Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Underground services offer targeted credential searches from infostealer data

Threat actors are monetizing infostealer data by offering targeted credential search services on underground forums, allowing buyers to query for specific companies or account types instead of purchasing bulk logs. This service layer streamlines the process from credential theft to account takeover and corporate intrusion. While customer feedback indicates issues with data quality, this model increases the efficiency and targeting of attacks using stolen credentials.
Read Full Article →

Identity Underground services offer targeted credential searches from infostealer data June 22, 2026 Share By SC Staff Threat actors are increasingly transforming massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for specific companies, platforms, geographies, or account types, as reported by Bleeping Computer. Researchers from Flare analyzed 470 underground forum posts between January 2025 and June 2026, revealing a service layer that bridges infostealer infections and account takeover activities. These services function as credential brokers, monetizing vast amounts of stolen logs by offering targeted extraction, filtering, and formatting. Buyers can query sellers' databases for specific credentials instead of purchasing bulk data, with common output formats including URL:LOGIN:PASS and MAIL:PASS. The "search your target" market sits between credential collection by infostealers and their use for account takeover, fraud, or corporate intrusion. While the market overlaps with Initial Access Brokers (IABs), it is distinct. Customer feedback indicates a gap between advertised services and actual results, with issues like invalid or duplicated credentials being common. This evolving service model allows attackers to efficiently process stolen data into actionable intelligence for targeted attacks. Source: Bleeping Computer SC Staff Related Identity Attackers stopped fighting MFA. They are now targeting the enrollment step nobody monitors. Nik Kale June 22, 2026 Attackers are bypassing MFA by targeting enrollment and trust workflows. Identity Lessons from Identiverse 2026 Roy Katmor June 22, 2026 The big lesson: too many organizations still don’t understand how identity works inside their applications. Identity Identity is the foundation of trust. That makes it everyone’s problem. Heather Flanagan June 18, 2026 Identiverse 2026 highlighted identity’s expanding role in AI, trust and governance. Related Events Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Cybercast The industrialization of identity compromise On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article