Infostealer Logs Driving Massive Cloud Data Breaches

Infostealer logs have rapidly become the driving force behind massive cloud data breaches, as attackers shift focus from technical exploits to buying stolen credentials and session tokens. This trend now dominates the cybercrime economy, with infostealer logs providing a direct route into cloud and SaaS environments by simply replaying stolen sessions. As a result, infostealer logs are powering some of the largest and most damaging breaches in recent years.

How Infostealer Logs Became Central to Cloud Data Breaches

In the past, cybercriminals typically relied on phishing or exploiting technical vulnerabilities to gain initial access to enterprise networks. However, recent research reveals a decisive shift: threat actors are now overwhelmingly purchasing infostealer logs from underground markets to obtain valid usernames, passwords, session cookies, and SSO tokens. By replaying these sessions against cloud consoles, SaaS platforms, and VPN gateways, they can often bypass multi-factor authentication entirely.

Cisco Talos’ Q1 2026 incident-response data underscores this shift. Phishing and credential-based access, especially through infostealer logs, have now overtaken vulnerability exploitation as the top initial-access method. The vast majority of these credentials are harvested on infected endpoints by malware such as RedLine, Lumma, and Vidar, then packaged and sold as “stealer logs” to other threat actors.

This approach is efficient and scalable for attackers, allowing them to focus on post-compromise activity, often leading to ransomware or extortion. The entire process has become so streamlined that it now represents the primary vector for enterprise breaches.

Case Studies: Infostealer Logs Fuel High-Profile Breaches

The 2024 Snowflake Breach: A Blueprint for Modern Attacks

The 2024 breach of cloud data warehousing provider Snowflake exemplifies the infostealer log threat. In this case, the threat group UNC5537 (also known as Scattered Spider or ShinyHunters) did not exploit a technical vulnerability in Snowflake’s platform. Instead, they leveraged credentials stolen via infostealer malware from Snowflake customers’ employees, with some infections dating back as far as 2023.

Many compromised credentials were found stored in unsecured spreadsheets and password managers. Critically, none of the affected accounts had multi-factor authentication enabled, allowing attackers to access cloud environments with only a username and password.

The breach affected at least 165 organisations, including major names such as AT&T, Ticketmaster, Santander Bank, Neiman Marcus, and Advance Auto Parts. The attackers exfiltrated over 50 billion AT&T call records and issued extortion demands surpassing $2 million. Once inside, UNC5537 used a custom exfiltration toolkit called FROSTBITE to automate the scraping of vast amounts of data from breached Snowflake instances.

The Zestix/Sentap Campaign: Widespread Corporate Impact

Another major campaign, identified in January 2026 and attributed to Zestix/Sentap, further demonstrates the scale of the issue. Attackers used credentials harvested by popular infostealer malware—specifically RedLine, Lumma, and Vidar—to access corporate accounts on cloud file-sharing platforms such as ShareFile, Nextcloud, and OwnCloud.

Without exploiting any technical vulnerabilities, they exfiltrated sensitive assets including defence engineering blueprints, healthcare records, and legal or financial archives. Again, the absence of multi-factor authentication on many accounts made these attacks possible via simple credential replay.

Scale of Exposure: Millions of Credentials at Stake

The 2026 State of Enterprise Infostealer Exposure report from Flare quantifies the expanding threat. In 2025, 2.05 million infostealer logs exposed enterprise identity credentials. The percentage of logs containing enterprise credentials rose from 6 percent in early 2024 to almost 16 percent by 2026. Astonishingly, 79 percent of these logs included Microsoft-linked SSO credentials—reflecting widespread adoption of single sign-on technology and its exploitation by attackers.

Of particular concern, 1.17 million of the logs included both credentials and live session cookies, enabling immediate access and bypassing multi-factor authentication through session replay. This capability allows attackers to jump straight into sensitive cloud environments with minimal effort.

The Infostealer-to-Breach Kill Chain Explained

The lifecycle of an infostealer-driven breach involves a well-defined supply chain, typically comprising five stages, each handled by specialised actors:

  • Infection: A user, often on an unmanaged or personal device, is lured into executing infostealer malware through phishing or malicious downloads.
  • Collection: The malware harvests browser-stored credentials, session cookies, and authentication tokens from the infected device.
  • Packaging: Stolen data is bundled into “logs” and uploaded to centralised command-and-control (C2) infrastructure.
  • Sale: These logs are sold on cybercrime marketplaces, typically within hours of collection.
  • Exploitation: Other criminals purchase the logs, replay sessions or use credentials to gain access to cloud and SaaS environments, often bypassing MFA.

This efficient supply chain allows breaches to move from initial infection to full cloud compromise in days or even hours, making time-to-detection critical for defenders.

Why This Matters for Organisations

The widespread availability of infostealer logs, combined with the ability to bypass MFA using session replay, means that traditional defences are often insufficient. Even robust password policies or perimeter controls cannot prevent breaches if attackers can simply buy their way into cloud platforms. The risk is particularly acute for organisations with unmanaged endpoints or incomplete MFA coverage.

Actionable Steps to Mitigate Infostealer Threats

While no single solution can eliminate the risk, organisations can take targeted actions:

  • Audit and enforce mandatory MFA for all cloud and SaaS accounts, including those accessed by third parties and contractors.
  • Monitor for the presence of infostealer malware on both managed and unmanaged endpoints, especially those used for remote work.
  • Regularly review and revoke active sessions, especially following possible credential exposure or suspected infections.
  • Educate users about the dangers of storing credentials in unsecured files or password managers lacking strong encryption.

By understanding the infostealer kill chain and acting quickly to close common gaps, organisations can reduce the risk of joining the growing list of high-profile breach victims.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins
Category
Malware
Published
Jul 24 - 2026
Post Tags
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call