7.4M devices looted in 2026

Article by Nacata Security, 17/08/2026

Can you imagine someone emptying your digital wallet while you sleep, without you even noticing?

That is exactly what the modern infostealer does, every single second.

In the first half of 2026, infostealers stole 1.7 billion credentials. It wasn’t luck: it was an automated machine that needs neither rest nor supervision.

Flashpoint documented 7.4 million infected devices, a 27% increase over the previous half-year. The scale is no longer measured in isolated attacks: it is measured in continuous production.

Illustrates the mechanics of automated credential stuffing: as soon as the infostealer captures data, the system validates it and launches it against thousands of platforms in parallel, without pause.
Speed without pause

The infostealer is no longer a program: it is an assembly line.

Variants such as Vidar, StealC, and Lumma lead this ecosystem. When they infect a device, they don’t just copy passwords: they extract active sessions, cookies, authentication tokens, and any high-value data. All of that information travels within seconds to automated distribution networks that sort it, filter it, and put it into circulation before the victim has finished their coffee.

The system tests everything, in parallel.

Stolen logs are fed into credential stuffing engines that attack thousands of platforms simultaneously. If your password works on one site, the system records it instantly. There is no hacker watching a screen: there is an autonomous process that ingests data, validates it, and monetizes it. Flashpoint calls it a machine-speed credential processing engine.

A machine that harvested 1.7 billion credentials in just six months.

Represents the expanded pattern: any connected user, regardless of size or relevance, is a valid target for these automated systems that do not discriminate between victims.
No one is left out

This pattern does not affect only large enterprises.

Any user with an active account is a valid target for automated systems that make no distinction between large or small victims.

Automation eliminates the cost of the attack, making it equally profitable to target millions at once.

Flashpoint recorded 6,256 ransomware victims during that period, a 45% increase over the previous six months.

The scale has already changed. So has the risk.

When an attack requires no human effort, defense cannot rely solely on reaction either. Understanding how this machinery works is the first step toward not feeding it unknowingly. And there are more layers to this story.

AI is redesigning the criminal marketplace.

Flashpoint captured more than 22 million posts about malicious AI use on forums and closed channels during the first half of 2026. Many actors are already deploying AI tools locally, without relying on underground networks. Access to open-source models has democratized the creation of malware and phishing scripts at near-zero cost.

Evidence of the expanded pattern: open-source AI and messaging platforms have become accessible, low-cost criminal infrastructure, redesigning the cybercrime marketplace from within.
AI in service

Telegram, Reddit, and GitHub have become criminal distribution infrastructure.

These platforms function as a distribution layer for malware and deception scripts. They are not the source of the problem, but they connect actors with their tools and victims at a speed that traditional defenses do not anticipate.

Vulnerabilities are also continuing to grow in parallel.

Flashpoint tracked 21,667 vulnerability disclosures, an 8% increase over before. Of these, 239 were being actively exploited, nearly triple the number recorded on the official CISA list. In addition, 6,808 had already been identified before NVD published them, dangerously narrowing the window between discovery and patching.

Automation, scale, and speed: the new trinity.

The criminal ecosystem already operates like an industry. The question is whether your digital hygiene is up to what that industry can already do.

What you can do

  • Enable two-factor authentication on all your important accounts.
  • Check whether your credentials have been leaked at Have I Been Pwned.
  • Download software only from official sources and always verify its origin.

How many of your passwords have gone months without changing and are still protecting everything?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Technical

In-depth explanations of how attack and defense techniques work in cybersecurity: from intrusion methods to malware analysis.

Educational, analytical content, useful to understand the “how” beyond the news of the moment.



RATING


8



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.