Also on CyberFence: CyberFence Breach Monitor for continuous breach alerts · run a free breach check on your email .
In July 2026, Cybernews researchers reported a massive credential dump containing 24 billion records — usernames, passwords, and account data aggregated from countless breaches, infostealers, and credential stuffing sets accumulated over years of active cybercrime operations. One month before that, the same team had documented 16 billion exposed credentials in a separate collection. Both datasets circulate freely in criminal forums, ready to be used in automated attacks against any account associated with your email address.
These numbers are so large they become abstract. To understand what they actually mean for your personal and professional accounts — and what you can do about it — it helps to understand how stolen credentials move from breach databases to active attacks.
Where These Numbers Come From
The 24 billion and 16 billion figures represent aggregated credential collections, not single breaches. They're compiled from multiple sources:
- Historical breach databases — credentials stolen in past breaches at major companies (LinkedIn, Adobe, Dropbox, Yahoo, and thousands of smaller sites) that were shared or sold and have since been repackaged into combined collections
- Infostealer malware harvests — malware like Redline, Vidar, and Racoon Stealer runs on infected devices and extracts browser-saved passwords, cookies, and credentials directly from the infected machine, then uploads them to criminal infrastructure. This is particularly dangerous because it captures active session cookies, not just stored passwords.
- Credential stuffing attack logs — attackers run automated login attempts against websites using known credential pairs. When a login succeeds, the valid credential is noted and saved. These "combo lists" of confirmed-working credentials are especially valuable and circulate as premium sets in criminal forums.
- Phishing harvests — fake login pages, fake software, and social engineering campaigns that capture credentials directly from users who believe they're logging into legitimate services
The key point about the 2026 datasets: they're not primarily old, stale data. A significant portion comes from infostealer harvests conducted in 2025 and 2026 — meaning credentials from devices infected in the past year. Your accounts could be in these collections even if you've never knowingly been part of a major breach.
How Credential Attacks Actually Work
Understanding the attack chain helps explain why credential exposure is dangerous even when you haven't been directly targeted.
Credential Stuffing
This is the most common automated credential attack. Attackers take a list of email/password pairs from breach databases and run them against hundreds of websites simultaneously using automated tools. Most people reuse passwords across multiple sites. If your password from a 2020 LinkedIn breach matches your current email password, bank login, or healthcare portal, a credential stuffing attack will find and exploit that match.
The scale is industrial: automated tools can test millions of credential pairs per day against a single target site. The success rate doesn't need to be high — even a 0.1% hit rate against a 10 million record credential list produces 10,000 compromised accounts.
Account Takeover via Session Tokens
Infostealer malware doesn't just harvest stored passwords — it steals browser session cookies, which are the authentication tokens that keep you logged into sites without re-entering passwords. A session token for Gmail, Microsoft 365, or a banking site can be replayed by an attacker to access those accounts immediately, bypassing password authentication and often bypassing MFA as well (since the session is already authenticated).
This is the specific mechanism that makes infostealer infections so dangerous and so valuable to credential markets: they provide immediate, authenticated access rather than just passwords that may have already been changed.
Business Email Compromise (BEC)
When attackers obtain valid corporate email credentials — particularly Microsoft 365 or Google Workspace accounts — they don't always announce themselves. They may silently monitor email traffic for weeks, learn about pending wire transfers, collect confidential business information, or set up forwarding rules to receive ongoing intelligence. The FBI reported $2.9 billion in BEC losses in 2025 — it's the highest-value cybercrime category by financial impact, outpacing ransomware.
Dark Web Resale and Targeting
Credentials don't just circulate in bulk collections. Verified working credentials for high-value targets — corporate VPNs, financial institutions, healthcare portals, government systems — are sold individually or in small batches at premium prices. An authenticated login to a healthcare provider or financial institution's employee portal can sell for hundreds of dollars in criminal markets.
Check If Your Email Is Already Exposed
CyberFence Breach Monitor continuously scans known breach databases for your email addresses. Find out if your credentials are already circulating — before attackers use them.
Check Your Email →Why Multi-Factor Authentication Isn't Enough Anymore
MFA remains an essential defense — it blocks the majority of automated credential stuffing attacks. But 2026 has produced significant evidence that MFA is being systematically circumvented by more sophisticated attacks.
The most recent documented example: in July 2026, security researchers disclosed two phishing kits — Jalisco and OmegaLord — specifically designed to defeat Microsoft 365 MFA. These adversary-in-the-middle (AiTM) phishing kits work by proxying the real Microsoft login process: the victim enters their credentials and MFA code on a convincing fake page, the kit relays the authentication to Microsoft in real time, captures the resulting session token, and delivers it to the attacker. The MFA was completed legitimately — but the session token now belongs to the attacker.
This isn't theoretical. AiTM phishing is the primary mechanism behind the wave of Microsoft 365 compromises that drove $2.9 billion in BEC losses. The technique bypasses both password protection and MFA, leaving organizations that rely on these two controls alone significantly exposed.
