Flashpoint: attackers stole 3.2B credentials from organizations in 2024, up 33% YoY, 2.1B of which was via info-stealing malware infecting 23M hosts and devices
Inexpensive information-stealing malware surged in 2024, infecting 23 million hosts, according to Flashpoint. — Learn more.
Context & Ripple Effects
Credential theft was already becoming a preferred route into organizations: an earlier IBM report found attackers increasingly logging in with legitimate credentials and linked a sharp rise in info-stealing malware to that shift. Flashpoint's 2024 figures put a much larger scale on that credential-led access problem.
The finding also fits recent coverage in which malware-free intrusions dominated reported intrusions in 2024. Stolen credentials can support that pattern because the initial compromise may appear as a valid login rather than an overt malware event.
First-order effects
- Organizations whose hosts or devices were infected face a substantially expanded pool of exposed credentials, increasing the immediate need to identify compromised accounts and sessions.
- Info-stealing malware accounted for 2.1 billion of the 3.2 billion credentials reported stolen, making endpoint infections a primary source of credential exposure rather than a secondary concern.
Second-order effects
- Security teams will have to put more weight on controls that distinguish legitimate-looking but risky account use from routine login activity, as stolen credentials can bypass perimeter-focused defenses.
- The reported volume reinforces pressure on identity and endpoint security suppliers to connect device-infection signals with credential remediation; cloud-intrusion growth had already highlighted the expanding cloud intrusion problem.
Third-order effects
- If credential harvesting continues to scale, identity becomes an increasingly central security boundary: intrusion detection must account for abuse of valid access alongside malware detection.
- The combination of large-scale infostealers and malware-free intrusion reporting points toward a threat environment in which initial access is less visibly technical, raising the strategic value of continuous identity verification and endpoint hygiene.
The trend: This is one data point in the shift from breaking into networks to acquiring and abusing legitimate credentials at industrial scale.