Attackers Have the Password. It Still Works.

By Ken O'Brien, CTO, Enzoic [ Join Cybersecurity Insiders ]
20

Enzoic CTO Ken O’Brien explains how infostealers have changed credential theft and how continuous credential defense helps organizations detect and contain active exposure.

Organizations have spent years strengthening authentication with password screening, MFA, and tools that watch for suspicious logins. Even so, a password can be valid when created, become exposed later, and still be treated as trusted by the identity system. An attacker can then use it to sign in, often without triggering the warning signs of a conventional break-in. Most account takeover starts exactly there, with a login that looks legitimate.

The 2026 Credential Risk Report, based on a survey of 872 cybersecurity professionals, found that 85% of respondents consider compromised credentials a primary attack path into the enterprise. Yet only 19% continuously monitor active credentials and automatically remediate exposure. The report found that only 30% of organizations can detect a newly compromised credential within hours. Among organizations that had experienced an authentication-related incident, 66% said attackers had used valid credentials.

Cybersecurity Insiders spoke with Ken O’Brien, Chief Technology Officer at Enzoic, about how infostealers have shortened the path from credential theft to credential abuse, and how continuous credential intelligence helps organizations identify exposed credentials, connect those findings to identity controls, and reduce the time from detection to containment.

Cybersecurity Insiders: What do you typically see when a company’s credentials are already circulating before the organization detects the exposure?

Ken O’Brien: Credentials are often circulating in breach data or infostealer-derived datasets while the organization still considers those accounts trusted. From the company’s perspective, nothing looks wrong: the user remains active, authentication is succeeding, and there is no obvious incident to investigate.

The research found that 73% of organizations had identified employee or contractor credentials in third-party breach data, dark web sources, or infostealer logs during the previous year.

That gap is what makes credential exposure so dangerous. The credential can be circulating outside the organization long before the company detects unauthorized use. And the attacker’s first login looks exactly like the employee’s.

Cybersecurity Insiders: Walk us through the market for stolen credentials. How does a batch move from an infected machine to a buyer, and what makes one set more valuable than another?

Ken O’Brien: Infostealers have changed the economics of credential theft. One common format we see is what threat actors call a ULP list: URL, login, password. An infostealer harvests these records from an infected machine, and operators compile them into lists that are traded or sold through criminal markets. Enzoic has processed billions of credentials from these datasets.

The URL is particularly valuable because it tells the attacker exactly the site or service where that password can be used, eliminating much of the guesswork that used to come with older credential dumps. 

The easier a stolen credential is to use, the more valuable it becomes. Credentials are worth more when they were exposed recently, provide access to high-value enterprise services, or include session tokens or other authentication data that give an attacker a much shorter path to access.

Infostealers typically harvest saved browser passwords, and much of that harvesting happens on personal or unmanaged devices where an employee saved a work login. The corporate EDR never sees that machine, which is why an organization with solid endpoint coverage can still find its own credentials in a ULP list. The report shows the blind spot: 39% have found employee credentials in infostealer logs, while 43% do not monitor that channel or are unsure whether they do. 

Cybersecurity Insiders: What does Enzoic see across those sources that a standard breach database misses?

Ken O’Brien: Conventional breach databases reflect historical events, often tied to known breaches. Infostealer data is much closer to the point of theft. It shows that a credential was harvested from an endpoint and often includes the URL associated with the login or other authentication material. That gives defenders a better chance of identifying the exposure while the credential remains active and usable.

Enzoic brings these sources together. We combine automated collection with human threat research to build intelligence from breach data, dark web sources, and infostealer datasets. Our threat research team has processed infostealer-derived ULP data for years, including large datasets that are not tied to a single named corporate breach. We also run honeypots that capture credentials from attacks in progress, which surfaces material that never appears in a published dump.

That combination gives us broader and fresher credential intelligence. The question we answer is simple: is a credential that works today already in someone else’s hands?

Cybersecurity Insiders: Why isn’t screening at password creation or reset not sufficient, and what determines how quickly an exposure gets contained once you find it?

Ken O’Brien: Screening at creation or reset answers only one question: ‘Was this password known to be compromised at this moment?’ It does not tell you whether the password remains safe tomorrow. A global banned-password list, the kind built into most directory platforms, has the same limit: it checks the password once, never sees the username-and-password pair, and never looks again.

A credential can subsequently appear in a third-party breach, be harvested by an infostealer, or otherwise become exposed while the password itself never changes. The research shows the mismatch clearly: 49% check at creation or reset, but only 29% screen against live breach intelligence in real time or daily, and just 19% continuously monitor active credentials and automatically remediate exposure.

How fast an exposure gets contained depends on the customer’s environment and the remediation policy, so there is no single meaningful average. What Enzoic controls is the delay between detection and enforcement. Enzoic for Active Directory keeps checking active credentials against updated compromise data and can trigger automated remediation when a password is found to be compromised, rather than waiting for a ticket or the next scheduled reset.

Cybersecurity Insiders: MFA is everywhere. Why does a stolen password still matter?

Ken O’Brien: MFA reduces risk, but it does not eliminate the vulnerabilities created by credential exposure. Once exposure is confirmed, there is little security value in allowing the password to remain active simply because another control can stop some attempts to use it.