The defense against AiTM phishing is not a better password or a different MFA method — it's blocking the malicious domains before the phishing page loads. That's exactly what Web Shield DNS filtering does.
The Infostealer Problem
Of all the threat categories driving 2026 credential markets, infostealer malware represents the fastest-growing and most difficult to detect. Unlike phishing, infostealers don't require the victim to take any obvious action — they're delivered via malicious downloads, fake software, game mods, pirated content, and malicious ad networks. Once installed, they run silently and exfiltrate credentials before most security tools detect anything.
What makes infostealer data particularly dangerous in credential markets:
- Passwords are harvested from browser vaults, including passwords the user hasn't recently typed
- Session cookies provide immediate access to authenticated accounts
- The harvest includes every saved credential on the device — not just one service
- Crypto wallet seeds and private keys are specifically targeted
- Corporate credentials (VPN, email, internal apps) are extracted alongside personal accounts
Web Shield DNS filtering intercepts infostealer connections at the DNS layer — blocking the command-and-control domains that infostealers use to exfiltrate data and receive instructions. If an infostealer can't reach its C2 server, harvested credentials can't be transmitted to the attacker.
What Breach Monitoring Actually Does
Breach monitoring services — including CyberFence Breach Monitor — scan known breach databases and credential collections for your email addresses and notify you when your credentials appear in newly surfaced datasets. The key word is "known": monitoring services work from disclosed breaches and leaked collections that have surfaced on the dark web.
The value of monitoring is time: most credential abuse happens weeks or months after a breach, once credentials circulate through criminal markets and reach automated attack tools. Monitoring gives you the opportunity to change affected passwords before the attack window opens.
Monitoring is not a prevention layer — it's a detection layer. It tells you what has already happened, so you can respond. Prevention requires stopping credentials from being stolen in the first place (phishing protection, infostealer blocking) and limiting the damage if they are stolen (unique passwords per site, MFA that isn't vulnerable to AiTM).
The Layered Defense That Actually Works in 2026
Given the current threat environment — 24 billion exposed credentials circulating in criminal markets, AiTM phishing bypassing MFA, infostealers running silently on consumer devices — a single security control is insufficient. The combination that addresses the full attack chain:
1. Password manager with unique credentials per site — eliminates the reuse problem that makes credential stuffing profitable. If every site has a unique password, a breach at one service exposes exactly one account. The attacker's credential lists are useless against you.
2. Phishing-resistant MFA where available — FIDO2/WebAuthn hardware keys or passkeys are resistant to AiTM attacks because the authentication is bound to the legitimate domain. Software TOTP is better than nothing but vulnerable to AiTM. Hardware keys are the gold standard for high-value accounts.
3. DNS-layer phishing protection — CyberFence's Web Shield blocks malicious domains at the DNS level, stopping phishing sites and AiTM proxies before they load. When the fake Microsoft 365 login page never loads, the AiTM attack never starts.
4. Network encryption via VPN — CyberFence's AES-256-GCM encryption prevents network-layer credential interception, particularly relevant on public Wi-Fi where session token theft and credential-in-transit attacks occur. Also prevents DNS queries from being hijacked to serve phishing redirects.
5. Breach monitoring — CyberFence Breach Monitor provides the detection layer: alerting you when your credentials surface in known breach datasets so you can rotate passwords before the attack window opens.
These five controls address different parts of the attack chain. Omitting any one of them leaves a gap that attackers will find and exploit.
What to Do Right Now
Given the scale of credential exposure documented in 2026, the practical starting point is checking your current exposure:
- ✅ Check your email addresses against breach databases at cyberfenceplatform.com/tools/breach-check — this is the same data criminal forums use
- ✅ For any account where your password appeared in a known breach, change the password immediately and don't reuse it
- ✅ Enable MFA on every account that supports it — prioritize email, banking, and work accounts
- ✅ For your most critical accounts (primary email, financial accounts, work email), consider a hardware security key
- ✅ Install CyberFence to activate Web Shield DNS filtering — the prevention layer that blocks phishing domains and infostealer C2 connections before credentials are stolen
- ✅ Enable CyberFence Breach Monitor on your personal and professional email addresses for ongoing detection
The 24 billion figure isn't a distant statistical abstraction. It represents credentials associated with real accounts — accounts whose owners may not know they're in a criminal database. The difference between being in that database and having your accounts compromised is whether the accounts have unique passwords, whether phishing domains are blocked before you interact with them, and whether you find out about exposure before attackers do.
Start Monitoring Your Email Addresses Today
CyberFence Breach Monitor scans continuously and alerts you the moment your credentials appear in a new breach dataset. Start protecting your accounts — start your free trial.
View Plans →Want to go deeper? Read how CyberFence Breach Monitor works , the free CyberFence breach check tool , or the CyberFence password strength tool .