Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
Stolen login data is so abundant that criminal markets can sell it for almost nothing. Meanwhile, verified entry into large companies commands far higher prices, reshaping the underground economy. Infostealer malware drives that divide. It reaches victims through phishing lures, fake updates, pirated downloads or malicious attachments, then collects browser passwords, cookies and data. The […] The post 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket appeared f
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket
By Tushar Subhra Dutta
August 12, 2026
Stolen login data is so abundant that criminal markets can sell it for almost nothing.
Meanwhile, verified entry into large companies commands far higher prices, reshaping the underground economy.
Infostealer malware drives that divide. It reaches victims through phishing lures, fake updates, pirated downloads or malicious attachments, then collects browser passwords, cookies and data.
The logs are reused against cloud services, VPNs and business accounts. Analysts at DarkOwl noted the shift in a report shared with Cyber Security News (CSN).
The report cites 2.86 billion compromised credentials in 2025, while another analysis counted 1.8 billion stolen in the first half, an 800% jump from six months earlier.
The result reaches well beyond a reused password. A correct username and password can no longer prove identity when criminals can buy huge volumes of records. The underground market also rewards access that can be used immediately against larger organizations.
2.86 Billion Credentials Flood Criminal Markets
At the commodity end, stolen information is priced for scale. A Social Security number may sell for $1 to $6, a name-and-email record for under $15, and a complete identity package for roughly $20 to $100.
A payment card with a security code commonly sells for $10 to $40. This abundance changes the meaning of a password leak.
Criminals can test old credentials across many services, while fresh logs may include browser data needed to take over accounts.
A recent report on infostealer logs and cloud breaches shows why stolen credentials increasingly serve as a route into corporate systems.
The high end of the market is moving in the opposite direction. Research cited by DarkOwl found that average initial-access-broker listings across five forums rose from about $2,726 in 2024 to $113,275 in 2025.
That 4,055% increase was influenced by a small number of listings claiming access to high-revenue targets.
Typical access costs hundreds or thousands, not the headline average. It signals an ultra-premium tier for access to large enterprises.
Healthcare records, which cannot simply be cancelled and reissued, held at about $250 to $310 each, while verified cryptocurrency accounts also commanded higher prices.
For defenders, a rising price is a warning about attacker interest, not a precise measure of exposure.
Organizations in healthcare, finance and critical infrastructure should review internet-facing systems, privileged accounts and internal movement detection.
The growing trade in initial access broker listings makes that review important after any credential exposure.
Cookies Turn MFA Into a Target
Passwords are not the only item for sale. Stolen session cookies, small data files that keep a user signed in after authentication, have a premium because they can let an attacker replay an approved session.
In practice, that can sidestep a password prompt and the usual multi-factor authentication check.
This method does not mean multi-factor authentication has failed, but it shows that authentication must protect the session after sign-in.
Recent coverage of pass-the-cookie MFA bypass attacks illustrates how malware and phishing campaigns capture these tokens and reuse them without a new code.
DarkOwl recommends shorter session lifetimes, binding sessions to devices, when possible, and watching for session replay.
Teams should also move toward phishing-resistant MFA and continuous verification rather than treating passwords and SMS codes as sufficient proof of identity. Those controls reduce the value of the data criminals are trying to buy.
The market is becoming more selective as well as larger. Bulk dumps continue to lose value, but AI-curated records tailored to a company or role can command a premium because they make targeted fraud and phishing easier.
Reports on phishing kits stealing session tokens underline how attackers focus on authenticated access, not merely passwords.
Dark web pricing should be treated as an early warning signal. Security leaders can use it with exposure monitoring and incident response to decide where defenses need attention first.
The key lesson from the 2.86 billion credential figure is simple: cheap stolen data can still lead to expensive enterprise compromise.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Cyber Security
Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
Cyber Security News
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Cyber Security News
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Cyber Security News
Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?