Infostealer malware compromised more than 7.4 million unique hosts worldwide in the first half of 2026, extracting over 1.7 billion credentials and identity records, according to Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition. Infected-device counts rose 27% compared to the previous six months, with Vidar, StealC and Lumma the three most prevalent variants. The same report tracked 21,667 new vulnerability disclosures, an 8% increase, and 6,256 ransomware victims, up 45%, along with more than 22 million forum posts related to malicious use of AI tools.

The number that should concern security leaders most is not the credential total on its own, it is what 1.7 billion stolen credentials in six months implies about how account compromise now happens. Credential theft at that scale is not the product of targeted phishing against individual employees; it is an industrial pipeline of malware infections, most of them unrelated to the organization ultimately affected, feeding a resale and automated credential-stuffing market that tests stolen logins against thousands of unrelated services at machine speed. This publication has already covered a breach traced directly to infostealer-harvested credentials reaching far beyond the device originally infected, and Flashpoint’s figures suggest that pattern is now the rule rather than the exception.

That has a direct implication for defense priorities. Password rotation policies and even strong, unique passwords do little against an infostealer that exfiltrates the credential, and often the active session token, directly from an infected endpoint the moment it is typed or cached. Security leaders should treat phishing-resistant, passkey-based authentication and continuous session validation as the actual mitigation for this threat, not a convenience upgrade, and should assume that any credential set tied to a device that shows other signs of compromise, of the kind seen in other recent intrusion research, is already circulating regardless of the password’s strength.