Key Findings
85% of organizations view stolen credentials as a top threat
Exposed credentials become available on the Dark Web within 24 hours
73% of organizations have found their workforce’s credentials in breach, Dark Web, or infostealer data in the past year
71% of organizations experienced an authentication-related security incident in the past year
29% of organizations treat automated credential abuse as a defined strategic priority
49% of organizations screen passwords at creation or reset
13% of organizations believe MFA adequately addresses the credential threat
39% of organizations identified employee passwords in infostealer logs
19% of organizations continuously monitor credential integrity and automatically remediate exposure
Organizations show a 66%-point gap between recognizing stolen-credential risk (85%) and continuously monitoring and automatically remediating exposure (19%)
43% of organizations do not monitor infostealer logs or are uncertain if they do
In 66% of organizations' most recent attacks, hackers used valid credentials
41% of organizations plan to implement compromised credential monitoring
66% of organizations are concerned about MFA bypass
62% of MFA deployments still allow a password fallback