Skip to main content
All customer stories
Telecommunications

From 57,300 leaked credential records to 23 accounts worth rotating today

Client: A mobile network operator in Southeast Asia serving roughly 21 million subscribers across two consumer brands, with about 7,500 employees, close to 3,000 franchised retail outlets and an outsourced contact-centre operator in a neighbouring country · details anonymised

The Challenge

A 40,000-row credential report that nobody could act on

The operator had bought dark-web monitoring during a previous capability review and had renewed it twice. What it received was a flat table of email addresses and passwords, refreshed monthly, with no provenance, no liveness and no distinction between a staff identity on the corporate identity provider and a subscriber on the consumer self-care app. The security team had two options, both bad: force a blanket reset the service desk would resist and that would not touch a stolen session cookie, or leave the report unactioned and own that decision at the next audit. Endpoint telemetry did not close the gap, because the machines most likely to be carrying stealer infections — franchised dealer PCs, contact-centre workstations run by a supplier, staff personal devices used for webmail — sit outside the operator's endpoint management by design.

The Solution

Reconstruct the compromise, not the row

ShadowMap treated the infected machine, rather than the credential row, as the unit of analysis. Artefacts were grouped by device to establish infection date, repeat observation, and the full set of what each machine held — credentials, cookies, tokens, autofill data and browser history — then ranked by recency and by whether the machine carried session material for the identity provider or administrative surfaces. Attack Surface and Asset Explorer supplied the other half of the correlation: matching the URL a credential was captured against to an asset the operator actually owns is what turns a brand-name string match into a finding about the dealer portal. CART then validated a bounded, authorised set of credentials against the operator's own login surfaces, recording confirmed-live and confirmed-dead results with equal weight, and stating explicitly where no test was performed.

The Results

Twenty-three rotations the same day, and a queue small enough to review weekly

The act-now list ran to 41 items and closed inside 48 hours: 23 confirmed-working credentials rotated, 14 identity-provider session sets revoked, and four shared dealer-portal logins retired in favour of per-user accounts. A second tier of 48 credentials where the first factor was accepted but MFA held was rotated over the following fortnight. The consumer population was handled as a targeted intervention rather than a mass reset — 610 subscriber accounts whose credentials originated from recent infections received a forced reset and step-up authentication, while the remaining 7,680 went to monitoring. Median time from a record entering the corpus to rotation of a confirmed-working credential fell to under 24 hours, against a previous cycle governed by a monthly feed delivery.

Full Case Study

· 6 min read

You do not act on 40,000. No security team can, and the figure was never built to be acted on — it is a match count against a breach corpus, and a breach corpus is mostly history. The question worth asking is much narrower, and it has two parts: which of these credentials would authenticate against something we own if someone tried it this afternoon, and which of them sit on a machine that is still infected right now. Everything else belongs in a monitoring queue, not an escalation.

When this operator ran ShadowMap alongside its incumbent feed during a three-week evaluation, ShadowMap matched 57,300 raw credential records — more than the 40,000 the incumbent reported, because the collection is broader. That was not the point, and a bigger raw number is not a better product. Those 57,300 records collapsed to 11,900 unique identity–credential pairs, of which 3,610 belonged to corporate or dealer identities rather than consumer subscribers, and 41 were placed in the Act Now queue. Twenty-three accounts were rotated the same day. Fourteen active session sets were revoked at the identity provider. Four shared dealer logins were retired. The rest of the estate was not reset, and the service desk was never asked to reset it.

What the incumbent report could not tell them

The operator serves roughly 21 million subscribers across two consumer brands, employs about 7,500 people, and sells through close to 3,000 franchised outlets plus an outsourced contact centre in a neighbouring country. The identity estate reflects that shape: staff on a corporate identity provider, dealers on a separate franchise portal, subscribers on a self-care app. The incumbent report ignored all three distinctions and sorted by nothing in particular.

Cross-referenced afterwards, roughly 31,000 of the incumbent's 40,000 rows traced to two aggregated regional dumps dated 2016 and 2017 against the consumer self-care portal — which had forced a full credential reset in 2019. Dead by construction. The incumbent had no way to know that, because a credential row does not carry its own provenance unless somebody keeps the source material and can reprocess it.

Counting properly before counting loudly

Deduplication came first, because resellers repackage the same dumps and the same row can arrive a dozen times under a dozen names. At 4.8 raw rows per unique pair, the headline number was inflated by nearly five before anyone had assessed a single credential.

Then attribution. A stealer log records the URL a credential was captured against, and matching that URL to an asset discovered by Attack Surface is what turns a password with our brand in the email domain into a password for our dealer portal. The correlation ran in both directions and made the queue smaller: 2,177 of the corporate and dealer pairs pointed not at the operator at all, but at third-party services staff had signed up to with a work address.

The unit of analysis is the machine, not the row

Grouping artefacts by infected device produced 287 distinct machines carrying at least one item linked to the operator. Each became a case rather than a row: infection date, first and last observation, and the complete inventory of what that machine held — credentials, cookies, tokens, autofill data, browser history, device details.

That reconstruction is what separates a stale password from a live compromise. Of the 287, 96 showed infection activity in the trailing 120 days. Of those, 31 held session material for operator-owned domains, and 14 held session sets for the corporate identity provider or SSO-fronted administrative surfaces. Those 14 were the finding. A valid session cookie is indifferent to a password changed this morning, which is exactly why a rotation-only response to a credential report gives false comfort.

Thirty-four machines appeared in two or more collection deliveries weeks apart — evidence the infection had never been remediated. The largest single grouping was not corporate laptops at all; it was dealer outlet PCs and workstations at the contact-centre supplier.

AI Review sorted the queue into Confirmed Exposure, Needs AI Review, Likely False Positive and Benign. Benign rows moved to Filtered by AI, where they remain visible and reversible — nothing is deleted, and an analyst verdict always overrides the model.

What was validated, and what deliberately was not

Of the 3,610 corporate and dealer pairs, 1,433 targeted a login surface the operator owns and had authorised for testing. CART tested all of them and reported in three states:

  • 23 confirmed working — a real authentication response, not an inference drawn from a credential's format or age. Each carries evidence and an audit identifier so the operator could reconcile the validation activity against its own logs.
  • 1,362 confirmed rejected. Reported rather than quietly dropped: a credential confirmed dead removes noise while keeping the architectural signal that the account and its surface were once exposed.
  • 48 returned a second-factor challenge — the first factor was accepted and MFA held. ShadowMap did not proceed past the challenge, and reported them as password valid, not carried further, rotate this cycle.

Three things were deliberately not tested, and each finding says so:

  • No subscriber credential was tested. Authenticating to a consumer account is neither authorised nor appropriate, whatever the credential's apparent status.
  • The 2,177 pairs pointing at third-party services were not tested, because the operator cannot authorise testing against someone else's endpoint. They carry not tested — confirm and rotate with the provider.
  • Session cookies were not replayed. Scope was established from issuing domain, path and expiry and reported as revoke server-side. The operator's own identity-provider logs subsequently confirmed 11 of the 14 session sets were still valid — its verification, not ours.

Modules that found nothing said so. No corporate payment instrument appeared in compromised card artefacts. Compromised wallets returned nothing. No post offering access to the operator's network was found in the reporting window. Negative assurance is evidence that a module looked.

What they did

The 41 Act Now items went into Action Center with a named owner, an SLA and a ticket in the operator's service-management tool: 23 rotations, 14 session revocations, four shared dealer logins replaced with per-user accounts. All closed within 48 hours, the rotations inside the day. The 48 MFA-held credentials were rotated over the following fortnight.

The consumer queue was not a reset exercise. Of 8,290 subscriber pairs, 610 originated from stealer infections in the trailing 180 days; those accounts received a forced reset and step-up authentication on the self-care app. The remaining 7,680 went to monitoring, most predating the 2019 portal reset.

The 2,177 third-party pairs turned out to be a governance finding rather than a security one: 190 distinct SaaS services in use with corporate addresses, 63 of them absent from the sanctioned application register. That went to IT governance. The 34 repeat-infection machines went to procurement, and produced a device-hygiene clause and a re-infection reporting obligation in the contact-centre supplier's contract.

What changed, and what it meant for governance

Median time from a record entering the corpus to rotation of a confirmed-working credential is now under 24 hours, against a cadence previously set by a monthly feed delivery. The credential programme is a thirty-minute weekly review of a queue in the tens, not a quarterly argument about a spreadsheet in the tens of thousands. Repeat infection on unmanaged devices — previously invisible to the operator entirely — is now tracked and contractually addressable.

For reporting, each cycle produces a dated scan window, a named scan session, a stated counting methodology (the unique identity–credential pair is the unit; raw row counts are reported separately and never presented as the exposure figure), and a validation state per finding. The Security Rating trend gives the board a line rather than an anecdote. And the auditor's question — how do you know your credential exposure is being managed? — now has an answer with dates, owners, states and evidence in both directions: what was live, what was confirmed dead, and what was not tested and why.

The point was never that 57,300 was wrong. It is that 57,300 is an observation, and 41 is a decision.

Related to

dark web monitoring for telecoms stealer log monitoring leaked credential validation infostealer infected device detection compromised credential triage session cookie theft detection corporate credential exposure monitoring dark web report too many findings identity provider session revocation credential rotation prioritisation machine level credential correlation dark web monitoring alternative

Ask what ShadowMap would find on your assets.

A 30-minute live walk-through with a ShadowMap engineer on your own domains. We map you live; you keep the report whether or not you choose to engage.