惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
量子位
博客园 - 司徒正美
IT之家
IT之家
V
Visual Studio Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
Google DeepMind News
Google DeepMind News
Last Week in AI
Last Week in AI
Microsoft Security Blog
Microsoft Security Blog
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
Vercel News
Vercel News
B
Blog
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
小众软件
小众软件
罗磊的独立博客
博客园 - 叶小钗
雷峰网
雷峰网
Martin Fowler
Martin Fowler
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
2.8 Billion Credentials Stolen As Password Attacks Surge
Davey Winder · 2026-04-30 · via Forbes - Innovation
Taking the word password using tweezers from a screen of binary code.

The infostealer password credential theft crimewave exposed.

getty

A newly published analysis of cybercrime statistics across 2025 has revealed that the number of ransomware victims surged by 45% over the previous year. But that’s not the revelation that you need to pay the most attention to. Rather, the underlying reliance on stolen credentials as the primary access method takes center stage as far as I am concerned. No matter what platform you use, no matter what accounts you are protecting, the time to start taking password security seriously has long since passed.

The State of Cybercrime 2026 report from KELA identified no less than 2.86 billion compromised credentials, including passwords and session cookies that enable 2FA bypass. Shockingly, business cloud and authentication services accounted for more than 30% of this exposed data across 2025. What’s more, the analysis showed that infostealer malware responsible for compromising credentials doesn’t care about your operating system assumptions: “infections on macOS devices increased from fewer than 1,000 cases in 2024 to more than 70,000 in 2025, a 7,000% increase,” the report confirmed.

ForbesNo Microsoft Patch—All Windows Versions Likely At Risk From PhantomRPC

Password Security — From Clicks To Credentials

I have been warning readers of the danger posed by infostealer malware for a number of years now. From millions of Gmail passwords contained in leaked infostealer logs, to FBI operations aimed at taking down the cybercrime gangs behind the stolen password databases. Yet, as the KELA analysis has shown all too plainly, the threat continues. Not only does it continue, in fact, but it also surges year on year.

Infostealer malware, Kela explained, is “designed to exfiltrate sensitive data from compromised machines, including login credentials, authentication tokens, and other critical account information.” And with the now almost universal availability of malware-as-a-service operations to the infostealer criminal world, the barrier to entry has not only been lowered but kicked to the curb completely.

Between January 1 and December 31, 2025, KELA said, it “observed approximately 3.9 million unique machines infected with infostealer malware globally, which collectively yielded 347.5 million compromised credentials.” In total, however, KELA tracked a total of 2.86 billion compromised credentials across all sources, including databases of infostealer logs and the like that are available from criminal marketplaces.

ForbesGmail Accounts Under Persistent Hacking Attacks—‘Always Be Wary’By Davey Winder

The most common methods used by infostealers last year, according to the KELA report, were as follows:

  • Email, messaging apps, and AI-generated
    personalized scams, often bypassing MFA via Phishing-as-a-Service.
  • Users tricked into manually executing scripts, evading traditional security tools, in so-called hack your own password attacks.
  • Malicious ads and search results push trojanized software,
    boosting infection rates.
  • Poisoned packages and DevTools impersonation target
    high-privilege credentials in supply chain attacks.
  • Compromised browser extension updates enable form-grabbing and cookie theft.
  • Pirated apps and fake software updates also remained effective.

To mitigate against the risk of becoming just another statistic in next year’s cybercrime report, it is advised that you keep all software and operating systems updated, using official channels only, and never follow links in unsolicited emails or messages, no matter how genuine they may seem. Use a password manager to ensure there is no sharing of passwords across accounts, limiting the impact of any single compromise. Always ensure that you employ 2FA on all accounts where available, as this provides an additional layer of protection against password theft. That said, infostealers that compromise session cookies to bypass 2FA protections are now becoming commonplace. So, the final advice is to switch to using passkeys instead of a password wherever possible as these offer strength by default, phishing resistance and, importantly, because passkeys are randomly generated and never shared during the sign-in process, and your private keys never leave your device, they are all but impossible to compromise through interception or by the kind of infostealer malware covered by this article.

ForbesUpdate Safari Browser Before May 24—1Password Users WarnedBy Davey Winder