The massive credential database reveals how infostealers are turning browsers into gateways to business systems.
Key takeaways
- The 24-billion-record database uncovered in June highlights the growth of the infostealer economy.
- Attackers increasingly target complete digital identities, not just passwords.
- Browsers now store valuable business assets that comprise complete identities, including tokens, sessions and cloud access.
- Organizations should focus on identity protection, session security and account takeover prevention.
- Layered security and managed detection capabilities can help reduce the impact of stolen credentials.
When news broke in June that researchers had uncovered a database containing 24 billion stolen records, the headlines were predictable. Yet another enormous credential leak, at a nearly incomprehensible scale. And as usual, a reminder to change your passwords.
But the sheer size of the database may be drawing attention away from the real significance of this discovery, which is that the data appears to come largely from infostealer malware, reflecting a broader shift in how attackers operate. Modern cybercrime is increasingly focused on harvesting complete digital identities rather than simply collecting credentials.
That shift has important implications for businesses because it changes where attacks begin and how defenders need to think about protecting users.
The browser is your most vulnerable endpoint
For years, cybersecurity strategies were built around a model in which attackers delivered malware, exploited vulnerabilities or tricked users into revealing credentials through phishing attacks. But today, many attacks start at the browser.
Modern browsers have become central hubs for both personal and business activity. They store passwords, maintain authenticated sessions, connect users to SaaS applications, remember cloud accounts, and hold the tokens that keep users logged in throughout the day. As a result, browsers increasingly contain everything an attacker needs to impersonate a legitimate user.
This is why infostealer malware has become such a valuable tool for cybercriminals. Rather than stealing a single password, attackers can harvest browser data, authentication tokens, session cookies, cloud credentials, and other information that provides immediate access to business systems.
In many cases, an attacker doesn't have to "hack" an account at all. The infostealer lets them simply inherit an authenticated identity.
Passwords are commodity data
The 24-billion-record database is also a reminder that passwords alone no longer hold the same value they once did. For years, attackers focused on stealing passwords using a variety of means. As the cybercrime economy matured, it became possible to simply buy large collections of breached passwords from other criminals.
Today, many cybercriminal operations are interested in something far more useful: complete digital identities that include browser sessions, SaaS access, VPN connections, and authentication tokens.
That evolution helps explain why credential theft continues to play a central role in ransomware, business email compromise and account takeover attacks. Recent threat intelligence reporting consistently identifies compromised credentials and infostealer activity as major sources of initial access for criminal groups.
This is also closely connected to the rise of account takeover attacks. Once attackers obtain access to a trusted account, they can move through an organization while appearing to be legitimate users. Traditional security controls designed to stop malware or suspicious logins may never be triggered because the attacker is operating with valid credentials and active sessions.
What this means for businesses
For organizations, especially those with small security teams, the important takeaway is that identity protection can no longer focus exclusively on passwords.
Businesses need to assume that some credentials are already exposed. The priority should be reducing the value of stolen information by adding layers of protection around identities and sessions.
That means strengthening multi-factor authentication, adopting phishing-resistant authentication where practical, monitoring for account takeover activity, and limiting the impact of compromised accounts through least-privilege access controls.
It also means paying closer attention to the browser itself. Security teams have traditionally treated browsers as applications running on endpoints. Increasingly, they should be viewed as security boundaries that deserve their own protections and monitoring.
This is particularly important as attackers continue to distribute infostealers through fake software updates, malicious browser extensions, cracked applications, and increasingly convincing AI-themed lures. A single infected device can provide cybercriminals with access to far more than a username and password.
Looking beyond the latest credential dump
Cybercriminals are no longer collecting credentials simply to crack accounts. They're harvesting identities, sessions and trusted access that can be sold, shared or used to launch follow-on attacks. The credential itself is becoming just one component of a much larger identity package.
For defenders, that means thinking beyond passwords and focusing on the broader identity ecosystem. The organizations that adapt first will be better positioned to stop account takeover attacks before they become ransomware incidents, business email compromise events or major breaches.
And while no single security control can eliminate the risk, a layered approach that combines strong identity protection, phishing defense, session security, and continuous monitoring can make it significantly harder for attackers to turn a stolen browser profile into a successful intrusion.
Managed detection and response services like Barracuda Managed XDR can also help lean IT and security teams identify suspicious account activity, investigate potential compromise and respond before stolen credentials or session data lead to a larger incident. The goal is not just protecting passwords. It's protecting the digital identities that increasingly power modern business.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit
