Stolen Credentials Flood Markets as Attackers Target High-Value Enterprise Access
A surge in compromised credentials is devaluing personal data, while initial access broker listings for enterprise networks skyrocket, signaling a shift towards high-value targets.

The underground cybercriminal economy is undergoing a significant transformation, marked by an unprecedented flood of stolen credentials and a corresponding surge in the value of initial access to enterprise networks. In 2025, an estimated 2.86 billion compromised credentials entered criminal markets, driving down the prices of data like Social Security numbers and payment card information to commodity levels. This oversupply has fundamentally altered the economics of cybercrime, making it cheaper than ever for attackers to acquire vast quantities of personal data.
This abundance of stolen login information, often harvested by infostealer malware, is enabling attackers to bypass traditional security measures. Infostealers, distributed through phishing campaigns, malicious downloads, and fake software updates, excel at exfiltrating browser passwords, cookies, and session data. This collected information can then be used to impersonate legitimate users, bypass multi-factor authentication (MFA) through techniques like session replay, and gain access to cloud services, VPNs, and business accounts.
The impact of this credential flood is far-reaching. A single compromised username and password, once a significant security concern, now carries less weight due to the sheer volume of available data. Attackers can test old credentials across numerous services or leverage fresh logs containing crucial session cookies to take over accounts. The value of individual data points has plummeted, with SSNs fetching only $1-$6 and complete identity packages around $20-$100.
Conversely, the market for initial access to enterprise networks has seen a dramatic increase in value. Research indicates that average initial access broker listings across several forums surged from approximately $2,726 in 2024 to over $113,000 in 2025, representing a more than 4,000% increase. While this headline average is influenced by a small number of high-value listings, it clearly signals a growing demand for and premium pricing of access to large, revenue-generating organizations.
This shift indicates a strategic pivot by cybercriminals. Instead of focusing on low-value, high-volume data theft, threat actors are increasingly prioritizing direct access to corporate systems. This is particularly concerning for sectors like healthcare and finance, where sensitive data, such as patient records, cannot be easily reissued and commands higher prices on the black market. The rising prices for initial access serve as a critical warning sign of increased attacker interest and potential exposure.
Compounding the threat is the increasing sophistication of MFA bypass techniques. Stolen session cookies, which allow users to remain logged into services, are particularly valuable as they can enable attackers to replay an authenticated session, effectively sidestepping password prompts and MFA challenges. While this doesn't mean MFA has failed, it highlights the need to secure sessions post-authentication and move towards more robust, phishing-resistant MFA solutions.
Security leaders are advised to treat dark web pricing trends as an early warning system. By integrating this intelligence with exposure monitoring and incident response capabilities, organizations can better prioritize defenses. The core lesson from the 2.86 billion credential figure is that even cheap, readily available stolen data can serve as a gateway to extremely costly enterprise compromises, underscoring the need for continuous vigilance and adaptive security strategies.