惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
D
Docker
GbyAI
GbyAI
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
小众软件
小众软件
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
B
Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
2.8 Billion Credentials Stolen As Password Attacks Surge
Davey Winder · 2026-04-30 · via Forbes - Consumer Tech
Taking the word password using tweezers from a screen of binary code.

The infostealer password credential theft crimewave exposed.

getty

A newly published analysis of cybercrime statistics across 2025 has revealed that the number of ransomware victims surged by 45% over the previous year. But that’s not the revelation that you need to pay the most attention to. Rather, the underlying reliance on stolen credentials as the primary access method takes center stage as far as I am concerned. No matter what platform you use, no matter what accounts you are protecting, the time to start taking password security seriously has long since passed.

The State of Cybercrime 2026 report from KELA identified no less than 2.86 billion compromised credentials, including passwords and session cookies that enable 2FA bypass. Shockingly, business cloud and authentication services accounted for more than 30% of this exposed data across 2025. What’s more, the analysis showed that infostealer malware responsible for compromising credentials doesn’t care about your operating system assumptions: “infections on macOS devices increased from fewer than 1,000 cases in 2024 to more than 70,000 in 2025, a 7,000% increase,” the report confirmed.

ForbesNo Microsoft Patch—All Windows Versions Likely At Risk From PhantomRPC

Password Security — From Clicks To Credentials

I have been warning readers of the danger posed by infostealer malware for a number of years now. From millions of Gmail passwords contained in leaked infostealer logs, to FBI operations aimed at taking down the cybercrime gangs behind the stolen password databases. Yet, as the KELA analysis has shown all too plainly, the threat continues. Not only does it continue, in fact, but it also surges year on year.

Infostealer malware, Kela explained, is “designed to exfiltrate sensitive data from compromised machines, including login credentials, authentication tokens, and other critical account information.” And with the now almost universal availability of malware-as-a-service operations to the infostealer criminal world, the barrier to entry has not only been lowered but kicked to the curb completely.

Between January 1 and December 31, 2025, KELA said, it “observed approximately 3.9 million unique machines infected with infostealer malware globally, which collectively yielded 347.5 million compromised credentials.” In total, however, KELA tracked a total of 2.86 billion compromised credentials across all sources, including databases of infostealer logs and the like that are available from criminal marketplaces.

ForbesGmail Accounts Under Persistent Hacking Attacks—‘Always Be Wary’By Davey Winder

The most common methods used by infostealers last year, according to the KELA report, were as follows:

  • Email, messaging apps, and AI-generated
    personalized scams, often bypassing MFA via Phishing-as-a-Service.
  • Users tricked into manually executing scripts, evading traditional security tools, in so-called hack your own password attacks.
  • Malicious ads and search results push trojanized software,
    boosting infection rates.
  • Poisoned packages and DevTools impersonation target
    high-privilege credentials in supply chain attacks.
  • Compromised browser extension updates enable form-grabbing and cookie theft.
  • Pirated apps and fake software updates also remained effective.

To mitigate against the risk of becoming just another statistic in next year’s cybercrime report, it is advised that you keep all software and operating systems updated, using official channels only, and never follow links in unsolicited emails or messages, no matter how genuine they may seem. Use a password manager to ensure there is no sharing of passwords across accounts, limiting the impact of any single compromise. Always ensure that you employ 2FA on all accounts where available, as this provides an additional layer of protection against password theft. That said, infostealers that compromise session cookies to bypass 2FA protections are now becoming commonplace. So, the final advice is to switch to using passkeys instead of a password wherever possible as these offer strength by default, phishing resistance and, importantly, because passkeys are randomly generated and never shared during the sign-in process, and your private keys never leave your device, they are all but impossible to compromise through interception or by the kind of infostealer malware covered by this article.

ForbesUpdate Safari Browser Before May 24—1Password Users WarnedBy Davey Winder