How long stolen credentials go unnoticed
A password reaches a criminal market. Somewhere between that moment and the moment an organisation finds out, there is an interval. Measuring it, and shortening it, is some of the most valuable work in cyber security, and almost none of it is visible from outside.
Twenty-two seconds. In its 2026 report, Google's Mandiant team measured the median time between one attacker gaining access to an organisation and handing that access to whoever would use it next. Four years earlier the same handoff took more than eight hours. The reason for the collapse is mundane and slightly chilling: the first attacker now pre-stages the second one's tools during the initial break-in, so the handover is already prepared before it happens.
Set that against the other clock. Across the same body of 2025 investigations, Mandiant put the global median dwell time, the span between an intrusion starting and somebody noticing, at 14 days. It had been 11 days the year before.
Seconds on one side. Days on the other. Everything that matters in this article happens in the space between those two numbers.
Where the passwords actually come from
Very few of these credentials are guessed. Most are harvested in bulk by infostealer malware, a category of software with one job: land on a machine, copy every saved password, session cookie and authentication token out of the browser, and send them onward. The victim usually installs it themselves, attached to a cracked application or a file that arrived looking useful.
The volumes are difficult to hold in your head. Flashpoint, a threat intelligence firm, reported 11.1 million infected machines over a year, yielding more than 3.3 billion stolen credentials, session cookies and cloud tokens circulating on criminal markets. That figure comes from a commercial vendor with an interest in the number being large, and it should be read with that in mind. The direction it points, though, matches what government assessors and incident responders describe independently.
Flashpoint's own summary of what this changes is the clearest sentence published on the subject in 2026: attackers do not need to escalate privileges or deploy custom malware to gain access, they simply log in.
Price check: a corporate login costs less than a laptop
The economics are the part that tends to land with boards. In its 2026 edition, Verizon's Data Breach Investigations Report analysed advertised prices for stolen corporate accounts and found a median of about $700 for a standard user account. Administrator access went for roughly $1,300. Verizon's analysts added a note of their own surprise, writing that they had expected a higher median price.
| What is being sold | Typical asking price | Reported by |
|---|---|---|
| Standard user account | $700 median | Verizon DBIR, 2026 edition |
| Administrator account | $1,300 median | Verizon DBIR, 2026 edition |
| Full network access listing | $400 to $1,000 median | KELA quarterly reports, 2022 to 2023 |
| One infostealer log | From $10 | Flare, Russian Market pricing, 2023 |
Averages in this market are close to meaningless, because a handful of six-figure listings for large companies drag the mean far above what anything typically sells for. Flare demonstrated the distortion neatly in 2023: across 72 auctions on one forum, the average price was $4,699 with outliers included and $1,328 with them removed. The median is the honest number, and the median is low.
Credential leaks arrive before the ransomware does
For defenders, the useful finding is that this leaves a trail, and the trail arrives early. Verizon matched ransomware victims against credential-leak data for its 2026 report. Among the victims that had any prior exposure, half had a credential or infostealer event within 95 days of being publicly named as a ransomware victim. Twenty-seven per cent had no such event in the year beforehand at all.
Mandiant's 2026 figures point the same way from a different angle. Prior compromise, meaning access obtained by somebody else and passed along, was the leading initial infection vector in ransomware operations at 30 per cent, double the 15 per cent recorded in 2024.
The credentials, in other words, often surface somewhere before the extortion note does. Somebody could have seen them. In most organisations, nobody was looking.
Nine days, or twenty-five
The most useful number in Mandiant's 2026 report is not the 14-day global median. It is what happens when that median is split by who did the noticing. Organisations that spotted the intrusion themselves sat at a median of 9 days. Organisations told by somebody outside sat at 25.
The balance has been moving in the right direction. Just over half of compromises, 52 per cent, were detected internally in 2025, up from 43 per cent the year before, while external notifications fell from 43 per cent to 34 per cent. More organisations are finding their own intrusions than at any point Mandiant has measured.
Which leaves the last category, and it is the one worth sitting with. In 14 per cent of cases, the organisation learned it had been compromised from the attacker. A ransom note is a detection method. It is simply the most expensive one on the list.
Three intervals worth putting a number on
Dwell time is the metric the industry quotes, and it is the wrong one to start with, because it can only be calculated after an incident. The intervals below can be measured this quarter, without waiting to be attacked.
Who closes the gap
Nothing in the paragraphs above happens on its own. Somebody has to subscribe to the feeds, tune out the noise, and decide which of four hundred alerts about leaked addresses is the one attached to a live privileged account. Somebody has to make the case for mandatory multi-factor authentication to a business that experiences it as friction. Somebody has to insist that revoking a session is a separate action from resetting a password, and then build the runbook that makes both happen inside an hour.
