Infostealer Attacks in August 2026: Monthly Report

Infostealer Attacks in August 2026: Monthly Report

How many passwords an infostealer steals from one machine, and why resetting the account your alert specifies isn’t enough.

• One infected machine leaks every password saved in that browser, not just the account you were alerted about.
• Infostealer infections hit managed company computers, not just home PCs.
• Stolen AI tool credentials expose whatever your staff pasted into them, including source code and customer data.
• Resetting a password doesn’t end a hijacked session. Revoke the leaked sessions or the attacker stays logged in.

381,088 of August’s infected machines ran a Windows Enterprise edition, which only comes through volume licensing. That’s close to a third of the machines we indexed.

We index infostealer logs as they’re leaked or sold on private Telegram channels and criminal marketplaces.

This is the first month of the series, so there’s no month-over-month comparison yet. The methodology note at the end sets out what we counted and what we left out.

Here’s what the August 2026 numbers show.

August 2026 infostealer numbers at a glance

August is the first month we’ve published infostealer volume, so these numbers are the baseline the rest of the series gets measured against.

Stealer logs are the files infostealer malware sends back after it infects a machine. Each log holds the passwords saved in that machine’s browsers, along with its cookies and system details. Operators sell them in bulk on criminal marketplaces and Telegram channels.

  • 1,217,555 infected machines in the infostealer logs we indexed
  • 27 saved logins taken from the typical machine
  • 133,005,847 credential records, holding 57,979,449 distinct username and password pairs
  • 612,096 email domains appeared in the stolen usernames
  • 176,784 machines held a Microsoft 365 credential
  • 384,955,693 cookies captured from the same logs

These numbers cover the infostealer logs we index, not every infection out there.

One infection leaks 27 stolen logins, not one

The typical machine in August had 27 saved logins taken from it. A quarter of machines lost more than 87 credentials. One in ten lost more than 202.

The average works out at 85, but a handful of enormous logs increased that number. Most machines leaked nowhere near that.

When one of your employees turns up in a stealer log, you’re not looking at the single account that triggered the alert. You need to reset everything that was saved in that person’s browser.

Two-thirds of stolen credentials have no malware family defined

Of August’s 133,005,847 credential records, 44,728,743 arrived with a malware family defined. That’s a third. For the remaining 88 million, the logs say nothing about which family took them.

FamilyCredentialsMachinesShare of attributed
Meta12,395,517173,76127.7%
RedLine11,467,129202,15425.6%
StealC10,781,277139,41424.1%
Vidar8,525,852119,29419.1%
Mystic385,9657,2970.9%
Raccoon278,0533,9600.6%
Lumma109,6851,8260.2%
AMOS98,2981,0840.2%

Those top four families account for 96.5% of everything we could attribute.

Those percentages are shares of the 44.7 million credentials that included a label, not of the full 133 million records.

A third of the infections were on work machines

1,205,794 of the infected machines reported which version of Windows they were running. 381,088 of those ran an Enterprise edition.

Enterprise editions aren’t sold in shops. You get them through volume licensing, which means somebody’s IT department bought and deployed them. Another 296,607 machines ran a Home edition. Windows Pro was the largest group at 406,134, but it tells you less: plenty of people buy Pro for a home machine.

The passwords stolen from those managed machines were mostly personal accounts. google.com led with 1,316,590 stolen credentials, then facebook.com with 1,200,534. Roblox sits fourth at 704,262.

Then there’s microsoftonline.com, where Microsoft work and school accounts authenticate. 300,602 of those accounts turned up across 176,784 machines, roughly one in every seven we saw. About half sit on company domains, and another four in ten on school and university domains.

OpenAI credentials were on one machine in 14

That’s 89,571 infected machines, with 138,042 distinct OpenAI logins between them.

AI platformAccounts
openai.com138,042
huggingface.co7,831
runwayml.com4,125
mistral.ai138
cohere.com18
perplexity.ai7
character.ai5
replicate.com4
claude.ai4

Don’t read the gap between OpenAI and the rest as a straight measure of who’s more exposed. A lot of people sign into AI tools with Google or Microsoft SSO, and an SSO login stores no separate password for the browser to leak. Those accounts are still reachable, just through the identity provider’s credential instead.

What makes a stolen AI login worth resetting is the conversation history behind it. People paste source code and customer records into these tools, and whoever holds the password can read all of it.

Stolen cookies and session hijacking

We captured 384,955,693 cookies from August’s logs. Most are analytics and tracking junk, so don’t read that total as 384 million hijackable sessions.

These are cookies for a sample of business services, not a ranking of risk. Any cookie that keeps someone signed in to your data deserves the same attention.

DomainCookies captured
login.microsoftonline.com422,216
adobe.com321,794
zoom.us317,339
samsung.com290,553
outlook.live.com166,838
upwork.com152,988
www.microsoft.com142,235
mail.google.com113,333
slack.com64,482
github.com64,349
salesforce.com35,048
atlassian.net3,647

A session token is the credential your browser holds after you authenticate, so the server treats you as already signed in. It’s a bearer token, which means whoever presents it is treated as you. An attacker who imports a stolen one lands inside a live session without touching the login flow, so MFA never fires.

Changing a password doesn’t invalidate a session that’s already running. Revoking those sessions is a separate action that must be done when a session token is leaked.

Developer and collaboration accounts

Logins for developer tools and team chat turn up in the same logs.

PlatformAccounts
discord.com781,790
github.com151,129
slack.com10,854
docker.com6,342
gitlab.com5,160
atlassian.net2,756
npmjs.com1,638
bitbucket.org1,155
pypi.org497

GitHub credentials leaked from 90,774 separate machines. A stolen GitHub login is worth more than the account itself, because of what the account can reach: private repositories, and whatever secrets are sitting in the CI pipelines.

We can’t tell a person’s login from a service account in this data. Service accounts are the ones nobody rotates when an employee leaves.

What security teams should do

Scope the reset to the machine, not to the alert. August’s typical machine had 27 saved passwords, and the malware took all of them. If you reset just the account that fired the alert, you’ve left the other 26 exposed.

Revoke the session tokens too. 422,216 Microsoft login cookies leaked in August’s stealer logs. Each one is a session that a password reset on its own won’t close.

Set up Dark web monitoring alerts. Real-time alerts notify you when your employees’ credentials show up in infostealer logs or combo lists. Third-party breaches too.

Stolen credentials reach attackers by more than one route. Our August 2026 phishing report counts the ones taken from fake login pages, and the August 2026 ransomware report counts the companies named on leak sites that month.

Methodology

Every credential here was recovered from infostealer logs we index directly from private Telegram channels and criminal marketplaces. This isn’t a count of all infostealer activity for the month. Figures are dated by when we indexed the log, not when the machine was initially infected.

We count credential records, not unique credentials. The same username and password often turns up in several logs in one month, so August’s 133,005,847 records hold 57,979,449 distinct username and password pairs. The machine count is distinct within the month, but a machine infected across two months is counted in both.

22.3% of August’s credential rows carry no machine identifier. The per-machine figures in this report use the 103,292,422 rows that do.

Family attribution comes from the log itself. Some entries carry a seller’s Telegram handle in place of a family name. We’ve left those out of the family table.

The cookie total counts every cookie in the logs, including tracking and analytics cookies. We can’t tell an authentication cookie from a tracking one in this data, so the total isn’t a count of hijackable sessions.

Breachsense monitors the dark web and criminal marketplaces for your company’s exposed data, from leaked credentials to files stolen in ransomware attacks, and alerts your team by webhook or email when your data has surfaced.

August 2026 Infostealer FAQ

Breachsense indexed 133,005,847 credential records from 1,217,555 infected machines in August 2026. Those records hold 57,979,449 distinct username and password pairs across 612,096 email domains. That covers the infostealer logs we index, so the real total across all infections is higher.
In August 2026 the typical infected machine had 27 saved logins taken from it. A quarter of machines lost more than 87 credentials, and one machine in ten lost more than 202. The average of 85 logins is due to a small number of very large logs. In any case, always reset every account saved in the browser on the infected device, not just the one your alert specified.
Meta led the families we could identify with 12,395,517 credentials, ahead of RedLine with 11,467,129 credentials and StealC with 10,781,277. Note, that ranking covers only a third of August’s credentials, the ones that arrived with a family label. The other two-thirds didn’t specify one.
OpenAI logins appeared on 89,571 infected machines in August 2026, 138,042 distinct accounts between them. That’s about one in every 14 machines we saw. Other AI platforms barely appeared, partly because many people sign into them with Google or Microsoft SSO, which stores no separate password.
Both, on the same machine. 381,088 infected machines in August 2026 ran a Windows Enterprise edition, which is only sold through volume licensing. Most of the stolen logins were personal, led by Google and Facebook. 50,885 of the machines also had a Microsoft 365 credential saved. The browser’s saved password store doesn’t separate work from personal.
Monitor your company domains against infostealer malware logs as they’re indexed. Dark web monitoring covers that alongside third-party breaches and combo lists. Phishing kits too. Alerts should reach your security stack by webhook or email so you can automatically force a reset before the credentials get exploited.