Skip to main content
Emerging ThreatsMalware & Ransomware

Infostealers Harvest 1.7 Billion Credentials in Six Months

Server room interior with technicians and rows of computer equipment.

“These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed. This evolution redefines the lifecycle of a breach,” the Flashpoint report explained.

Flashpoint's H1 2026 numbers

Flashpoint, in its 2026 Global Threat Intelligence Report: Midyear Edition, documented a sharp uptick in identity-focused cybercrime across the first half of 2026. The company recorded 7.4 million devices infected with infostealer malware — a 27% increase from the prior six months — and concluded that hackers harvested 1.7 billion credentials between January and June 2026. The report also logged 21,667 vulnerability disclosures over the period (an 8% increase), and counted 6,256 ransomware victims in H1 2026 — a 45% rise from the previous six months.

Vidar, StealC and Lumma lead the credential harvest

Flashpoint identified Vidar, StealC and Lumma as the three most prolific infostealer variants driving the credential haul. The company framed the infostealer landscape not as a collection of stand-alone malware families but as a fully automated threat ecosystem: harvested data moves rapidly from endpoint to illicit markets and attack tooling without ongoing human intervention.

How automated credential processing engines operate

According to the report, modern infostealer systems perform several chained tasks at machine speed. Once an infostealer family harvests data, systems immediately ingest records, parse out high-value metadata and automatically initiate parallel credential stuffing and active session testing across thousands of environments simultaneously. Flashpoint described these platforms as connecting “malicious agents directly to raw log supply chains,” turning what used to be manual post-compromise work into an automated pipeline that can expand the scope and speed of breaches.

Malicious AI activity and distribution channels: Telegram, Reddit, GitHub and Pastebin

Flashpoint tied the underground evolution to a surge in malicious AI activity. Over H1 2026 the company captured more than 22 million posts related to the malicious use of AI on illicit forums and closed-chat channels. It noted that commoditized access to open-source AI enables many actors to deploy tooling locally, reducing reliance on public underground networks or paid deployment services. For those that still use shared channels, cybercrime-trained AI offerings are concentrated on rapid-delivery messaging platforms and open-source infrastructure — platforms Flashpoint explicitly names as Telegram, followed by Reddit, GitHub, and Pastebin. The report said these channels have become a distribution layer for malware, social-engineering scripts and other tools.

Vulnerabilities, KEV counts and ransomware dynamics

Flashpoint found that nearly one in five disclosed flaws (19%) during H1 2026 came with public or functional exploit code. Despite the large volume of disclosures, only a smaller subset was observed in active exploitation: Flashpoint’s Known Exploited Vulnerabilities (KEV) catalog tracked 239 flaws undergoing in-the-wild exploitation in H1 2026 — a figure the company says is 191% higher than the 82 flaws listed on the federal CISA KEV list. Flashpoint further asserted that its team isolated 6,808 vulnerabilities for customers before those flaws were published to the National Vulnerability Database (NVD). On the extortion front, Flashpoint linked the increase in ransomware victims to automation, low-cost initial access and a mature ransomware-as-a-service ecosystem, while noting that fewer organizations are paying extorters.

What this means for technologists, policymakers, and end users

  • Technologists and security teams: Expect credential theft to arrive pre-parsed and attack-ready; Flashpoint’s description of automated ingestion and parallel credential stuffing suggests defenders will face faster, higher-volume testing of stolen records.
  • Policymakers and regulators: The gap Flashpoint reports between its KEV catalog (239 flaws) and the federal CISA KEV list (82 flaws) highlights differing views of what is actively exploited and when it is cataloged — a coordination and disclosure challenge for policy and vulnerability-management processes.
  • End users and organizations: The scale of the reported credential harvest — 1.7 billion credentials and 7.4 million infected devices — underlines that account compromise remains a primary attack vector; stolen records are being converted into live attacks at machine speed.

Flashpoint’s midyear snapshot draws a single, stark line through the first half of 2026: credential theft has industrialized, AI-enabled tooling is reshaping underground distribution, and the tempo of exploitation and extortion has risen. The concrete questions left by those facts are operational: who will detect credential stuffing at machine speed, how quickly will exploited flaws be identified and shared across catalogs, and which controls can blunt an automated supply chain that turns stolen logs into live intrusion attempts within minutes?

https://www.infosecurity-magazine.com/news/infostealers-17-billion/