← Back to News

One Infection, Every Password: What Real Malware Data Shows Us

10 September 2026

The Risk

Most password advice treats every account as if it's attacked on its own — reuse warnings, strength meters, periodic reset reminders. That framing misses how credential theft actually works today. It isn't one password at a time. It's everything on a device, at once.

The Threat

We analysed real data from "info-stealer" malware — malicious software that, once it's on a device, quietly copies every username and password saved in the browser and hands the whole haul to whoever deployed it. This isn't a rare or exotic threat: it's one of the most common types of malware in circulation, and the stolen data it produces gets traded across dark web and underground criminal channels within days of a device being infected. The picture from our own collection is stark.

In two out of three infections (67%), a single piece of malware sitting on one device exposed six or more separate online accounts in one automated sweep — email, banking, work logins, social media, all harvested in the same moment. In four out of ten infections (40%), it was more than twenty accounts from one device.

The damage doesn't stop at what the malware directly grabbed, either. Of victims whose stolen data spanned more than one account, 63% had reused the exact same password across at least two of them. That means accounts the malware never touched are still exposed the moment an attacker takes the stolen password and simply tries it on other websites — a technique called credential stuffing, and it only works because people repeat passwords.

The passwords themselves rarely put up a fight. Roughly a quarter (27%) were eight characters or shorter, and the single most common structure we found — a word followed by a couple of digits — appeared in almost one in four (24%) of all the passwords we examined.

The Fix

  • Assume one bad click can cost you everything saved in your browser, not just one account. An info-stealer infection harvests everything at once — it isn't a targeted attack on a single login.
  • Never reuse passwords across sites. A password manager makes this effortless, and it's the single biggest lever against the fan-out we saw in 63% of multi-account victims.
  • Turn on multi-factor authentication (MFA) everywhere it's offered — the extra confirmation step (a code on your phone, an app prompt) beyond just your password. It's the one control that still holds after a password has already been stolen.
  • Be deliberate about what you install. Cracked software and shady downloads remain the most common way this malware actually gets onto a device.
  • If you suspect a device is compromised, rotate everything saved on it — not just the one password you're worried about.

This is drawn from our own live threat intelligence collection — the actual credential-theft ecosystem attackers are trading in right now, not a hypothetical.

⚙