Fortune 500 Credentials Leaked Every 100 Seconds

Corporate giants are appearing in dark web credential dumps, with nearly 10 million employee credentials exposed.

Password Hirun
istock.com/hirun

Findings from NordLayer reveal that credentials of Fortune 500 employees are being leaked on the dark web at an alarming rate, with the overall number of leaked credentials reaching nearly 10 million. The numbers are accelerating in 2026 — infostealer logs from this year show a new Fortune 500 credential appearing on the dark web every 100 seconds.

NordLayer analyzed findings from NordLayer Intelligence by NordStellar, a threat intelligence platform, which revealed that over 6.6 million unique corporate email addresses were exposed. The leaked credential sets analyzed in the research comprise combolists — re-purposed credentials obtained from data breaches and infostealer infections — and dated infostealer logs, the only sets that record when the data was collected. 

Analysis of infostealer logs shows that 130,000 Fortune 500 employee credentials were leaked on the dark web across roughly 147 days in 2026 alone. “The credential leaks that could be traced down to this year were harvested using infostealer malware,” says Andrius Buinovskis, cybersecurity expert at NordLayer. 

“Unlike ransomware, which typically targets specific organizations, infostealer campaigns are often more opportunistic, focusing on individual users rather than entire companies. This malware primarily hides within pirated software, gaming applications, fraudulent ads, fake captchas, and phishing emails.”

According to Buinovskis, infostealers scrape data from users’ devices almost immediately after infection, stealing any credentials or credit card details they come across. The browser is their preferred hunting ground for users’ log-in information — of the analyzed 2026 infostealer logs that record a source application, 99 percent point to browsers.

“Infostealer malware is specifically designed to extract credentials from built-in browser password managers. Because standard browsers store this sensitive data in predictable local directories, it is an easy target for malware,” explains Buinovskis. “The vulnerability of these industry giants proves that even the best corporate defenses can be bypassed by a single employee’s habits. In the face of opportunistic malware, the browser has become the enterprise’s weakest link.”

Buinovskis highlights five main measures companies should implement to build an infostealer-resistant cybersecurity strategy. 

  1. Secure the browser. Browsers are the main hunting ground for infostealers, yet consumer-grade browsers often lack robust security measures and the ability to enforce centralized security controls. To reduce the risk of users downloading infostealers, the browser must block malicious websites and prevent users from downloading infected files.
  2. Implement proper password hygiene. “Abandon built-in browser password managers and ensure that employees are not reusing the same passwords for different accounts,” says Buinovskis. “Password reuse can turn a single leak into a total compromise. If an employee uses the same login for every work application, they’re not just losing one password to an infostealer — they’re handing over the keys to every company resource at once.”
  3. Raise employees’ cybersecurity awareness. Cybersecurity is everyone’s responsibility — fostering this mindset is crucial to reduce user error where possible. When an employee understands how a single pirated file or a click on a link in a phishing email can compromise the entire company, it’s easier for them to shift from treating cybersecurity incidents like an IT problem and start seeing them as their own responsibility.
  4. Monitor the dark web for any company credential leaks. This enables companies to have a heads up as soon as possible, empowering them to quickly implement necessary remediation steps, like flagging compromised accounts, resetting passwords that appeared in the data leak, and keeping a close eye on any anomalies.
  5. Adopt a zero-trust approach to security to reduce the fallout. “A comprehensive cybersecurity strategy is essential to minimize the impact of a data breach,” says Buinovskis. “Instead of automatically trusting users and devices, companies should embrace a zero-trust mindset and treat every login attempt as a potential threat until proven otherwise. By verifying every move, organizations can effectively stop threat actors from infiltrating the network, preventing a simple credential leak from turning into a major security breach.”

 

More in Cybersecurity