nordlayer.com Fortune 500 Credentials Leaked at Alarming Rate
Article Content
- •Nearly 10 million Fortune 500 employee credentials leaked on the dark web.
- •99% of stolen credentials were taken from web browsers via infostealer malware.
- •Companies must assess their exposure and monitor the dark web for leaks.
A report from Nordlayer reveals that nearly 10 million employee credentials from Fortune 500 companies are available on the dark web, with a credential leaked every 100 seconds. The majority of these credentials, 99%, were stolen from web browsers through infostealer malware that targets saved logins. The report indicates that 6.6 million corporate email addresses are currently circulating, heightening the risk for organizations. Threat actors exploit these credentials to gain unauthorized access to corporate networks, often leading to ransomware attacks. Companies are urged to assess their exposure and implement measures to monitor the dark web for credential leaks and properly offboard employees. The findings highlight a significant vulnerability, particularly among midsize technology firms, where the risk is notably higher.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
How many credentials are affected?
What is the primary attack vector?
What should companies do to mitigate this risk?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…