惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
人人都是产品经理
人人都是产品经理
L
LINUX DO - 最新话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
Arctic Wolf
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Jina AI
Jina AI
The Cloudflare Blog
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
NISL@THU
NISL@THU
G
GRAHAM CLULEY
Project Zero
Project Zero
博客园_首页
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Spread Privacy
Spread Privacy
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
Latest news
Latest news
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tor Project blog
S
Securelist
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
IT之家
IT之家
Google DeepMind News
Google DeepMind News
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Last Watchdog
The Last Watchdog
T
Tenable Blog
宝玉的分享
宝玉的分享
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
量子位
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic

Ransomware – ThreatDown by Malwarebytes

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes The anatomy of an Akira ransomware attack AI-orchestrated cyberattacks Tracking remote ransomware attacks at their source Ransomware in April 2025—RansomHub is gone Ransomware in March 2025 Living Off the Land (LOTL) Attacks: Detect Ransomware Gangs - ThreatDown by Malwarebytes Ransomware group Mora_001 targets Fortinet applications - ThreatDown by Malwarebytes Ransomware in February 2025—Cl0p and RansomHub run riot - ThreatDown by Malwarebytes Infighting brings down the Black Basta ransomware group
One in five Fortune 500 companies had leaked credentials in the past 30 days - ThreatDown by Malwarebytes
Pieter Arntz · 2025-04-11 · via Ransomware – ThreatDown by Malwarebytes
Fortune 500

Stolen credentials can open the door for ransomware and Business Email Compromise (BEC).

Research by Malwarebytes shows that 111 Fortune 500 companies (the 500 largest organizations in the USA) have had employee credentials leaked in just the last 30 days.

Leaked credentials can occur for a number of reasons, including phishing, password reuse, brute force password guessing, and data leaks. Losing control of an employee credential represent a serious danger. Cybercriminals can exploit stolen credentials to gain unauthorized access to corporate systems and for lateral movement inside a network—perfect preparation for data theft and ransomware.

Looking further back than 30 days, the number of Fortune 500 companies with leaked credentials in the Malwarebytes data goes up to 363. Which means that 73% of these companies have lost control of at least one employee credential at some point.

The financial impact of ransomware can be devastating. Aside from the ransom itself, recovery can involve legal fees, regulatory fines, operational downtime, and opportunity costs. Beyond financial losses, organizations face reputational damage as customers and stakeholders lose trust in their ability to safeguard data.

Stolen credentials can also open the door for financial fraud like business email compromise (BEC) where cybercriminals impersonate someone inside an organization an employee trusts—like a CEO, vendor, lawyer, or business partner—to trick them into making a fraudulent payment or providing sensitive data.

The situation is even more serious when it comes to user credentials—credentials belonging to people who use services provided by those 500 organizations. A staggering 456 (91%) of Fortune 500 companies have had users’ credentials leaked.

And even though leaked customer credentials are not always the affected companies’ fault, it does seem as if there is a relationship between the number of leaked employee credentials and the number of leaked customer credentials, suggesting that some companies are more resistant to credential leakage than others. (In the graph below, the “r” value refers to the Pearson correlation coefficient. A value of 0.20 indicates a weak positive correlation.)

correlation employees and customer accounts leaked

Countermeasures

To address these risks of leaked customer and employee credentials, organizations must adopt proactive security measures: