Report by KELA
Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security
4 FINDINGSPublished Apr 29, 2025
View Original Report →Key Findings
Credentials for victims of the Play, Akira, and Rhysida ransomware groups were found on cybercrime marketplaces between 5 and 95 days prior to the reported attack.
KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theftRansomwareThreat group
Among the roles most vulnerable to credential theft, 28% were in Project Management, followed by Consulting (12%) and Software Development (10.7%).
KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theft
Infostealer activity has surged by 266% in recent years.
KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
Infostealer
The average time between credentials being found and the reported ransomware attack was 2.5 weeks
KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theftRansomware