Noah MitchellVIEW PROFILE →
The quiet epidemic: how infostealer malware harvested 1.7 billion passwords in six months
Ransomware grabs the headlines, but the real engine of modern breaches is quieter and far more personal. Infostealer malware quietly siphoned 1.7 billion credentials in just six months of 2026. Here is how it works, who is behind it, and why your passwords are the target.
Ransomware gets the dramatic headlines, the locked hospitals and the seven figure demands, but as someone who believes every breach has a story, I want to tell you about a quieter and in many ways more personal threat that powers a huge share of those attacks, the humble infostealer.
An infostealer is a type of malware with one simple, ruthless job, to quietly harvest the credentials saved in your browser and apps, your passwords, your session cookies and your login tokens, and then ship them off to a criminal without you ever noticing that anything has happened.
How the theft actually works

The scale of this in 2026 is genuinely staggering, because security researchers recorded that infostealers harvested around one point seven billion credentials in just the first six months of the year, with three families known as Vidar, StealC and Lumma leading the pack as the most prolific offenders.
Behind that number sits a flood of infected machines, since researchers counted roughly seven point four million devices hit by infostealer malware in the first half of 2026 alone, a twenty seven percent jump from the previous six months, which tells you this problem is accelerating, not fading away.
What makes it so dangerous is precisely how ordinary it feels, because these programs do not smash their way in or encrypt your files with a scary ransom note, they simply slip in through a fake download or a malicious attachment, copy what they want, and quietly leave, often within seconds of infection.
From your laptop to the dark web
Once the credentials are stolen, they enter a fast and brutal marketplace, and one study found that the window between an infostealer infection and the stolen data appearing for sale on the dark web can be as short as forty eight hours, giving victims almost no time to react before the damage spreads.
The sheer volume of this trade is hard to imagine, but the discoveries speak for themselves, because in late January of 2026 researchers uncovered a database containing one hundred and forty nine million passwords, along with forty eight million Gmail accounts and six and a half million Instagram accounts, all bundled for criminal use.
It got even worse in June, when a single exposed database on an open server was found holding an astonishing twenty four billion records, and chillingly it had been enriched with live vulnerability data so that attackers could prioritise exactly which victims and systems were easiest to break into next.
Why this matters for you
The reason this ecosystem keeps growing is depressingly simple economics, because infostealers now have a very low barrier to entry and easy to use interfaces, which means even unskilled criminals can rent them and start stealing, turning identity theft into a booming and almost fully automated industry.
It is not only passwords at risk either, since one major report documented eighteen point one million exposed API keys and access tokens harvested from malware sources alone, the kind of digital keys that can unlock entire company systems long after a single employee laptop was quietly infected.
So what is the story here, and for me it is that the front line of security has moved from the corporate firewall to the everyday device in your hands, which is why the boring advice finally matters, use a password manager, turn on two factor authentication, and treat every unexpected download as the potential first page of your own breach story.






