Somewhere on a criminal marketplace right now, corporate credentials are changing hands for the price of a coffee. Some of them probably belong to organisations that have no idea. This is not a reason to panic - it is a reason to understand how the credential economy actually works and to make sure a leaked password is not enough to hurt you.
How credentials end up for sale
The mental image most people have - a dramatic breach of some big database - is increasingly out of date. The dominant source of fresh, working corporate credentials today is far more mundane and far more dangerous: infostealer malware.
An employee installs a cracked application, clicks a malicious ad, or opens the wrong attachment on a personal device. A lightweight piece of malware runs for a few seconds, scrapes every saved password, browser cookie, and session token, and quietly sends them to the operator. That bundle - called a "log" - is then sold in bulk. Because it comes straight from the victim's browser, the credentials are current and correct.
A leaked database is often old and hashed. An infostealer log is fresh, plaintext, and comes with the victim's active session cookies - which can let an attacker log in without needing the password or the second factor at all.
What dark-web monitoring can and cannot do
Monitoring services scan criminal markets, forums, and paste sites for your domains and credentials, and alert you when they appear. This is genuinely useful - but only if you are honest about what it is.
What it does well: it gives you early warning that a specific account is exposed, often before the attacker has used it, buying you time to reset and investigate. It also reveals patterns - a spike in exposures may point to a compromised device or a team being targeted.
What it cannot do: it cannot see everything (plenty of trade happens in private channels it never touches), and it cannot fix anything on its own. An alert that no one acts on is just a more expensive way of not knowing.
Dark-web monitoring is a smoke alarm. It is valuable precisely because of what you do in the ninety seconds after it goes off - and worthless if no one is home.
What to do when you are alerted
A credible exposure alert should trigger a small, practised routine:
- Reset the credential immediately and revoke all active sessions for that account - not just the password, the live tokens too.
- Assume the device is compromised. If the source is an infostealer, the password reset alone is not enough; the malware will simply steal the new one. The affected device needs to be investigated and cleaned or rebuilt.
- Check for reuse. People reuse passwords across work and personal accounts. One exposed credential often unlocks several doors.
- Look for what they already did. Review authentication logs for that account. Has it logged in from somewhere unusual? Have mail rules or MFA devices been added?
The controls that make a leaked password worthless
The real goal is not to prevent every credential from ever leaking - that is impossible. It is to make an individual leaked credential a non-event. Three controls do most of the work:
- Phishing-resistant multi-factor authentication. Passkeys and hardware security keys mean a stolen password on its own gets an attacker nowhere. This is the highest-value change most organisations can make.
- Short session lifetimes and re-authentication for sensitive actions. Because stolen session tokens bypass passwords entirely, limiting how long a token is valid - and forcing a fresh login for high-risk operations - closes the infostealer's favourite path.
- Device health checks. Requiring that logins come from a known, healthy, managed device stops credentials stolen from an unmanaged personal machine from working against corporate systems.
Treat exposure as a given. Monitoring tells you which credentials are out, and a small set of strong controls - phishing-resistant MFA, short sessions, device health - makes that exposure cost the attacker far more than it costs you.
If you want visibility into what is circulating about your organisation, and a plan for responding when it appears, that is the work our threat intelligence practice does every day.