Skip to content
Fortune 500 Credentials Leaked at Alarming Rate

Fortune 500 Credentials Leaked at Alarming Rate

First seen 1 Oct 2026, 22:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 23:15 UTC
  • •Nearly 10 million Fortune 500 employee credentials leaked on the dark web.
  • •99% of stolen credentials were taken from web browsers via infostealer malware.
  • •Companies must assess their exposure and monitor the dark web for leaks.

A report from Nordlayer reveals that nearly 10 million employee credentials from Fortune 500 companies are available on the dark web, with a credential leaked every 100 seconds. The majority of these credentials, 99%, were stolen from web browsers through infostealer malware that targets saved logins. The report indicates that 6.6 million corporate email addresses are currently circulating, heightening the risk for organizations. Threat actors exploit these credentials to gain unauthorized access to corporate networks, often leading to ransomware attacks. Companies are urged to assess their exposure and implement measures to monitor the dark web for credential leaks and properly offboard employees. The findings highlight a significant vulnerability, particularly among midsize technology firms, where the risk is notably higher.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Nordlayer report published
Nordlayer reports that 9.96 million employee logins from Fortune 500 companies are on the dark web, with a credential leaked every 100 seconds.
Nordlayer
2026-10-01
Natlawreview article published
Natlawreview discusses the Nordlayer report, emphasizing the risks posed by credential leaks and infostealer malware.
Natlawreview

More articles in this cluster (2)

Common questions

How many credentials are affected?
Approximately 10 million employee credentials from Fortune 500 companies are reported to be on the dark web.
What is the primary attack vector?
The primary attack vector is infostealer malware that targets saved logins in web browsers.
What should companies do to mitigate this risk?
Companies should assess their exposure, monitor for credential leaks, and ensure proper offboarding of employees.