetected in a log that pre-dated the network intrusion.

These briefings cover how infostealer families work, how the market for compromised credentials functions, how a stolen credential translates into account compromise and lateral movement, and what investigation and detection approaches actually reduce the risk. The coverage is practitioner-level: it addresses the mechanics of the attack, not the compliance language that describes it after the fact.

Recommended next step

If you need to know which credentials are already exposed

The Lockdown maps credential and session exposure across breach corpora, stealer-log references and dark-forum archives, then prioritises the accounts at realistic takeover risk.

If something specific has leaked, the reference on what each kind of leaked data enables and what actually revokes it sets out, item by item, whether it can be revoked and which action does it — including the artefacts a password reset never touches. For the personal response in sequence, the data breach recovery checklist walks through securing accounts and cutting standing exposure. For organisations, the GDPR breach response checklist and its US counterpart cover the 72-hour notification window.

All briefings in this hub

GUIDE

Has My Data Been Leaked?

The answer is almost certainly yes, so the useful question is which of your data leaked, whether you can change it, and how to reduce what you can't.

8 min·18 Jul 2026
ANALYSIS

Why Cybercrime Isn't About You: Motivation, Opportunity, and How Victims Are Surfaced

In most cyber incidents no human selected the victim. Exposure did. Why motivation is not the bottleneck, and what that changes about defence.

11 min·19 Jun 2026
GUIDE

What to Do After a Data Breach: A Step-by-Step Playbook

A step-by-step playbook for the moment you learn you have been breached: secure your accounts, triage by data class, work the four-wave attack timeline, and use your EU rights.

12 min·10 Jun 2026
GUIDE

What Is Account Takeover: The Full Attack Anatomy

A practitioner-level anatomy of account takeover — the credential supply chain, MFA bypass mechanics, post-access exploitation, and a layered defence that maps to each attack class.

19 min·10 Jun 2026
ANALYSIS

From Gamble to Calculation: How Your Exposure Decides Who Gets Attacked

An intrusion told backwards from a single email address, and why a findable digital footprint turns a target from a gamble an attacker takes into a calculation they can run.

11 min·25 May 2026
ANALYSIS

How Modern Infostealers Work: Execution, Telemetry, and the 2026 Log Economy

How RedLine, Lumma, and Vidar execute on the host, what they harvest, what is visible on the wire, and how stolen credentials flow through 2026 log markets.

17 min·10 May 2026
METHOD

How a Lockdown Investigation Runs

The Lockdown is the credential-and-account-takeover tier of our investigation work. Five business days, fixed €995, the full Mirror foundation plus seven Lockdown-specific deliverables. This article walks the methodology stage by stage: discovery, cross-reference, verification, report.

14 min·6 May 2026
ANALYSIS

How Crypto Anonymity Breaks at the Endpoint

Crypto privacy was designed against chain analysis, not against the endpoint. The Fowler 2026 database showed why that gap is now the dominant threat.

13 min·3 May 2026
GUIDE

Dark Web Monitoring: What It Actually Does and When It’s Worth Paying For

What dark web monitoring actually catches, what it misses on stealer logs and live session cookies, and when bundled, standalone, or human-led options each make sense.

18 min·27 Apr 2026
INTEL

Stealer Logs: Inside The Credential Market HIBP Doesn't See

Stealer logs are the credential exposure vector most organisations cannot see — per-device snapshots containing passwords and live session cookies, sold in underground markets within hours of infection.

11 min·20 Apr 2026
GUIDE

If You Were in the Odido Breach — What to Do Now

The Odido dataset is public. If you were a customer — even a decade ago — your data is likely in it. This is what the exposure enables, and what closes it.

7 min·14 Mar 2026
INTEL

Odido: One Month After Disclosure, the Breach Is Still Expanding

One month after Odido disclosed the breach, every dimension has escalated. The full dataset is public. Ministers and protected persons are in it. Former customers who left a decade ago are in it. And the fraud is doubling.

8 min·13 Mar 2026
INTEL

The Odido Breach: 30 Days of Criminal Activity, Documented

The Odido breach was confirmed February 12. Within 19 days, the full dataset was published on criminal infrastructure. Within 20 days, active phishing campaigns were running. This is not a prediction — it is a documented sequence.

7 min·10 Mar 2026
ANALYSIS

Synthetic Identity Fraud Is Becoming an Identity-Bypass Chain

MFA was supposed to solve password theft. KYC was supposed to solve identity fraud. Both assumptions are now broken — defeated not by nation-states but by criminal groups using free software, breach data as raw material, and OSINT to source every component.

12 min·6 Mar 2026
INTEL

Odido Breach: How ShinyHunters Stole 6.2M Records

ShinyHunters is publishing stolen Odido customer data daily — names, IBANs, ID numbers, sensitive account notes. The attack used a phone call, not a zero-day. Here is exactly how it unfolded.

7 min·27 Feb 2026

If your credentials might already be circulating, a Lockdown investigation maps the exposure.

Check breached credentials