← Back to Insights
Cyberattack Case

Stolen Credentials: The Break-In Started Months Ago

Stolen Credentials: The Break-In Started Months Ago

On 22 August a Swiss firm with a few dozen staff appeared on a ransomware group's leak site. Next to the name sat a note that says more about how this happened than the extortion does: the firm's VPN credentials had been sitting in a traded collection for some time. The break-in did not start this week, it started the day someone somewhere lifted those credentials, and the stretch in between is what an organisation can still act on.

How many working credentials are in circulation right now?

Flashpoint counted roughly 1.7 billion credentials harvested by infostealer malware between January and June 2026, spread across 7.4 million infected devices, 27 percent more than in the previous six months (Infosecurity Magazine, 17 August 2026). These are not guessed passwords, they are working logins with the username attached.

Why does a security update not close this?

On 18 June 2026 Bitsight published an analysis of a campaign it calls FortiBleed: verified administrator and VPN credentials are circulating for more than 73,000 internet-facing FortiGate firewalls across 194 countries, around half of every publicly reachable device of that type. No new vulnerability sits behind it, only material from earlier compromises. CISA advised the same day that organisations terminate all active VPN and administrative sessions and reset every password. Patching alone does not shut this door, because the door is not broken, the key is simply gone.

How would you know it was starting?

Weeks usually pass between the theft of a credential and any visible damage, and during those weeks something happens that your people can actually see: a request for a code, a confirmation nobody triggered, a message from an address that looks familiar. Whether those moments get reported is measurable. The Korix Phishing Simulation schedules and launches itself, rotates its vectors, and in its multi-turn mode holds a conversation rather than sending a single mail. The Security Dashboard then shows you the report rate and the path from Sent through Opened and Clicked to Reported. Why that figure tells you more than the click rate is covered in an earlier piece: Why click rate is the wrong target

What can you actually do this week?

Your IT team owns the first three. The fourth has no owner in most organisations, because it is not a technical task, and that is exactly where Korix sits.

  • Reset passwords for remote access and administrative accounts, even without suspicion, and end active sessions.
  • Require a second factor on every route in from outside.
  • Take firewall and router management interfaces off the public internet.
  • Rehearse the second step, not only the first: the Korix Invoice Fraud Simulation recreates the moment a changed payment instruction gets waved through. It is bounded, reversible and leaves no lasting impact, and Kora answers questions inside the flow.

Which leaves the open question. If someone stood in your network today with valid credentials and tomorrow asked a colleague to confirm something, would you hear about it? Most organisations have to say no here, and that is not a weakness, it is normal, because no process exists for that case. Korix closes that gap: simulations that schedule themselves, a report rate you can compare across months, and Kora for the questions in between. Book a 15 minute call: Book a call