Connect people

Inside a 24 Billion Credential Leak: Passwords, Exploits, and How Attackers Connected Them, Part 1

Share with your network!

In this 2-part blog series, we break down a June 2026 disclosure of 24 billion stolen credentials and what it means for security leaders. This blog, Part 1, covers how stolen corporate passwords lead to account takeover, and what security leaders can do to close that exposure window. Part 2 covers the other half of the same disclosure: how attackers are pairing stolen credentials with active vulnerability data to prioritize which systems to target next.

In June 2026, researchers at Cybernews found a publicly exposed database holding 24 billion stolen credential records, drawn from 36 sources and built largely from infostealer malware logs (Cybernews). The database went offline within days. The credentials did not.

Security leaders have seen headline credential counts before. What made this one worth a second look was not the number. It was the composition.

Why this database is different

Most mega-breach compilations are static: old passwords from old incidents, most useful against people who never rotated a credential after a 2019 or 2021 breach. This one skewed toward fresh infostealer output, meaning a significant portion of the records may still be valid, including active browser session cookies in some logs (Tech Times).

That distinction matters more than it sounds. A stolen password lets an attacker try to log in. A stolen session cookie lets an attacker skip that step entirely, stepping into an already-authenticated session. Multifactor authentication (MFA) stops the first scenario. It does very little against the second, because there is no login attempt for it to challenge.

Layer in password reuse, and the math gets worse. Independent survey research on credential-stuffing behavior consistently finds that a large majority of people reuse a password across more than one site. A password harvested from a personal account, a retail login, or a forgotten subscription becomes an immediate liability the moment it also unlocks a corporate mailbox or VPN.

The strategic gap: reactive hygiene isn't a strategy

The standard advice after a breach disclosure is familiar: check exposure, rotate passwords, enable MFA. All three are necessary. None of them address the actual moment of failure.

Password rotation is reactive by design. It responds to compromise that has already happened. It does nothing about the compromise that is happening right now, on a device where an infostealer is still running, or in a browser tab where someone is about to type a corporate password into a site that was never meant to receive it.

Security leaders who treat credential hygiene as a periodic campaign, a mandatory reset every 90 days, a phishing test every quarter, are optimizing for compliance, not for the actual attack chain. The attack chain does not wait for a scheduled reset. It exploits the gap between when a credential is exposed and when someone notices.

A framework for closing the exposure window

Three layers of control matter here, and most organizations have built two of them well.

Prevent delivery. Email and collaboration security stop most of the phishing and malicious-link attempts before they reach anyone. This is table stakes, and most mature security programs already invest here.

Detect compromise. Identity and session monitoring, anomalous login detection, and account takeover response catch the attacks that get through, usually by spotting behavior after an account is already compromised.

Close the gap in between. This is the layer most programs miss. Between the moment a phishing email bypasses a filter and the moment a compromised account starts behaving suspiciously, there is a specific, observable event: someone typing a valid corporate password into a site or app that was never authorized to receive it. Almost nothing in a typical security stack is watching for that moment specifically, because it happens in the browser, not in the mail flow and not in the identity provider's logs.

That is the actual strategic gap. Not "are passwords getting stolen" (they are, constantly), but "does anything in our environment see the moment a credential gets misused, before it becomes an account takeover." For most organizations, the honest answer is no.

What to do with this

Three actions translate this into practice, in order of leverage.

Stop treating session hijacking as an edge case. If your incident response plan ends at "reset the password," update it. Confirmed infostealer compromise should trigger session invalidation and device remediation, not just a credential reset.

Ask where in your environment credential misuse is actually visible. Most detection stacks answer for what happens after a login. Few can answer for what happens at the moment someone types a corporate password into an unsanctioned site. That answer, honestly assessed, tells you where the real gap is.

Build the point-of-entry layer, not just more downstream detection. Adding another tool that analyzes logins after the fact does not close this gap. Closing it requires visibility at the point where the credential is actually typed, before it becomes a valid login attempt anywhere.

Where Proofpoint fits

This is the exact gap Proofpoint built SSO Password Guard to close, as part of Proofpoint Collaboration Security Prime. It runs in the browser, establishes a secure reference to an organization's valid corporate credentials at the point of legitimate authentication, and then recognizes when that same credential is entered on an unsanctioned site or application. When it detects that moment, it surfaces real-time, in-context guidance and logs the event for the security team, giving analysts visibility into who was exposed, where, and how often (Proofpoint).

The point is not that this eliminates password exposure. Nothing does, as long as people can be phished and malware can steal browser data. The point is closing the specific window between exposure and takeover, the window every framework above is built to protect, with visibility that most security stacks simply do not have today.

The same June 2026 disclosure that exposed 24 billion credentials also contained something else: nearly 10,000 documents cross-referencing those credentials against known, actively exploited vulnerabilities. That is not a password story anymore. It is a targeting story, and it deserves its own analysis. Part 2 will cover what that means for vulnerability prioritization and exploit defense.

Learn more about Proofpoint SSO Password Guard and Collaboration Security Prime.