Exposed Credentials Fuel Attacks, Organizations Lag in Defense, Enzoic Report Finds
A new report from Enzoic reveals that 73% of organizations found employee or contractor credentials in breach data, highlighting a persistent threat that attackers exploit for early access.

Organizations are increasingly aware of the risks posed by exposed credentials, yet their ability to monitor and respond to these threats continues to fall short, according to Enzoic's 2026 Credential Risk Report. The report found that a significant 73% of organizations discovered employee or contractor credentials within breach data, dark web sources, or infostealer logs over the past year. Alarmingly, nearly one in five organizations lack visibility into whether their own credentials have been compromised.
Compromised credentials often remain active long after their initial exposure, providing attackers with a critical window of opportunity. The report indicates that more than seven in ten companies experienced an authentication-related incident in the past year, with two-thirds of these incidents involving attackers successfully logging in with valid, albeit compromised, credentials. This underscores the critical need for proactive identification and remediation of exposed accounts before they can be exploited.
Infostealer malware has emerged as a primary vector for credential theft, harvesting not only passwords but also browser data, authentication tokens, and session cookies. Attackers can leverage these stolen session cookies to bypass multi-factor authentication (MFA) and gain access to accounts without triggering traditional security prompts. The Verizon Data Breach Investigations Report further highlights this threat, noting that half of ransomware victims with associated credential leaks or infostealer events experienced such an event within 95 days prior to the ransomware attack.
Despite the prevalence of credential exposure, many organizations still rely on outdated security practices. While credentials are often screened during creation or reset, they are frequently exposed later through phishing, third-party breaches, or infostealer malware. Continuous monitoring of active credentials remains limited, with fewer than 20% of companies implementing automated remediation for exposed accounts. This approach contradicts NIST SP 800-63B guidance, which advocates for password changes only when compromise is evident, rather than on a fixed schedule.
Even with the widespread adoption of MFA, it is not a panacea for credential exposure. Organizations continue to report attack techniques that can bypass or weaken MFA, such as adversary-in-the-middle attacks, users without MFA, password fallback mechanisms, and the use of credentials before an MFA challenge is triggered. Only 13% of organizations believe MFA adequately addresses credential exposure, with some admitting to not implementing credential monitoring due to a false sense of security provided by MFA.
The scope of credential monitoring also remains a concern. While workforce identity systems are often monitored, SaaS accounts, service accounts, machine identities, customer-facing systems, and third-party access receive less attention. External identities, which represent another significant attack surface, are also frequently overlooked, leaving organizations vulnerable to credential-based attacks.
Responsibility for credential security is often fragmented across multiple teams or lacks a clearly defined owner, leading to integration challenges and hindering efforts to prioritize automated credential abuse prevention. As organizations invest in credential security solutions like expanded MFA, passwordless authentication, and identity threat detection and response (ITDR), a more unified and strategic approach to managing and protecting credentials is vital.