Infostealer Attacks in September 2026: Monthly Report

Infostealer Attacks in September 2026: Monthly Report

Quick Summary

The stealer logs we indexed in September 2026 came from 1,176,466 infected machines. The median machine leaked 19 saved credentials, and 166,287 machines had a Microsoft 365 password saved. When an employee turns up in a stealer log, reset their work passwords and revoke their sessions. Then have them change every other password saved in that browser.

One infected machine leaks every password saved in its browser

Infostealer malware takes every password saved in the browser, work and personal. The median infected machine in September’s logs leaked 19 saved passwords, and a quarter leaked more than 61. A personal password the employee also uses at work puts the work account at risk too.

We index stealer logs leaked or sold on private Telegram channels and criminal marketplaces.

Why listen to us?

Breachsense is a dark web monitoring API that indexes stealer logs alongside phishing kit credentials and breach data. Our founder, Josh Amishav, used leaked credentials to get into client networks during nearly 20 years as a penetration tester. Our stealer-log alerts include the plaintext password and, when the log records them, details of the infected machine. We’ve indexed over 41 billion leaked credentials. Kaspersky’s ICS CERT cites our breach records in its quarterly industrial cybersecurity reports, and TechTarget has cited our research. See who else cites our data.

Does a password reset end a stolen session?

Not always. Microsoft Entra ID ends sessions created with a password when the password changes. Sessions from a passwordless sign-in keep working, so a stolen session cookie still gets the attacker in. Revoking the user’s sessions in Entra ends them all.

September 2026 infostealer numbers at a glance

  • 1,176,466 infected machines identified in the logs we indexed
  • 19 saved credentials leaked from the median machine
  • 115,531,775 credential records, containing 53,760,438 distinct username and password pairs
  • 166,287 machines had a Microsoft 365 password saved
  • 69,186 machines had an OpenAI credential saved

The median infected machine leaked 19 saved credentials

A quarter of machines leaked more than 61 saved credentials, and one in ten leaked more than 135.

We use the median because a few very large logs pull the average up.

One in seven infected machines had a Microsoft 365 password saved

369,893 distinct usernames for login.microsoftonline.com, the Microsoft 365 sign-in page, turned up across 166,287 machines.

6.3% of those usernames were on Microsoft’s default onmicrosoft.com tenant domains.

Monitor your tenant’s onmicrosoft.com domain, not just your main domain. The first admin account in a Microsoft 365 tenant is created on the onmicrosoft.com domain.

AI and developer accounts in September’s logs

OpenAI credentials turned up on 69,186 machines, one in every 17.

AI platformCredentials
openai.com111,544
huggingface.co6,811
runwayml.com3,238
mistral.ai87
chatgpt.com74
cohere.com24

GitHub credentials came from 83,809 machines, more than any other developer platform we track.

PlatformCredentials
discord.com791,272
github.com141,742
slack.com15,563
docker.com6,355
gitlab.com4,856
atlassian.net2,458
npmjs.com1,746
bitbucket.org1,269

A stolen GitHub session cookie gets an attacker past GitHub’s two-factor check. Revoke GitHub sessions for any employee whose machine turns up in a stealer log.

What security teams should do

Have the employee change every password saved in that browser. Start with any they also use for a work account.

Revoke the user’s sessions too, starting with Microsoft 365 and GitHub.

Route stealer-log alerts into your SOAR or ticketing system. Breachsense sends alerts by webhook, so a stealer-log alert can open the reset and revocation tasks without someone reading it first.

How we collected this data

This report counts the infostealer logs we index, not all infostealer activity for the month. Figures are dated by when we indexed the log, not when the machine was infected. We don’t compare monthly totals, because the number of logs we index varies from month to month.

The same credential often turns up in several logs, so September’s 115,531,775 records contain 53,760,438 distinct username and password pairs.

21.4% of September’s credential records have no machine identifier. The per-machine figures use the 90,822,586 records that include a machine identifier. The per-machine figures count each combination of site, username and password once per machine. The Credentials columns count distinct username and password pairs.

The platform tables cover a fixed list of sites, not every site in the logs.

Find out if your staff are in stealer logs

Dark web monitoring alerts you by webhook or email when we find one of your employees’ passwords in a stealer log.

Breachsense is a dark web monitoring API for security teams and MSSPs. It finds credentials and session tokens that have already been stolen from your staff or customers, whether by infostealer malware or a phishing page. It delivers them by webhook so teams can reset the affected accounts before attackers use them. It also indexes the files ransomware groups leak, so you can search them for your own company’s data.

To see what has already leaked for your domain, run a free dark web scan, then book a demo to set up alerts.

Our September 2026 phishing report counts credentials taken from fake login pages. The September 2026 ransomware report counts the companies named on leak sites.

September 2026 Infostealer FAQ

The stealer logs Breachsense indexed in September 2026 contained 115,531,775 credential records from 1,176,466 infected machines. Those records contain 53,760,438 distinct username and password pairs, because the same credential often turns up in several logs. The count covers the logs we index, not every infection.
The median infected machine in the logs we indexed in September 2026 leaked 19 saved credentials. A quarter of machines leaked more than 61 credentials, and one in ten more than 135. Have the employee change every password saved in that browser, starting with any they also use at work.
A password reset stops a stolen session cookie only on some services. Microsoft Entra ID ends sessions created with a password when the password changes, but not sessions from a passwordless sign-in. Revoking the user’s sessions ends both kinds, so reset the password and revoke the sessions.
Microsoft 365 credentials appeared on 166,287 infected machines in the stealer logs we indexed in September 2026, one machine in seven. Those machines had 369,893 distinct usernames saved for the Microsoft sign-in page, and 6.3% of the usernames were on default onmicrosoft.com tenant domains.
OpenAI credentials appeared on 69,186 infected machines in the stealer logs we indexed in September 2026, one machine in 17. Those machines contained 111,544 distinct OpenAI credentials. Other AI platforms on our list appeared far less often.
Monitor infostealer malware logs for your company domains. Breachsense dark web monitoring sends a webhook or email alert when an employee’s credentials appear in a log we index. Reset the employee’s work passwords and revoke their sessions.