Infostealer logs have rapidly become the driving force behind massive cloud data breaches, as attackers shift focus from technical exploits to buying stolen credentials and session tokens. This trend now dominates the cybercrime economy, with infostealer logs providing a direct route into cloud and SaaS environments by simply replaying stolen sessions. As a result, infostealer logs are powering some of the largest and most damaging breaches in recent years.
How Infostealer Logs Became Central to Cloud Data Breaches
In the past, cybercriminals typically relied on phishing or exploiting technical vulnerabilities to gain initial access to enterprise networks. However, recent research reveals a decisive shift: threat actors are now overwhelmingly purchasing infostealer logs from underground markets to obtain valid usernames, passwords, session cookies, and SSO tokens. By replaying these sessions against cloud consoles, SaaS platforms, and VPN gateways, they can often bypass multi-factor authentication entirely.
Cisco Talos’ Q1 2026 incident-response data underscores this shift. Phishing and credential-based access, especially through infostealer logs, have now overtaken vulnerability exploitation as the top initial-access method. The vast majority of these credentials are harvested on infected endpoints by malware such as RedLine, Lumma, and Vidar, then packaged and sold as “stealer logs” to other threat actors.
This approach is efficient and scalable for attackers, allowing them to focus on post-compromise activity, often leading to ransomware or extortion. The entire process has become so streamlined that it now represents the primary vector for enterprise breaches.
Case Studies: Infostealer Logs Fuel High-Profile Breaches
The 2024 Snowflake Breach: A Blueprint for Modern Attacks
The 2024 breach of cloud data warehousing provider Snowflake exemplifies the infostealer log threat. In this case, the threat group UNC5537 (also known as Scattered Spider or ShinyHunters) did not exploit a technical vulnerability in Snowflake’s platform. Instead, they leveraged credentials stolen via infostealer malware from Snowflake customers’ employees, with some infections dating back as far as 2023.
Many compromised credentials were found stored in unsecured spreadsheets and password managers. Critically, none of the affected accounts had multi-factor authentication enabled, allowing attackers to access cloud environments with only a username and password.
The breach affected at least 165 organisations, including major names such as AT&T, Ticketmaster, Santander Bank, Neiman Marcus, and Advance Auto Parts. The attackers exfiltrated over 50 billion AT&T call records and issued extortion demands surpassing $2 million. Once inside, UNC5537 used a custom exfiltration toolkit called FROSTBITE to automate the scraping of vast amounts of data from breached Snowflake instances.
The Zestix/Sentap Campaign: Widespread Corporate Impact
Another major campaign, identified in January 2026 and attributed to Zestix/Sentap, further demonstrates the scale of the issue. Attackers used credentials harvested by popular infostealer malware—specifically RedLine, Lumma, and Vidar—to access corporate accounts on cloud file-sharing platforms such as ShareFile, Nextcloud, and OwnCloud.
Without exploiting any technical vulnerabilities, they exfiltrated sensitive assets including defence engineering blueprints, healthcare records, and legal or financial archives. Again, the absence of multi-factor authentication on many accounts made these attacks possible via simple credential replay.
Scale of Exposure: Millions of Credentials at Stake
The 2026 State of Enterprise Infostealer Exposure report from Flare quantifies the expanding threat. In 2025, 2.05 million infostealer logs exposed enterprise identity credentials. The percentage of logs containing enterprise credentials rose from 6 percent in early 2024 to almost 16 percent by 2026. Astonishingly, 79 percent of these logs included Microsoft-linked SSO credentials—reflecting widespread adoption of single sign-on technology and its exploitation by attackers.
Of particular concern, 1.17 million of the logs included both credentials and live session cookies, enabling immediate access and bypassing multi-factor authentication through session replay. This capability allows attackers to jump straight into sensitive cloud environments with minimal effort.
The Infostealer-to-Breach Kill Chain Explained
The lifecycle of an infostealer-driven breach involves a well-defined supply chain, typically comprising five stages, each handled by specialised actors:
- Infection: A user, often on an unmanaged or personal device, is lured into executing infostealer malware through phishing or malicious downloads.
- Collection: The malware harvests browser-stored credentials, session cookies, and authentication tokens from the infected device.
- Packaging: Stolen data is bundled into “logs” and uploaded to centralised command-and-control (C2) infrastructure.
- Sale: These logs are sold on cybercrime marketplaces, typically within hours of collection.
- Exploitation: Other criminals purchase the logs, replay sessions or use credentials to gain access to cloud and SaaS environments, often bypassing MFA.
This efficient supply chain allows breaches to move from initial infection to full cloud compromise in days or even hours, making time-to-detection critical for defenders.
Why This Matters for Organisations
The widespread availability of infostealer logs, combined with the ability to bypass MFA using session replay, means that traditional defences are often insufficient. Even robust password policies or perimeter controls cannot prevent breaches if attackers can simply buy their way into cloud platforms. The risk is particularly acute for organisations with unmanaged endpoints or incomplete MFA coverage.
Actionable Steps to Mitigate Infostealer Threats
While no single solution can eliminate the risk, organisations can take targeted actions:
- Audit and enforce mandatory MFA for all cloud and SaaS accounts, including those accessed by third parties and contractors.
- Monitor for the presence of infostealer malware on both managed and unmanaged endpoints, especially those used for remote work.
- Regularly review and revoke active sessions, especially following possible credential exposure or suspected infections.
- Educate users about the dangers of storing credentials in unsecured files or password managers lacking strong encryption.
By understanding the infostealer kill chain and acting quickly to close common gaps, organisations can reduce the risk of joining the growing list of high-profile breach victims.
Originally reported by cybersecuritynews.com.




