Estimated reading time: 6 minutes
In June, a stream went live on IGN’s official Twitch channel. Nobody at IGN had started it. A self-identified white hat hacker had taken over a senior video director’s Restream account. He launched the broadcast himself. The account’s credentials had been sitting in an infostealer dump for more than a month before anyone used them. No new hack was needed on the day of the stream. The login had already been stolen, and it was still good.
“Removing the malware ends the infection, but not the exposure,” said Darren James, senior product manager at Specops Software. The stolen data outlives the cleanup that follows it.
That gap between theft and use is the infostealer credential exposure problem Specops Software’s newest research sets out to explain. The IGN stream was a stunt with no lasting damage. The same pattern, run by attackers instead of white hats, produced one of 2026’s larger breach stories.
Mandiant traced accounts used in the 2024 Snowflake attacks back to credentials exposed years earlier. Some traced to an infection from November 2020. At least 79.7% of those accounts ran on credentials exposed before the breach, Mandiant found. The malware itself had been gone for years. The compromised passwords never changed.
How An Infostealer Attack Unfolds
Infostealer malware needs only a short window on an endpoint. It searches browsers, local folders, and developer tools for saved passwords, session cookies, autofill data, API keys, and cloud credentials. Once that data leaves the device, removing the malware does not make it disappear.

Families including Lumma, RedLine, Vidar and Raccoon all work to the same end. Development now mirrors a subscription software business. Operators sell access on criminal forums for as little as $120 a month. The resulting logs change hands from around $10, rising past $100 for credentials judged high value.
Enforcement action shows the scale. Australian authorities charged two men in August over their alleged role in TeamPCP. The group is linked to supply chain attacks on GitHub projects. The campaign potentially affected more than 1,000 organizations. It exposed more than 500,000 credentials, the Australian Federal Police said.
Specops has added more than 46 million newly compromised passwords to its Breached Password Protection service. This is the credential exposure figure the update tracks. A further 5.4 million went onto the express blocklist used by Specops Password Auditor. The count measures passwords new to the database. That is different from passwords taken in new infections, James told Cyber Insurance News & Information (CINI). The breakdown by infection age has not been published. “Dating a credential to a particular infection gets harder once logs have been resold and merged into combined sets, which is part of why an old password is still worth buying. ”
“An infostealer like Lumma or RedLine only needs a short window on a machine to steal passwords, session cookies and authentication tokens,” James said. “If an attacker has a valid session, MFA alone may not stop them.”
Credential Exposure Reaches Past The Password
A password reset closes the compromised password. It does not revoke a session or rotate a stolen API key.
“A stolen session cookie may still let an attacker in until the session is revoked or expires,” James said. Specops Password Protection checks Active Directory passwords against known breaches. A separate control, Specops Device Trust, can block a stolen session cookie from replaying on an untrusted device. “[Organisations] still need to revoke stolen sessions and rotate API keys and cloud credentials with the services that issued them,” James told CINI. This kind of credential exposure runs well past the password field, as the IGN stream hijack showed above.
What Insurers Can Check Beyond MFA
“MFA and endpoint protection do not tell an insurer what happens after an infostealer has taken passwords or session cookies,” James said. He named four questions for insurers to ask instead.
- Does the organization continuously check for compromised passwords?
- Does it verify callers before service desk resets?
- Does it restrict access from untrusted devices?
- Does it have a process to revoke stolen sessions and tokens?
Evidence should follow the same shape.
- How quickly did the organization change exposed passwords?
- Do records show suspicious reset attempts?
- Do logs show access blocked from untrusted devices?
- Do records show session revocation, not just password changes?
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
What Claims Investigators Need To Preserve On Credential Exposure
Stolen credentials can surface in an attack months or years after the original infection. That gap creates a specific evidence problem. Claims investigators need to separate the initial theft from the later unauthorized access.
James recommends preserving endpoint telemetry from the original infection. That means what the malware ran and when. Hold the forensic image rather than reimaging the device. Add password change history from the directory. Add sign-in logs from the identity provider. Those logs should show which sessions and tokens were issued, and from where.
Retention is the difficulty. Log retention windows are typically far shorter than the multi-year gaps Mandiant found in the Snowflake attacks. James recommends routing logs to a SIEM instead. Logs held there sit away from the affected systems. They can be kept for as long as compliance requires.
“Once a password is in circulation, its age matters far less than whether it’s still in use in your directory,” James said.
Cyber Insurance News covered Specops’ breached password research in May, when the database held 6.4 billion compromised passwords. It has grown past that mark.
FAQ – Infostealer Credential Exposure
What is an infostealer?
Malware that collects saved passwords, session cookies, autofill data, API keys and cloud credentials from an infected device, then sends them to an attacker’s server. Removing the malware does not remove the stolen data.
How long do stolen credentials stay usable?
Mandiant found accounts used in the 2024 Snowflake breaches running on credentials exposed as early as November 2020. Once a credential is in circulation, its age matters less than whether it is still valid.
Does changing a password close the exposure?
Not fully. A password reset closes the password but does not revoke an active session or rotate a stolen API key. Attackers can still use a valid session cookie until it is revoked or expires.
What should insurers ask beyond MFA and endpoint protection?
Whether the organization continuously checks for breached passwords, verifies callers before service desk resets, restricts access from untrusted devices, and can revoke stolen sessions and tokens, with evidence that each control operates in practice.
What evidence helps claims investigators after an infostealer incident?
Endpoint telemetry and a forensic image from the original infection, password change history, and identity provider sign-in logs. Routing logs to a SIEM extends retention past the typical endpoint log window.
Related Cyber Insurance Posts
- CRC Specialty Puts Cyber, Tech E&O And Professional Liability On One Form
- Credential Theft Cyber Insurance: What 2.86 Billion Stolen Credentials Mean For Underwriters(Opens in a new browser tab)
- State of Cybercrime “Unprecedented” Sophistication: KELA Report(Opens in a new browser tab)
- Blumira Adds Microsoft 365 Threat Response Feature for Faster User Lockouts(Opens in a new browser tab)
- 16 Billion (with a “B”) Log-in Credentials Pilfered by “Infostealers:” Cybernews(Opens in a new browser tab)