This work is unusually hard to see from outside. It produces no artefact. When it succeeds, an intrusion that would have taken 14 days to notice instead ends on the afternoon it started, and no report is ever written. The identity engineer who cut the revocation interval from nine days to four hours has done something an organisation will feel for years, and will struggle to describe in a performance review.
Where these numbers come from
- Google Cloud and Mandiant, M-Trends 2026, drawn from over 500,000 hours of investigations in 2025. Source of the 22-second handoff, the 14-day global median dwell time, the 9-day internal and 25-day external notification medians, the 52/34/14 detection-source split and the 30 per cent prior-compromise figure.
- Verizon, Data Breach Investigations Report, 2026 edition. Source of the $700 and $1,300 median prices, and of the credential-leak analysis in Figure 48 covering 4,395 events.
- CISA, FY23 Risk and Vulnerability Assessments Analysis, covering 143 assessments. Source of the 41 per cent valid-accounts figure. FY23 is the most recent edition published.
- Sophos, Active Adversary Report 2026, covering 661 cases between November 2024 and October 2025. Source of the 67.32 per cent identity figure and the 59 per cent missing-MFA figure.
- Flashpoint, on infostealer volumes. A commercial vendor source, cited as such.
Start the clock this quarter
Pick one of the three intervals. Measure it honestly, including the cases where the answer is embarrassing. Write the number down with a date next to it, and measure it again in ninety days.
That record is worth keeping for its own sake, because it will tell you whether your organisation is getting faster. It is also, as it happens, precisely the evidence an independent panel can read, weigh and stand behind. Twenty-two seconds is the number the other side has already achieved. Yours is the one you can still change.
Stolen credentials, answered
How long do stolen corporate credentials go unnoticed?
Published incident data puts the answer in days to weeks, while the criminal side of the transaction now moves in seconds. Google and Mandiant reported a global median dwell time of 14 days across their 2025 investigations, up from 11 days the year before. That median splits sharply by who did the noticing: organisations that detected the intrusion themselves sat at a median of 9 days, while those notified by an outside party sat at 25 days. In 14 per cent of cases, the organisation was told by the attacker. Sophos, working from 661 incident-response cases between November 2024 and October 2025, reported a median of 3 days across its own caseload.
What does access to a corporate network sell for?
Less than most people assume. In its 2026 edition, Verizon reported a median advertised price of about $700 for a standard user account and roughly $1,300 for an administrator account, drily noting that its analysts had expected a higher figure. Quarterly market tracking by KELA across 2022 and 2023 put the median asking price for a full network access listing between $400 and $1,000. A single infostealer log, containing whatever passwords and session cookies one infected machine held, has sold for as little as $10.
Is logging in with valid credentials now the most common way attackers get in?
It is one of the most common, and by some measures the leading one. In its FY23 Risk and Vulnerability Assessments, covering 143 engagements, CISA found that abusing valid accounts accounted for 41 per cent of successful initial access attempts. The same analysis put the figure at 51 per cent in FY21 and 11.8 per cent in FY20, so the trend is sharply upward over five years without being a straight line. Sophos separately attributed 67.32 per cent of the root causes it investigated to compromised identity.
Why does an attacker not need malware if they have a password?
Because authentication is designed to let them through. Detection tools are built to notice things that look wrong: unfamiliar binaries, unusual processes, traffic to known bad destinations. A correct username and password produce none of those signals. The session looks like work. Flashpoint put it plainly in 2026: attackers do not need to escalate privileges or deploy custom malware to gain access, they simply log in. That is why the detection problem here is a problem of noticing something ordinary, which is much harder than noticing something strange.
What should an organisation actually measure?
Three intervals, each of which can be counted and improved. First, exposure to discovery: how long between a credential appearing in a public dump or criminal market and somebody in your organisation knowing. Second, discovery to revocation: how long between knowing and the account being disabled and the session invalidated. Third, revocation to assurance: how long before you can state, with evidence, that the credential is no longer usable anywhere it was reused. Most organisations cannot put a number on any of the three, which is itself the finding.
How does the Cyber Security Awards judge this kind of work?
Against published criteria, by an independent panel. The programme runs ten categories in 2026, five for individuals and five for organisations, and the judging process asks for evidence rather than adjectives: dated actions, outcomes a third party can confirm, and honest attribution of who did what. Work that shortens a detection interval suits this well, because it produces exactly the kind of evidence a panel can verify. Sponsors fund the ceremony and have no part in the result.
Identity is the new perimeter
Why identity security now decides who gets in, and how defenders are rebuilding the boundary around people.
Ransomware in 2026: what defenders changed
The attack got faster, so the first hour got rehearsed. What actually shifted in defensive practice.
The evidence panellists look for
Specific actions, dated and attributable, and outcomes a third party can confirm.