Most breaches do not start with sophisticated exploits. They start with a valid username and password, bought for a few dollars, belonging to someone on your team. The uncomfortable reality: for almost any business more than a few years old, some employee credentials are already circulating. The question is not whether - it is whether you find out before someone uses them.
How credentials leak in the first place
Third-party breaches. An employee signs up to a SaaS tool, a forum, or a webshop with their work email and a password. That service gets breached. If the password was reused anywhere in your business - and password reuse remains stubbornly common - the attacker now has a working key.
Infostealer malware. This is the fastest-growing source. An employee's personal or work device picks up malware from a cracked software download, a fake browser update, or a malicious ad. The stealer silently harvests every saved browser password, every session cookie, every autofill entry - then uploads the lot. These "logs" are sold in bulk on Telegram channels and dark-web markets within hours.
Phishing. Old, but still effective. A convincing login page harvests credentials in real time, sometimes together with the MFA code.
Why session cookies make this worse
Infostealer logs do not just contain passwords - they contain session cookies. A valid session cookie lets an attacker walk straight into an account as the logged-in user, bypassing the password and multi-factor authentication entirely. This is how companies with MFA everywhere still get breached. If a device was infected, changing the password is not enough: every active session must be revoked too.
What to do this week - mostly free
- Check your exposure. Have I Been Pwned allows free domain-wide monitoring for verified domain owners. It will not show you infostealer logs or private market listings, but it is the right first step and costs nothing.
- Kill password reuse where it matters. Deploy a password manager and enforce unique passwords on the accounts that can hurt you: email, admin panels, cloud consoles, finance systems.
- Prefer phishing-resistant MFA. Any MFA beats none, but hardware keys and passkeys resist the real-time phishing that defeats SMS and push approval.
- Shorten session lifetimes on critical systems. Long-lived sessions are exactly what stolen cookies exploit. Where the platform allows it, require re-authentication for admin actions.
- Write down the response play before you need it. When a credential surfaces: reset the password, revoke every session, check the account's recent activity, and check what that account could reach. Four steps - but only fast if decided in advance.
Where continuous monitoring fits
The free tools cover public breach corpuses - data that is often months or years old by the time it is indexed. The gap is the fresh trade: infostealer logs sold within hours of infection, combo lists shared in private channels, your brand mentioned in an access broker's listing. Closing that gap requires continuous monitoring of the criminal ecosystem itself, which is a service category rather than a free tool - it is what our monitoring plans do, with verified alerts inside two hours.
Whether you build that visibility with us or elsewhere, the principle stands: assume some of your credentials are already out there, and build so that a leaked password alone is not enough to hurt you.