A compromised employee’s device allows a stealer to infiltrate, completing its task in a matter of minutes This article explores infection enterprise breach. . A ransomware affiliate purchases it.

Flare’s 2026 State of Enterprise Infostealer Exposure report, which analyzed 18.7 million stolen credentials logs, found the average time from personal-device infection to enterprise breach to be seven days. The Numbers Behind the Shift Flashpoint recorded more than 1.8 billion credentials stolen during 2025 from roughly 5.8 million infected devices, which the firm described as an 800% increase over the previous period. The market has shown that takedowns actually increase the supply: after the LummaC2 disruption in mid-2025, the share migrated quickly to Rhadamanthys, then to Vidar and ACRStealer, which vendors remained among the most active families in 2026.

The shared admin credential in a Confluence page, the API key in a .env file committed three years ago, the router password in an ops runbook—these are the credentials that never rotate and never expire. Common failure points include browser extensions: if autofill is slower or less reliable than native browser functionality, users bypass it within weeks, and the policy that disabled browser saving simply results in no logging. Both cloud and on-premises editions of mature business password manager platforms reach production in weeks; the integration with your identity provider and changing engineer habits are what determine the timeline.