Infostealers Harvest 1.7 Billion Credentials in First Half of 2026
Infostealer malware campaigns have harvested approximately 1.7 billion user credentials in the first six months of 2026, marking a significant increase in the threat posed by these automated credential-harvesting tools.

The first half of 2026 saw a dramatic surge in the activity of infostealer malware, with researchers recording 7.4 million devices infected—a 27% increase from the preceding six months. This escalating threat landscape culminated in the harvesting of an estimated 1.7 billion user credentials by malicious actors, according to Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition.
The report, which aggregates data from deep and dark web forums, illicit marketplaces, and encrypted channels, highlights the growing sophistication and automation within the infostealer ecosystem. The top three most prolific variants identified were Vidar, StealC, and Lumma, contributing significantly to the massive credential theft.
Flashpoint emphasizes that infostealer operations have evolved into fully automated threat ecosystems. These systems operate with minimal human oversight, functioning as autonomous engines capable of processing harvested credentials at machine speed. This automation redefines the lifecycle of a data breach, enabling threat actors to connect malicious agents directly to raw log supply chains for immediate ingestion and analysis.
Once data is harvested, these automated systems parse out high-value metadata and initiate parallel credential stuffing and active session testing across thousands of environments simultaneously. This rapid, automated process significantly amplifies the impact of each successful infection, allowing for swift exploitation of stolen credentials across a wide range of online services.
Beyond credential theft, the report also noted a continued proliferation of software vulnerabilities, with 21,667 disclosures tracked during the period—an 8% increase. Nearly one in five of these flaws had publicly available exploit code, though only a fraction were actively exploited. Flashpoint's own Known Exploited Vulnerabilities (KEV) catalog identified 239 flaws undergoing active exploitation, far exceeding the CISA KEV list's count.
The underground markets facilitating the trade in both infostealers and exploits are increasingly influenced by the rise of AI. Flashpoint observed over 22 million posts related to the malicious use of AI on illicit forums. Threat actors are leveraging commoditized open-source AI tools, often deploying them locally or through rapid-delivery messaging platforms like Telegram, which have become distribution layers for malware and social engineering scripts.
In parallel, ransomware attacks also saw a significant increase, with 6256 victims recorded in the first half of 2026, a 45% rise from the previous period. This surge is attributed to automation, low-cost initial access, and a mature ransomware-as-a-service (RaaS) ecosystem. However, the report also indicates a trend of fewer organizations choosing to pay ransoms.
The sheer volume of harvested credentials underscores the persistent and evolving threat posed by infostealer malware. The automation and integration of AI into these operations present a formidable challenge for cybersecurity defenses, demanding continuous adaptation and vigilance from individuals and organizations alike.