Introduction to the Stolen Credential Market
Threat actors are increasingly turning massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for a specific company, platform, domain, geography, or account type. Researchers analyzed 470 underground forum posts published between January 2025 and June 2026, across different sources, related to actors offering to search for and extract stolen credentials from their databases.
Key Findings
The findings show a dedicated service layer sitting between infostealer infections, raw logs trading, and account takeover activity. The profile of the threat actors who offer these services is divided between the Malware-as-a-Service (MaaS) providers and the MaaS consumers. In many cases, they function as credential brokers or data processors, monetizing the vast number of logs and their ability to search, filter, format, and deliver targeted results from large stolen credential collections.
How the Service Works
The service model represents a practical example of T1589.001 (Gather Victim Identity Information: Credentials), where adversaries actively research and acquire credentials prior to exploitation, and potentially T1650 (Acquire Access), given that some sellers deliver results indistinguishable from direct access provisioning. The process involves infostealers infecting devices and collecting credentials, cookies, autofill data, and browser artifacts, which are then aggregated and inserted into private clouds, ULP databases, public dumps, or exchange-based collections.
The Role of Sellers
Sellers extract rows based on buyers' requests, and buyers then validate the credentials and use them for account takeover, fraud, spam, phishing, crypto theft, or corporate intrusion. The sellers in this dataset are often neither the first nor final step, but rather the processing layer that turns stolen credential noise into targeted attack material.
The Economy of the Stolen Credential Market
The market economy is similar to the DDoS market, where the buyer submits a domain and the service provider attacks it. In this case, a buyer sends a target, and the seller returns matching credentials. The target can be a company domain, login URL, ecommerce site, gaming platform, application, geographic market, or a list of emails. The output is usually delivered in formats such as URL:LOGIN, URL:LOG, MAIL, LOGIN, PHONE, or other combinations depending on the request.
Customer Feedback
Customer feedback indicates that the sellers are over-promising and under-delivering. They claim that some sellers aren’t credible, and that the credentials are often invalid, duplicated, and generally unusable. While the concept of large combo lists or aggregated credential files isn’t new, this service is still something unique that can eventually put a lot of businesses and organizations at risk if operated correctly.
Defending Against the Stolen Credential Market
Defenders should learn that attackers no longer need to manually process massive dumps to find what matters. They can outsource that work to sellers who specialize in turning noisy credential collections into focused target lists. For defenders, the challenge is to identify and close those exposed paths before a buyer turns them into access. Security teams can gain visibility into these underground markets and monitor exposed employee credentials, corporate domains, login portals, SaaS applications, and related indicators across deep and dark web sources.
- Identify and close exposed paths before a buyer turns them into access
- Monitor exposed employee credentials, corporate domains, login portals, SaaS applications, and related indicators
- Prioritize the most relevant exposures and respond faster with password resets, session revocation, MFA enforcement, and investigation of possible account misuse
Source: BleepingComputer