Stolen login data is so abundant that criminal markets can sell it for almost nothing.
Meanwhile, verified entry into large companies commands far higher prices, reshaping the underground economy.
Infostealer malware drives that divide. It reaches victims through phishing lures, fake updates, pirated downloads or malicious attachments, then collects browser passwords, cookies and data.
The logs are reused against cloud services, VPNs and business accounts. Analysts at DarkOwl noted the shift in a report shared with Cyber Security News (CSN).
The report cites 2.86 billion compromised credentials in 2025, while another analysis counted 1.8 billion stolen in the first half, an 800% jump from six months earlier.
The result reaches well beyond a reused password. A correct username and password can no longer prove identity when criminals can buy huge volumes of records. The underground market also rewards access that can be used immediately against larger organizations.
2.86 Billion Credentials Flood Criminal Markets
At the commodity end, stolen information is priced for scale. A Social Security number may sell for $1 to $6, a name-and-email record for under $15, and a complete identity package for roughly $20 to $100.
A payment card with a security code commonly sells for $10 to $40. This abundance changes the meaning of a password leak.
Criminals can test old credentials across many services, while fresh logs may include browser data needed to take over accounts.
A recent report on infostealer logs and cloud breaches shows why stolen credentials increasingly serve as a route into corporate systems.
The high end of the market is moving in the opposite direction. Research cited by DarkOwl found that average initial-access-broker listings across five forums rose from about $2,726 in 2024 to $113,275 in 2025.
That 4,055% increase was influenced by a small number of listings claiming access to high-revenue targets.
Typical access costs hundreds or thousands, not the headline average. It signals an ultra-premium tier for access to large enterprises.
Healthcare records, which cannot simply be cancelled and reissued, held at about $250 to $310 each, while verified cryptocurrency accounts also commanded higher prices.
For defenders, a rising price is a warning about attacker interest, not a precise measure of exposure.
Organizations in healthcare, finance and critical infrastructure should review internet-facing systems, privileged accounts and internal movement detection.
The growing trade in initial access broker listings makes that review important after any credential exposure.
Cookies Turn MFA Into a Target
Passwords are not the only item for sale. Stolen session cookies, small data files that keep a user signed in after authentication, have a premium because they can let an attacker replay an approved session.
In practice, that can sidestep a password prompt and the usual multi-factor authentication check.
This method does not mean multi-factor authentication has failed, but it shows that authentication must protect the session after sign-in.
Recent coverage of pass-the-cookie MFA bypass attacks illustrates how malware and phishing campaigns capture these tokens and reuse them without a new code.
DarkOwl recommends shorter session lifetimes, binding sessions to devices, when possible, and watching for session replay.
Teams should also move toward phishing-resistant MFA and continuous verification rather than treating passwords and SMS codes as sufficient proof of identity. Those controls reduce the value of the data criminals are trying to buy.
The market is becoming more selective as well as larger. Bulk dumps continue to lose value, but AI-curated records tailored to a company or role can command a premium because they make targeted fraud and phishing easier.
Reports on phishing kits stealing session tokens underline how attackers focus on authenticated access, not merely passwords.
Dark web pricing should be treated as an early warning signal. Security leaders can use it with exposure monitoring and incident response to decide where defenses need attention first.
The key lesson from the 2.86 billion credential figure is simple: cheap stolen data can still lead to expensive enterprise compromise.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket appeared first on Cyber Security News.



