MobbleOpen in Mobble ⇢
Business · Small business · published 2026-10-01 · via National Law Review / Ogletree Decon

Millions of Fortune 500 Employee Credentials Exposed on Dark Web

Image via National Law Review / Ogletree Decon
Image via National Law Review / Ogletree Decon

Nearly 10 million employee credentials from Fortune 500 companies have been posted to the dark web and are available to cybercriminals, with a new set of compromised credentials appearing every 100 seconds. According to a recent report, 99 percent of these stolen credentials come from web browsers where employees save login information, often through malware called infostealers that harvest stored passwords. Threat actors use these credentials to gain unauthorized access to company networks and launch attacks including ransomware operations.

Expanded Detail

The breach represents a significant vulnerability in how modern workplaces manage digital access. Infostealers—malicious software that employees unknowingly download—exploit a widespread practice of storing login credentials directly in web browsers. Once harvested, these credentials grant attackers the same network permissions as legitimate employees, enabling them to move laterally through company systems and access sensitive data.

The problem extends beyond employee carelessness. Companies often fail to decommission credentials when workers leave, leaving dormant accounts active on networks. Midsize technology firms face particularly acute risk due to higher concentrations of employees with corporate email accounts who save passwords in browsers, creating multiple entry points for threat actors seeking to establish footholds in organizational networks.

Context

This vulnerability could affect millions of workers across large and midsize organizations, as compromised credentials may enable identity theft, corporate espionage, or ransomware attacks that disrupt business operations. Small businesses may face disproportionate impact if they lack cybersecurity resources to monitor breaches or implement credential management protocols. The trend could incentivize companies to adopt stronger access controls and may increase cyber insurance costs, potentially affecting hiring and operational budgets across industries.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at National Law Review / Ogletree Decon →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Fortune 500 Companies' Credentials Leaking at an Alarming Rate.” Browse more stories.