Enzoic: Attackers Have the Password. It Still Works.

Enzoic: Attackers Have the Password. It Still Works.

Infostealers Reshape Credential Theft, Exposing Gaps in Enterprise Security

A recent analysis by Enzoic CTO Ken O’Brien highlights how infostealers have transformed credential theft, accelerating the path from compromise to exploitation while leaving organizations vulnerable to undetected account takeovers. Despite widespread adoption of multi-factor authentication (MFA) and password screening, attackers increasingly bypass traditional defenses by leveraging valid but exposed credentials, often harvested from personal or unmanaged devices.

The Credential Exposure Crisis
The 2026 Credential Risk Report, based on a survey of 872 cybersecurity professionals, reveals that 85% of respondents identify compromised credentials as a primary attack vector, yet only 19% continuously monitor active credentials for exposure. Alarmingly, 66% of organizations that experienced authentication-related breaches reported attackers used valid credentials credentials that appeared legitimate because they were never flagged as compromised.

Infostealers have streamlined credential theft by harvesting URL, login, and password (ULP) datasets from infected machines, often personal devices outside corporate endpoint detection. These datasets, traded on criminal markets, include session tokens and authentication data, making stolen credentials more valuable and easier to exploit than traditional breach dumps. The report found that 73% of organizations discovered employee credentials in third-party breach data, dark web sources, or infostealer logs in the past year, while 39% found them in infostealer logs specifically. Despite this, 43% do not monitor infostealer channels or are unsure if they do.

Why Traditional Defenses Fall Short
Password screening at creation or reset common in most identity systems only checks if a password was compromised at that moment. It fails to account for subsequent exposure, such as when a credential appears in a new breach or infostealer dataset. The report notes that 49% of organizations screen passwords at creation or reset, but only 29% check against live breach intelligence in real time or daily, and just 19% automate remediation for exposed credentials.

MFA, while effective at reducing risk, does not eliminate credential exposure. 62% of respondents said their MFA deployments still allow password fallback, and attackers exploit techniques like adversary-in-the-middle attacks, push fatigue, or stolen session tokens to bypass MFA challenges. Only 13% believe MFA alone adequately addresses credential risk.

The Shift to Continuous Credential Defense
O’Brien argues that credential security must evolve from a one-time policy check to an ongoing identity operation. Traditional approaches complexity rules, password expiration, and banned-password lists focus on preventing weak passwords but fail to address the 4% of Active Directory accounts using already-exposed passwords, compared to less than 1% failing complexity checks. The problem has shifted: credentials are four times more likely to be for sale than weak.

Continuous Credential Defense combines real-time exposure monitoring, automated remediation, and integration with identity controls to close the gap between detection and containment. Enzoic’s approach, for example, screens passwords at creation and continuously checks active credentials against updated compromise data, triggering automated responses (e.g., forced resets, step-up authentication) without manual intervention.

Measuring Success: Time to Containment
The most critical metric for credential security programs is time from exposure to containment. The 2026 Verizon DBIR found that 73% of ransomware victims had a credential or infostealer leak in the prior year, with half compromised within 95 days of exposure. Reducing this window through automated monitoring and remediation directly limits attacker dwell time.

For organizations assessing their exposure, O’Brien recommends starting with an audit of active credentials against current compromise intelligence. Tools like Enzoic’s AD Lite can identify unsafe passwords, but the next step is defining a clear remediation process one that doesn’t rely on manual tickets or delayed responses. Six months into a program, progress should be measured by fewer exposed credentials persisting, faster containment times, and reduced reliance on manual intervention.

The takeaway: Authentication systems trust credentials by default until something tells them not to. The challenge is ensuring that "something" acts before the attacker does.

Source: https://www.cybersecurity-insiders.com/attackers-have-the-password-it-still-works/

Enzoic cybersecurity rating report: https://www.rankiteo.com/company/enzoic

"id": "ENZ1790246017",
"linkid": "enzoic",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'Enterprises'}],
 'attack_vector': 'Infostealers, Valid Credentials, Session Tokens',
 'data_breach': {'data_exfiltration': 'Yes (traded on criminal markets, dark '
                                      'web)',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (Personally Identifiable '
                                        'Information, Authentication data)',
                 'type_of_data_compromised': 'Credentials, Session tokens, '
                                             'Authentication data'},
 'description': 'A recent analysis by Enzoic CTO Ken O’Brien highlights how '
                'infostealers have transformed credential theft, accelerating '
                'the path from compromise to exploitation while leaving '
                'organizations vulnerable to undetected account takeovers. '
                'Attackers increasingly bypass traditional defenses by '
                'leveraging valid but exposed credentials, often harvested '
                'from personal or unmanaged devices.',
 'impact': {'data_compromised': 'Credentials (URL, login, password), Session '
                                'tokens, Authentication data',
            'identity_theft_risk': 'High',
            'operational_impact': 'Undetected account takeovers, Increased '
                                  'attacker dwell time',
            'systems_affected': 'Enterprise authentication systems, Active '
                                'Directory accounts'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes (ULP datasets, '
                                                    'session tokens)',
                           'entry_point': 'Personal or unmanaged devices'},
 'lessons_learned': 'Credential security must evolve from a one-time policy '
                    'check to an ongoing identity operation. Traditional '
                    'defenses like password screening and MFA are insufficient '
                    'without continuous monitoring and automated remediation. '
                    'The critical metric is time from exposure to containment.',
 'motivation': 'Credential harvesting, Account takeover, Data exfiltration',
 'post_incident_analysis': {'corrective_actions': ['Adopt continuous '
                                                   'credential defense',
                                                   'Automate remediation for '
                                                   'exposed credentials',
                                                   'Integrate real-time breach '
                                                   'intelligence with identity '
                                                   'controls',
                                                   'Reduce time from exposure '
                                                   'to containment'],
                            'root_causes': ['Lack of continuous monitoring for '
                                            'exposed credentials',
                                            'Over-reliance on one-time '
                                            'password screening',
                                            'MFA bypass techniques (e.g., '
                                            'adversary-in-the-middle, push '
                                            'fatigue, stolen session tokens)',
                                            'Infostealer logs and third-party '
                                            'breach data not monitored']},
 'recommendations': ['Audit active credentials against current compromise '
                     'intelligence',
                     'Implement continuous credential defense with real-time '
                     'exposure monitoring',
                     'Automate remediation for exposed credentials (e.g., '
                     'forced resets, step-up authentication)',
                     'Reduce reliance on manual intervention for credential '
                     'security',
                     'Measure progress by fewer exposed credentials persisting '
                     'and faster containment times'],
 'references': [{'source': 'Enzoic 2026 Credential Risk Report'},
                {'source': 'Verizon 2026 DBIR'}],
 'response': {'containment_measures': 'Automated remediation (forced resets, '
                                      'step-up authentication), Continuous '
                                      'credential monitoring',
              'enhanced_monitoring': 'Continuous credential defense, Real-time '
                                     'breach intelligence checks',
              'remediation_measures': 'Integration with identity controls, '
                                      'Real-time exposure monitoring'},
 'title': 'Infostealers Reshape Credential Theft, Exposing Gaps in Enterprise '
          'Security',
 'type': 'Credential Theft',
 'vulnerability_exploited': 'Exposed credentials, Lack of continuous '
                            'monitoring, MFA bypass techniques '
                            '(adversary-in-the-middle, push fatigue, stolen '
                            'session tokens)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.