The Numbers Behind the Credential Gold Rush
The scale of the credential theft problem just got a lot clearer. New data from Flashpoint shows infostealer malware compromised 7.4 million devices in the first half of 2026. That is a 27% jump from the previous six-month window.
Think about what that means in practice. Each infected machine is a potential pipeline into corporate networks, personal accounts, and cloud infrastructure. The total haul? A staggering 1.7 billion credentials harvested between January and June alone.
The findings come from the company’s 2026 Global Threat Intelligence Report: Midyear Edition, which pulls data from deep web forums, illicit marketplaces, encrypted channels, and threat actor infrastructure.
Vidar, StealC, and Lumma Lead the Pack
Not all infostealers are created equal. Flashpoint identified three variants doing the heavy lifting: Vidar, StealC, and Lumma. These three families account for the bulk of the stolen credential volume.
What makes them so effective? Automation. The report describes a landscape that has morphed into a fully automated threat ecosystem.
“These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed,” the report states. “This evolution redefines the lifecycle of a breach.”
The implications are sobering. Once an infostealer family harvests data, the systems immediately ingest the records, parse out high-value metadata, and kick off parallel credential stuffing and active session testing across thousands of environments. Human involvement is almost an afterthought.
The Vulnerability Picture: More Disclosures, Fewer Exploits
Credentials are only part of the story. Flashpoint also tracked 21,667 vulnerability disclosures over the period, an 8% increase from the previous six months. Nearly one in five flaws (19%) shipped with public or functional exploit code.
Here is where the data gets interesting. Despite the high volume of disclosures, only a fraction saw real-world exploitation. Flashpoint’s Known Exploited Vulnerabilities (KEV) catalog logged 239 flaws under active, in-the-wild exploitation during H1 2026.
That figure is 191% higher than the 82 flaws on the federal CISA KEV list. The vendor also claims it isolated 6,808 vulnerabilities for its customers before the National Vulnerability Database (NVD) even published them.
The Patch Race Is Getting Faster
The gap between disclosure and exploitation is narrowing. Attackers are weaponizing known flaws at machine speed, which puts pressure on defenders to prioritize based on actual threat intelligence rather than CVSS scores alone.
Malicious AI Activity Surges on Underground Channels
The underground economy is being reshaped by AI, and the numbers are hard to ignore. Flashpoint captured over 22 million posts related to malicious AI use on illicit forums and closed-chat channels.
Many threat actors are now deploying AI tooling locally, thanks to commoditized access to open-source models. They no longer need to rely on public underground networks or specialized deployment services.
But for those who still need external services, the report points to a specific set of platforms. “Cybercrime-trained AI offerings remain overwhelmingly concentrated within rapid-delivery messaging platforms and open-source infrastructure,” the report notes. “These platforms, such as Telegram, are commonly utilized by illicit communities, followed by Reddit, GitHub, and Pastebin.”
These channels have effectively become a distribution layer for malware, social engineering scripts, and other attack tooling.
Ransomware Victims Up 45% — But Payouts Are Down
Ransomware activity continues to climb. Flashpoint counted 6,256 victims in the first six months of 2026, a 45% increase from the prior period. The growth is driven by automation, low-cost initial access, and a mature ransomware-as-a-service (RaaS) ecosystem.
Yet there is a counter-trend worth noting. Fewer organizations are paying the extortion demands. This mirrors broader industry observations that victims are increasingly refusing to negotiate, opting for backups and incident response instead.
The tension between rising victim counts and falling payout rates suggests the ransomware model is under pressure, even as it scales.
What This Means for Defenders
The takeaway from Flashpoint’s midyear data is clear: identity is now the primary attack surface. Infostealers are the entry point, and the automation behind them means credential stuffing campaigns can run at a scale that manual efforts could never match.
For organizations, the practical response involves a few priorities:
- Deploying robust multi-factor authentication to blunt the impact of stolen credentials
- Monitoring for session cookie theft, which bypasses traditional MFA protections
- Prioritizing patch management based on real-world exploit activity, not just severity scores
- Watching for AI-generated phishing and social engineering content on platforms like Telegram and Reddit
The infostealer ecosystem has industrialized. The question is whether enterprise defenses can keep pace with machines that never sleep.