# Infostealers Drive Surge in Credential Theft with 1.7 Billion Compromised Accounts

*Published August 19, 2026*
*Source: [https://www.infosecurity-magazine.com/news/infostealers-17-billion/](https://www.infosecurity-magazine.com/news/infostealers-17-billion/)*

## Executive Summary

Flashpoint's report reveals a sharp rise in infostealer malware activity, compromising 1.7 billion credentials in the first half of 2026. This surge, along with increased vulnerability exploitation and ransomware incidents, highlights a growing risk of account takeovers and cyber threats.

## Article

In the first half of 2026, security researchers identified 7.4 million devices infected by infostealer malware, marking a 27% increase compared to the previous period. This data comes from Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition, which compiles information from dark web forums, illicit marketplaces, and other clandestine channels. The report highlights that hackers have managed to extract 1.7 billion credentials using infostealer malware from January to June 2026, with Vidar, StealC, and Lumma being the most prevalent variants.

Flashpoint's findings indicate that the infostealer threat has evolved into an automated ecosystem where these malware types operate independently, requiring minimal human intervention. They function as credential processing engines, ingesting and orchestrating data at high speed. Once data is harvested, these systems immediately parse and test credentials across numerous environments, enhancing the risk of account takeovers.

Additionally, Flashpoint tracked a significant increase in vulnerability disclosures, with 21,667 reported in the same period, an 8% rise from the previous six months. Of these, 239 vulnerabilities were being actively exploited, showing a dramatic increase compared to federal CISA's records. The company also noted the influence of AI on cyber threats, with over 22 million discussions on malicious AI use captured from illicit forums.

The report also observed a sharp rise in ransomware incidents, with 6256 victims reported, driven by automation and the growth of the ransomware-as-a-service model. While the frequency of attacks has increased, fewer organizations are succumbing to extortion demands.
