Cybercriminals harvested 1.7 billion credentials through infostealer malware during the first six months of 2026, according to Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition. The threat intelligence firm documented 7.4 million devices compromised by infostealer infections over the same period, representing a 27% jump from the prior six-month span. The report gathered intelligence from deep and dark web forums, illicit marketplaces, encrypted communication channels, and infrastructure linked to threat actors.

The three most prolific infostealer variants were Vidar, StealC, and Lumma, according to the analysis. Beyond credential theft, researchers tracked 21,667 vulnerability disclosures over the six-month window, an 8% rise from the previous half-year. Public or functional exploit code accompanied nearly one in five flaws—19% of the total. Flashpoint's Known Exploited Vulnerabilities catalog identified 239 flaws undergoing active exploitation in the wild during the first half of 2026, which the vendor said was 191% more than the 82 flaws on the federal CISA KEV list. The company also reported isolating 6,808 vulnerabilities for clients before the National Vulnerability Database published them. On the ransomware front, the firm counted 6,256 victims in the first half of the year, a 45% increase from the six months before.

The infostealer landscape has evolved into "a fully automated threat ecosystem," the report stated. These systems operate as "autonomous credential processing engines capable of ingestion and orchestration at machine speed," requiring no constant human oversight. Threat networks now link these malicious agents directly to raw log supply chains, the authors explained. Once infostealer families capture data, the systems immediately ingest records, extract high-value metadata, and automatically launch parallel credential stuffing and active session testing across thousands of environments at once. The report also highlighted a surge in malicious AI activity, with researchers capturing over 22 million posts related to illicit AI use on underground forums and closed-chat channels during the period.

The automation behind credential theft reflects a broader shift in how cybercriminals operate at scale, according to the report. Many threat actors now deploy AI tooling locally using commoditized access to open-source models, eliminating their need for public underground networks or purpose-built deployment services. For those still relying on such services, cybercrime-trained AI offerings remain concentrated on rapid-delivery messaging platforms like Telegram, followed by Reddit, GitHub, and Pastebin. These channels have effectively become distribution infrastructure for malware and social engineering scripts. The rise in ransomware victims is similarly driven by automation, low-cost initial access, and a mature ransomware-as-a-service ecosystem, though the report noted that fewer organizations are paying their extorters.

The report's findings point to a threat environment where speed and automation have become central to criminal operations, with credential theft and vulnerability exploitation operating as interconnected supply chains rather than isolated attacks. As infostealers and AI-driven tools become more accessible and self-sufficient, the window between data harvesting and exploitation continues to shrink. Organizations face mounting pressure to adopt equally automated detection and response capabilities, though the sheer volume of credentials in circulation suggests defensive measures are struggling to keep pace with the scale of compromise. For enterprise leaders, the challenge now extends beyond preventing individual breaches to managing an environment where stolen credentials circulate as a permanent, renewable resource for attackers.