Introduction

Welcome to Part 2 of our series on external threat intelligence. In Part 1, we looked at how attacks begin outside your firewall, during a quiet reconnaissance phase.

This article, the second in our four-part series on managed threat intelligence, looks at how credentials leak, what happens after they do, and why watching for your own stolen identities is one of the highest value things a security program can do.

For most organizations, some employee passwords have already been exposed through past breaches and are circulating on criminal marketplaces. That is not cause for alarm on its own; it is a known and manageable condition, and this article looks at how to stay ahead of it.

Leaked credentials are not a sign that your team did anything wrong - It is the well-known security risk tied to people operating technology. People reuse passwords across dozens of accounts, and every year several major services get breached. People also often fall prey to widespread phishing campaigns, often undetected until a compromise occurs. When one of those breaches happens, the passwords inside it can get bundled up and sold. If an employee used the same password at work that they used on a hobby site that was breached in 2022, that work password is now part of the pile.

Attackers know this. It is why the modern break in often does not involve breaking anything. They do not pick the lock. They log in with a key someone already handed them.

How Credentials Leak in the First Place

Employee credentials reach criminal hands through a handful of well-worn paths, and none of them requires a sophisticated attack on your company. In fact, the single most common way attackers get in is simply by using credentials that are already valid — stolen credentials were the leading initial access vector in Verizon's 2025 Data Breach Investigations Report, ahead of both vulnerability exploitation and phishing. Those working credentials come from a few predictable sources.

  • Phishing — the most common and familiar path. An employee is tricked into entering their password, and sometimes their MFA code, on a fake login page, handing it over instantly. It remains the largest single way attackers harvest working credentials, and its real footprint is even bigger than it looks, because a phished password often shows up later simply as a "stolen credential" with its origin lost.
  • Third-party breaches. An employee signs up for an outside service with their work email and a reused password. That service is breached, and their credentials land in a stolen database — ready to be tried against your systems.
  • Infostealer malware — smaller today, but the fastest-growing. A quiet piece of software lands on a personal or work device and harvests saved passwords, browser data, and active login sessions before quietly deleting itself, often within minutes. (More on why this one is worth watching below.)

That last path is worth understanding in more depth, because it is growing fastest and reaches the deepest. Infostealers arrive through everyday means — a fake browser update, a malicious ad, a cracked application or game mod, a "click here to verify" captcha, or a phishing attachment. In 2026 research, Flare.io — Netrix's recommended external threat intelligence vendor — analyzed 18.7 million infostealer logs and found that enterprise identity exposure nearly doubled in two years, rising from roughly 6 percent of infections in early 2024 to about 14 percent by late 2025. Microsoft Entra ID credentials appeared in 79 percent of enterprise identity logs. And the window to react is short: industry research puts the average time between an infostealer infection and the first use of those stolen credentials at roughly 22 minutes.

The New Danger: Stolen Sessions, Not Just Passwords

For years the advice was simple. Turn on multifactor authentication, and a stolen password becomes far less useful. That advice is still correct. Requiring a second form of verification blocks the large majority of account takeover attempts, and every business should have it on.

But attackers have adapted, and the newer threat gets around passwords entirely. It is called session token theft.

When you log into a service and pass the multifactor check, the service gives your browser a small credential called a session token. That token is what keeps you logged in so you are not retyping your password every few minutes. It is convenience, and it is a target.

Infostealer malware captures these active session tokens right alongside saved passwords. An attacker who steals a valid token can load it into their own browser and enter the account already authenticated. The password does not matter, and the multifactor prompt never fires, because as far as the service is concerned the user has already passed it. In Flare’s dataset, more than 1.17 million logs contained both credentials and active session cookies, the pairing that lets an attacker bypass MFA.

This is why leaked passwords are only part of the picture. Exposed session tokens are worth watching too, because a stolen token is a live key that can skip the lock entirely.

What helps limit session theft

Monitoring for exposed tokens is one side of the equation; a few well-understood controls reduce the odds of a stolen session being useful in the first place. None of these is a silver bullet, but together they meaningfully raise the effort required. In our own incident work, these are the measures Netrix most often recommends:

  • Phishing-resistant MFA for your highest-risk users — executives, finance, IT admins, and legal. Methods like FIDO2 security keys, Windows Hello for Business, or certificate-based authentication are far harder to relay through a proxy than a push or one-time code.
  • Shorter session lifetimes and re-authentication for privileged and sensitive accounts. Reducing how long a token stays valid shrinks the window in which a stolen one is usable, at the cost of slightly more frequent sign-ins.
  • Conditional Access tied to device compliance. Requiring a managed, compliant, or hybrid-joined device means a token lifted onto an unmanaged machine is far less likely to work.
  • Disabling browser session persistence for sensitive roles, so sessions don't linger indefinitely on a device.
  • Retiring weaker factors such as SMS one-time codes where stronger options exist, and pairing all of it with ongoing user awareness on the phishing and fake-download tactics that deliver infostealers.

These are standard hygiene for a modern identity program, and most organizations already have the building blocks in a platform like Microsoft Entra ID. External monitoring complements them: the controls make a stolen token less useful, and monitoring tells you when one has been taken so you can revoke the session and reset the account before it's used.

What Happens After an Identity is Compromised

What happens next depends on how the identity was compromised in the first place. The path in largely determines the speed and the sequence of what follows — and each path has its own set of defenses that lower the odds of it succeeding.

After phishing — often used within minutes. When credentials are captured on a fake login page, modern phishing kits deliver them to the attacker almost instantly, frequently through automated Telegram bots. There is no waiting and no middleman. In many cases someone is logging in as the employee within minutes — reading email, sitting on the mailbox to study payment patterns, or quietly setting up forwarding rules before moving deeper. Because the login uses a real password, nothing looks obviously wrong. Common preventions: phishing-resistant MFA (FIDO2 security keys, Windows Hello, certificate-based auth) that can't be relayed through a fake page; Conditional Access tied to a compliant, managed device; user awareness on lookalike login pages; and fast session revocation when something looks off.

After a third-party breach — used later, at scale. When a reused work password surfaces in someone else's breach, it typically enters an economy before it is ever tried against you. Credentials are packaged into "combo lists," sold cheaply, and fed into automated credential-stuffing tools that test them across thousands of organizations at once. Exposure here can sit dormant for weeks or months before anyone attempts to use it. Common preventions: eliminating password reuse through a password manager and enterprise SSO; MFA on every external-facing system so a valid password alone isn't enough; and blocking known-breached passwords at reset so exposed credentials can't be re-set to the same value.

After an infostealer infection — sold fast, then exploited. Stealer logs move through a mature supply chain on a short clock. The credentials and session cookies harvested from a device surface on marketplaces and Telegram channels within roughly 24 to 72 hours, where automated bots begin testing them almost immediately. Worse, the log often includes an active session token — a live key that can bypass MFA entirely. Common preventions: EDR to catch the malware on the device; shorter session lifetimes and re-authentication for sensitive roles so a stolen token expires quickly; disabling browser session persistence; and treating any confirmed infection as a credential incident — reset passwords and revoke sessions from a clean device, not the infected one.

Across all three, one pattern holds: the person who steals an identity, the broker who packages it, and the attacker who ultimately exploits it are often three different parties. A single compromised identity is frequently used and sold at the same time.

When the first lines fail — layered defense can still prevent an attack. Every protection above lowers the odds, but none is perfect, and many companies don't have all of them in place to begin with. A user eventually clicks the convincing lure. A password gets reused despite the policy. A personal laptop outside your control picks up an infostealer. This is where external threat intelligence earns its place — a low-cost, layered defense against identity theft that assumes something eventually slips through. When a credential surfaces in a stealer log, a combo list, or a criminal marketplace, monitoring catches it in the quiet window between exposure and exploitation, while it is still just a warning sign. It turns a missed catch into a second chance: force the reset, kill the session, and close the door before anyone walks through it.

What Identity Exposure Management Does

Identity exposure management means continuously watching the clear, deep, and dark web for credentials, session tokens, and sensitive data tied to your people, then acting on what turns up.

Within Netrix Managed Threat Intelligence, built on the Flare Threat Exposure Management platform, this works as a managed loop rather than a raw alert feed.

The platform scans cybercrime forums, marketplaces, breach dumps, and infostealer logs for anything connected to your domains and your employees. When a match appears, a Netrix analyst in the Security Operations Center, or SOC, investigates it. They confirm whether the credential is current, judge how serious it is, and tell you what to do. Reset that password. Kill that session. Check that account for signs it was already used.

That human step matters more than it sounds. A stolen credential from a breach five years ago that an employee has since changed is noise. A fresh infostealer log containing a live session token for your finance director is an emergency. A raw tool treats both as an alert. A managed service tells you which is which, so your team spends its energy where it counts.

You also get something quieter and just as useful over time: a real picture of your identity risk. Which parts of your business keep showing up. Whether password reuse is a recurring pattern. Where an extra layer of protection would do the most good. That picture turns a stream of individual alerts into a security program that gets stronger each month.

Building Identity Into a Layered Defense

No single control stops identity-based attacks on its own. Each one an attacker can bypass — a password can be phished, MFA can occasionally be worked around, a device can be infected. Layered defense assumes that any one layer will eventually fail, and arranges the others to catch what gets through. Identity exposure monitoring is one of those layers, and it is strongest when it sits alongside the rest rather than standing in as a single alarm.

The layers reinforce one another:

  • Multifactor authentication, everywhere it can go — so a stolen password alone is not enough to get in.
  • Practical, regular training — so your team can spot the phishing and fake downloads that spread to infostealers in the first place.
  • Patched, protected devices — so malware has fewer ways to land and harvest credentials.
  • Identity exposure monitoring — so when a credential does slip out despite the rest, you learn about it while it is still just a warning sign.

Each layer covers the others' gaps. MFA blunts the credential that training missed; monitoring catches the exposure that MFA and patching could not prevent. That is the security-first mindset that runs through good managed IT — you are not just reacting to the credential that leaked today. You are steadily reducing the number that leak tomorrow, and making sure the ones that do get caught early.

Where to Go From Here

Stolen credentials are not a reflection of a careless team. They are a predictable byproduct of how the modern internet works. The businesses that stay safe are simply the ones that go looking for their exposed logins before an attacker does.

If you would like to know which of your credentials are already circulating, we can help you find out and walk through what to do about each one.

Talk to a Netrix Global team member about a free threat exposure assessment.
Common Questions

Frequently Asked Questions

Are my company's passwords really likely to be on the dark web?
Does multifactor authentication make credential monitoring unnecessary?
What is a session token, in plain terms?
How quickly do we need to act on a leaked credential?