Breaking
SecurityDeveloping Story

Infostealers Fuel 1.7B Credential Haul

Flashpoint logs 7.4M infostealer infections and 1.7B credentials stolen in H1 2026, up 27%.

··3 hours ago·4 min read
MacBook Pro turned-on
Photo by Michael Geiger on Unsplash

Infostealer malware has become an automated assembly line for credential theft, with researchers recording 7.4 million infected devices and 1.7 billion stolen credentials in the first half of 2026. That's a 27% jump in infections compared to the previous six months, according to threat intelligence firm Flashpoint.

The figures come from Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition, which draws on data from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure. The report paints a picture of a criminal ecosystem that no longer needs constant human attention to churn through stolen data.

The Rise of Autonomous Credential Engines

Flashpoint describes the infostealer landscape as a fully automated threat ecosystem. The report argues these systems operate as autonomous credential processing engines, ingesting and orchestrating data at machine speed, which fundamentally changes the lifecycle of a breach. The top three infostealer variants during this period were Vidar, StealC, and Lumma.

According to the report, threat networks are connecting these malicious agents directly to raw log supply chains. Once infostealer families harvest data, the systems immediately ingest records, parsing high-value metadata and automatically launching credential stuffing and active session tests across thousands of environments simultaneously. This automation means attackers can scale their operations without proportional increases in human effort.

“These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed. This evolution redefines the lifecycle of a breach,”

— Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition.

The report also highlights the proliferation of software vulnerabilities. Flashpoint tracked 21,667 vulnerability disclosures over the period, an 8% increase from the previous six months. Nearly one in five (19%) flaws came with public or functional exploit code, underscoring the ongoing challenge of patching known weaknesses.

Exploited Vulnerabilities and KEV Discrepancies

Despite the high number of disclosures, only a small percentage were actively exploited. Flashpoint's Known Exploited Vulnerabilities (KEV) catalog tracked 239 flaws undergoing active, in-the-wild exploitation during H1 2026. That's 191% more than the 82 flaws identified by the federal CISA KEV list, a discrepancy Flashpoint attributes to its broader visibility into dark web and threat actor infrastructure.

The vendor also claimed its team was able to isolate 6,808 vulnerabilities for customers before they were even published by the National Vulnerability Database (NVD). This early warning capability is critical for organizations looking to patch before exploits become widespread.

Malicious AI Activity Surges Underground

The underground markets supporting infostealers and vulnerability trading are being shaped by the rapid rise of AI threats. Flashpoint captured over 22 million posts related to malicious use of AI on illicit forums and closed-chat channels during the period.

With commoditized access to open-source AI, many threat actors are deploying tooling locally, reducing their reliance on public underground networks or specially built deployment services. However, for those that still need these services, cybercrime-trained AI offerings remain concentrated within rapid-delivery messaging platforms and open-source infrastructure.

“These platforms, such as Telegram, are commonly utilized by illicit communities, followed by Reddit, GitHub, and Pastebin,” the report continued. Such channels have effectively become a distribution layer for malware and social engineering scripts, Flashpoint noted.

Ransomware Victims Rise 45%

Ransomware activity also saw a significant uptick. Flashpoint counted 6,256 ransomware victims in the first six months of the year, a 45% increase from the previous six months. This trend is being driven by automation, low-cost initial access, and a mature ransomware-as-a-service (RaaS) ecosystem.

However, as has been noted elsewhere, fewer organizations are paying their extorters. This suggests that while attacks are more frequent, the financial incentives for attackers may be shifting, potentially leading to changes in tactics.

Key Figures from the Report

  • 7.4 million devices infected with infostealer malware in H1 2026 (27% increase from previous six months)
  • 1.7 billion credentials harvested via infostealers between January and June 2026
  • 21,667 vulnerability disclosures (8% increase), with 19% having public or functional exploit code
  • 239 actively exploited vulnerabilities in Flashpoint's KEV catalog (191% more than CISA's 82)
  • 6,808 vulnerabilities isolated before NVD publication
  • 22 million posts related to malicious AI use on illicit forums
  • 6,256 ransomware victims (45% increase from previous six months)

Implications for Defenders

The automation of credential theft and the rise of AI-powered attacks raise the stakes for organizations of all sizes. The sheer volume of credentials harvested means that even minor password reuse across accounts can lead to widespread compromise. Security teams should treat credential hygiene as a critical defense layer, regularly auditing for exposed credentials and enforcing multi-factor authentication where possible.

The discrepancy between Flashpoint's KEV list and CISA's suggests that relying solely on federal advisories may leave gaps. Organizations should consider supplementing official KEV feeds with commercial threat intelligence to get a more complete picture of active exploitation.

The increase in ransomware victims and the drop in ransom payments could lead attackers to pivot to other monetization methods, such as data extortion or selling access. This could mean that the next wave of attacks focuses more on data exfiltration than encryption, a shift that would require different defensive strategies.

As AI continues to lower the barrier for cybercrime, defenders must adopt similar automation to stay ahead. This suggests a future where machine-speed defenses are essential to counter machine-speed attacks.

#infostealer#credentials#flashpoint#ransomware#vulnerabilities#ai threats

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories