Credential Theft Surges 160% in 2023, Driving Major Security Breaches

Students walk on an outdoor part of a university campus.

A significant surge in leaked credentials marked 2023, with a 160 percent increase compared to the previous year, reshaping the cybersecurity landscape. The Verizon 2025 Data Breach Investigations Report indicates that leaked credentials played a role in 22 percent of data breaches, serving as primary entry points for attackers to infiltrate organizational systems. The trend matches a broader pattern of credential-based attacks that has led major companies like Mastercard and Microsoft to announce plans for eliminating traditional passwords in favor of more secure authentication methods.

The impact of credential theft manifested notably in the RubyGems ecosystem, where security researchers identified 60 malicious packages operating since March 2023. These packages, while presenting themselves as automation tools for social media and messaging platforms, functioned as credential theft mechanisms. In a separate incident, the GreedyBear group used over 150 malicious Firefox wallet extensions to orchestrate the theft of $1 million in cryptocurrency assets. The attack methodology mirrors recent incidents like the T-Mobile breach by LAPSUS$, where compromised credentials enabled attackers to access critical systems.

Cybersecurity experts, including former FBI personnel, recommend several preventive measures to combat credential-based threats. These include regular password audits and updates, especially for critical accounts, avoiding password reuse across multiple platforms, using VPNs on public networks, and implementing credit locks with reporting agencies. The rise of biometric authentication has emerged as a particularly promising solution, with recent studies showing that most consumers prefer biometric security measures over traditional password-based systems.

A former FBI agent and cybersecurity expert shared a relevant case study involving his father, a former MasterCard CEO and FBI agent, who experienced unauthorized withdrawals from his checking account due to unaddressed compromised credentials. The incident highlights the vulnerability of even security-conscious individuals to credential theft, particularly as SIM swap fraud and other sophisticated attack methods continue to evolve.

The documented increase in leaked credentials throughout 2023 represents a significant shift in attack vectors, highlighting the necessity for enhanced security protocols at both organizational and individual levels. In response, major financial institutions and technology companies are increasingly adopting passwordless authentication systems and implementing additional security measures to protect against credential-based attacks.

Sources: WIU Cybersecurity Center, AOL, Security-Portal.cz