The research found that 62% of respondents said their MFA deployment still allows password fallback. Some users are not enrolled, and attackers can also use adversary-in-the-middle techniques, push fatigue, or stolen session material to gain access without a fresh MFA challenge. Only 13% of respondents said MFA adequately addresses credential risk on its own.

Passwordless does not remove the exposure either. Legacy applications, hybrid infrastructure, recovery flows, and fallback paths keep passwords in use, and wherever a password remains active it can still be stolen and replayed.

I see MFA and compromised-credential monitoring as complementary controls. Enzoic applies the same principle in its integrations by monitoring the credential for compromise as new exposure data arrives, while MFA adds another verification layer. MFA decides whether to let a login through. It never asks whether the password should still exist.

Cybersecurity Insiders: What is the most important change security leaders need to make in how they think about credential security?

Ken O’Brien: The biggest conceptual shift is that credential security must extend beyond password policy and become an ongoing identity operation.

For years, organizations concentrated credential controls at the point of password creation: complexity rules, expiration schedules, and eventually screening against known-bad passwords. Those controls still matter, but they assume the important security decision happens when the password is created.

The complexity investment worked, and that is part of the problem. Data Enzoic contributed to the 2026 Verizon DBIR shows fewer than 1% of Active Directory accounts failing complexity checks, while 4% were using a password that had already been exposed. People are four times more likely to be using a password that is for sale than a weak one. A decade of investment solved the wrong problem.

Sometimes an intrusion succeeds precisely because the system does what it was designed to do: it accepts a valid credential. Authentication confirms that a credential is valid but it cannot determine whether that credential is still safe to trust. 

We describe the response to that gap as Continuous Credential Defense. It combines ongoing exposure visibility, monitoring of active credentials, automated remediation, coverage that reaches beyond the core directory, and clear ownership. 

Cybersecurity Insiders: Walk us through how Enzoic handles this end to end, from identifying an exposed credential to containing the risk. Which parts run automatically, and where is human judgment still needed?

Ken O’Brien: Enzoic provides the credential-risk intelligence and enforcement capability, but the organization defines how that signal is used. It first establishes what constitutes a confirmed, actionable exposure and then defines the appropriate response for different accounts and workflows.

In Active Directory, Enzoic screens passwords when they are created or changed and continues monitoring active credentials afterward. Screening uses a partial-hash comparison, so passwords never leave the customer’s environment. If an existing password later becomes compromised, Enzoic can trigger the customer’s defined enforcement or remediation process rather than waiting for the user to change it.

Through Enzoic’s APIs and integrations with IAM platforms and SIEM tools, the same intelligence can be integrated into account creation, login, password reset, and risk-based authentication workflows. Depending on the organization’s policy, an exposed credential can trigger a password reset, step-up authentication, an access restriction, or another fraud or risk workflow.

Routine checks and predefined responses are the parts to automate. Human judgment still matters when the action involves a sensitive account, an investigation already underway, or a critical process that cannot be disrupted without review. Nothing should wait for a person to notice what the database already knows. The goal is to stop making people the bottleneck for every known and repeatable credential-risk event.

Cybersecurity Insiders: A security leader reads this and suspects their company is exposed right now. What should they do first?

Ken O’Brien: Establish a baseline. Find out whether active credentials are already compromised.

In an Active Directory environment, that starts with an audit against current compromised-password intelligence. A password can satisfy every internal policy requirement and still already be known to an attacker. The Credential Risk Report found that 37% of organizations had identified compromised passwords in at least 5% of their Active Directory accounts, while roughly one in five had never checked. Enzoic’s AD Lite tool was built specifically to give organizations that initial view of exposed and unsafe credentials.

But I would not stop at the scan. The next question should be: ‘If we find an exposed credential today, what happens next?’ If the answer today involves an alert, a ticket, several handoffs, and eventually a manual reset, you have identified your next security gap.

So if you’re reading this and worried about your company’s credential security, first determine your current exposure, identify who owns it, and document the path from detection to containment.

Cybersecurity Insiders: Six months into a credential security program, what is the most important measure of progress?

Ken O’Brien: The metric I care most about is time from credential exposure to containment.

I would be cautious about judging a new program by how many compromised credentials it finds initially. Better visibility can cause that number to rise because the organization is uncovering exposure that was already present but hidden.

What should steadily go down is the amount of time an exposed credential remains active and usable. Organizations should also see fewer compromised credentials persisting in the environment, fewer manual remediation steps, and less dependence on users or analysts to discover exposure after the fact.

The 2026 Verizon DBIR shows how little time there is: 73% of ransomware victims had a credential or infostealer leak in the prior year, and half of them were hit within 95 days of the leak. That time window is the one number in credential security a leader can impact directly, and it is the one I would put on the dashboard. 

The identity system will keep trusting a compromised password until something tells it to stop. Build the process that stops trusting the password. Then measure the hours from exposure to containment. That is the whole job.

Resources from Enzoic

Read the 2026 Credential Risk Report to examine how organizations detect exposed credentials and where response processes stall.

Use the free Enzoic for Active Directory Lite password audit to establish a baseline of compromised, weak, and reused passwords.

 

 

Join our LinkedIn group Information Security Community!

No posts to display