Report by KELA

Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security

4 FINDINGSPublished Apr 29, 2025
View Original Report →

Key Findings

Credentials for victims of the Play, Akira, and Rhysida ransomware groups were found on cybercrime marketplaces between 5 and 95 days prior to the reported attack.

KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theftRansomwareThreat group

Among the roles most vulnerable to credential theft, 28% were in Project Management, followed by Consulting (12%) and Software Development (10.7%).

KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theft

Infostealer activity has surged by 266% in recent years.

KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
Infostealer

The average time between credentials being found and the reported ransomware attack was 2.5 weeks

KELAInside the Infostealer Epidemic: Exposing the Risks to Corporate Security·Apr 29, 2025
CredentialsCredential theftRansomware