Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Full definition
Leaked credentials are username and password combinations exposed in a data breach or stolen by malware, circulating in criminal forums, messaging channels and dark web markets. They are the raw material for much of the initial access into companies.
The risk is multiplied by one habit: reuse. A corporate password also used on a personal service that suffers a breach ends up exposed next to the work email, ready for credential stuffing and account takeover. Time matters: the longer a company takes to learn about the leak, the wider the attacker's window.
Defense combines continuous monitoring of public breach data and the dark web to detect exposure within hours, automatic response with forced password change, and multi-factor authentication so a stolen credential is not enough on its own.
Related terms
Credential stuffing
Automated testing of credentials stolen from one service against many others. It works because people reuse passwords.
Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
Dark web monitoring
Continuous surveillance of breaches and criminal markets to detect exposed company credentials or data, and react in hours instead of months.
Infostealer
Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.