CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Stolen login data is so abundant that criminal markets can sell it for almost nothing. Meanwhile, verified entry into large companies commands far higher prices, reshaping the underground economy. Infostealer malware drives that divide. It reaches victims through phishing lures, fake updates, pirated downloads or malicious attachments, then collects browser passwords, cookies and data. The […] The post 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket appeared f

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket By Tushar Subhra Dutta August 12, 2026 Stolen login data is so abundant that criminal markets can sell it for almost nothing. Meanwhile, verified entry into large companies commands far higher prices, reshaping the underground economy. Infostealer malware drives that divide. It reaches victims through phishing lures, fake updates, pirated downloads or malicious attachments, then collects browser passwords, cookies and data. The logs are reused against cloud services, VPNs and business accounts. Analysts at DarkOwl noted the shift in a report shared with Cyber Security News (CSN). The report cites 2.86 billion compromised credentials in 2025, while another analysis counted 1.8 billion stolen in the first half, an 800% jump from six months earlier. The result reaches well beyond a reused password. A correct username and password can no longer prove identity when criminals can buy huge volumes of records. The underground market also rewards access that can be used immediately against larger organizations. 2.86 Billion Credentials Flood Criminal Markets At the commodity end, stolen information is priced for scale. A Social Security number may sell for $1 to $6, a name-and-email record for under $15, and a complete identity package for roughly $20 to $100. A payment card with a security code commonly sells for $10 to $40. This abundance changes the meaning of a password leak. Criminals can test old credentials across many services, while fresh logs may include browser data needed to take over accounts. A recent report on infostealer logs and cloud breaches shows why stolen credentials increasingly serve as a route into corporate systems. The high end of the market is moving in the opposite direction. Research cited by DarkOwl found that average initial-access-broker listings across five forums rose from about $2,726 in 2024 to $113,275 in 2025. That 4,055% increase was influenced by a small number of listings claiming access to high-revenue targets. Typical access costs hundreds or thousands, not the headline average. It signals an ultra-premium tier for access to large enterprises. Healthcare records, which cannot simply be cancelled and reissued, held at about $250 to $310 each, while verified cryptocurrency accounts also commanded higher prices. For defenders, a rising price is a warning about attacker interest, not a precise measure of exposure. Organizations in healthcare, finance and critical infrastructure should review internet-facing systems, privileged accounts and internal movement detection. The growing trade in initial access broker listings makes that review important after any credential exposure. Cookies Turn MFA Into a Target Passwords are not the only item for sale. Stolen session cookies, small data files that keep a user signed in after authentication, have a premium because they can let an attacker replay an approved session. In practice, that can sidestep a password prompt and the usual multi-factor authentication check. This method does not mean multi-factor authentication has failed, but it shows that authentication must protect the session after sign-in. Recent coverage of pass-the-cookie MFA bypass attacks illustrates how malware and phishing campaigns capture these tokens and reuse them without a new code. DarkOwl recommends shorter session lifetimes, binding sessions to devices, when possible, and watching for session replay. Teams should also move toward phishing-resistant MFA and continuous verification rather than treating passwords and SMS codes as sufficient proof of identity. Those controls reduce the value of the data criminals are trying to buy. The market is becoming more selective as well as larger. Bulk dumps continue to lose value, but AI-curated records tailored to a company or role can command a premium because they make targeted fraud and phishing easier. Reports on phishing kits stealing session tokens underline how attackers focus on authenticated access, not merely passwords. Dark web pricing should be treated as an early warning signal. Security leaders can use it with exposure monitoring and incident response to decide where defenses need attention first. The key lesson from the 2.86 billion credential figure is simple: cheap stolen data can still lead to expensive enterprise compromise. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Tags cyber security news Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts Cyber Security Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability Cyber Security News CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure Cyber Security News Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals Cyber Security News Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