All articles
Threat Intelligence April 2026 6 min read

Your Credentials Are Already for Sale. Now What?

Stolen credentials appear on criminal markets within days of a phish or an infostealer infection. What dark-web monitoring can realistically do for you, what it cannot, and the concrete steps that make a leaked password worthless to an attacker.

JR Jacob RiggsChief Executive Officer, Cyse
Key takeaways
  • Assume some of your credentials are already exposed - the useful question is not "if" but "which, and what can we do about it".
  • Infostealer malware, not big database breaches, is now the dominant source of fresh corporate credentials on criminal markets.
  • Dark-web monitoring is an early-warning signal, not a control - its value is measured by what you do when it alerts.
  • Phishing-resistant multi-factor authentication makes a stolen password far less useful than it looks.
  • Session-token theft bypasses passwords entirely - which is why device health and re-authentication matter.

Somewhere on a criminal marketplace right now, corporate credentials are changing hands for the price of a coffee. Some of them probably belong to organisations that have no idea. This is not a reason to panic - it is a reason to understand how the credential economy actually works and to make sure a leaked password is not enough to hurt you.

How credentials end up for sale

The mental image most people have - a dramatic breach of some big database - is increasingly out of date. The dominant source of fresh, working corporate credentials today is far more mundane and far more dangerous: infostealer malware.

An employee installs a cracked application, clicks a malicious ad, or opens the wrong attachment on a personal device. A lightweight piece of malware runs for a few seconds, scrapes every saved password, browser cookie, and session token, and quietly sends them to the operator. That bundle - called a "log" - is then sold in bulk. Because it comes straight from the victim's browser, the credentials are current and correct.

Why this is worse than a breach dump

A leaked database is often old and hashed. An infostealer log is fresh, plaintext, and comes with the victim's active session cookies - which can let an attacker log in without needing the password or the second factor at all.

What dark-web monitoring can and cannot do

Monitoring services scan criminal markets, forums, and paste sites for your domains and credentials, and alert you when they appear. This is genuinely useful - but only if you are honest about what it is.

What it does well: it gives you early warning that a specific account is exposed, often before the attacker has used it, buying you time to reset and investigate. It also reveals patterns - a spike in exposures may point to a compromised device or a team being targeted.

What it cannot do: it cannot see everything (plenty of trade happens in private channels it never touches), and it cannot fix anything on its own. An alert that no one acts on is just a more expensive way of not knowing.

Dark-web monitoring is a smoke alarm. It is valuable precisely because of what you do in the ninety seconds after it goes off - and worthless if no one is home.

What to do when you are alerted

A credible exposure alert should trigger a small, practised routine:

  • Reset the credential immediately and revoke all active sessions for that account - not just the password, the live tokens too.
  • Assume the device is compromised. If the source is an infostealer, the password reset alone is not enough; the malware will simply steal the new one. The affected device needs to be investigated and cleaned or rebuilt.
  • Check for reuse. People reuse passwords across work and personal accounts. One exposed credential often unlocks several doors.
  • Look for what they already did. Review authentication logs for that account. Has it logged in from somewhere unusual? Have mail rules or MFA devices been added?

The controls that make a leaked password worthless

The real goal is not to prevent every credential from ever leaking - that is impossible. It is to make an individual leaked credential a non-event. Three controls do most of the work:

  • Phishing-resistant multi-factor authentication. Passkeys and hardware security keys mean a stolen password on its own gets an attacker nowhere. This is the highest-value change most organisations can make.
  • Short session lifetimes and re-authentication for sensitive actions. Because stolen session tokens bypass passwords entirely, limiting how long a token is valid - and forcing a fresh login for high-risk operations - closes the infostealer's favourite path.
  • Device health checks. Requiring that logins come from a known, healthy, managed device stops credentials stolen from an unmanaged personal machine from working against corporate systems.
The bottom line

Treat exposure as a given. Monitoring tells you which credentials are out, and a small set of strong controls - phishing-resistant MFA, short sessions, device health - makes that exposure cost the attacker far more than it costs you.

If you want visibility into what is circulating about your organisation, and a plan for responding when it appears, that is the work our threat intelligence practice does every day.

Need help putting this into practice?

Our practitioners deal with exactly these problems every week. A short conversation costs nothing and usually saves a lot.