Researchers Track 2.9 Billion Compromised Credentials

Researchers Track 2.9 Billion Compromised Credentials

Infosecurity Magazine
Infosecurity MagazineApr 29, 2026

Why It Matters

The scale of credential theft and AI‑enabled attacks forces enterprises to rethink legacy defenses, while the ransomware and DDoS spikes heighten operational risk and financial exposure.

Key Takeaways

  • 2.9 billion credentials compromised globally in 2025.
  • macOS infostealer infections jumped from <1k to >70k.
  • Ransomware victims rose 45% to 7,549 incidents.
  • AI now powers 80% of cyberattack workflows autonomously.
  • DDoS attacks surged 400% to 3,500 incidents.

Pulse Analysis

The sheer volume of compromised credentials—approaching three billion—highlights how attackers are exploiting every entry point, from traditional username/password combos to session tokens and cookies. The unprecedented surge in macOS infostealer infections, leaping from under a thousand to over seventy thousand machines, signals that threat actors are broadening their focus beyond Windows‑centric environments, forcing security teams to adopt cross‑platform monitoring and rapid credential rotation strategies.

Ransomware remains a dominant revenue stream, with victims up 45% year‑over‑year, while the number of active ransomware groups swelled to 147, including 80 newcomers. Simultaneously, the vulnerability landscape tightened as 238 flaws entered the CISA KEV catalog, reflecting a 29% increase. Hacktivist activity and DDoS attacks also exploded, driven by geopolitical tensions, underscoring the need for robust network resilience and real‑time threat intelligence to mitigate multi‑vector assaults.

Perhaps the most consequential shift is the integration of artificial intelligence into the cyber kill chain. KELA reports that over 80% of attacks now incorporate AI, enabling autonomous workflow execution, AI‑assisted malware, and sophisticated prompt‑injection techniques. This evolution diminishes the effectiveness of static defenses and places a premium on AI‑enhanced detection, behavior analytics, and automated response capabilities. Organizations that fail to adopt AI‑driven security risk being outpaced by increasingly self‑learning adversaries.

Researchers Track 2.9 Billion Compromised Credentials

Comments

Want to join the conversation?

Loading comments...