Skip to main content
Intelligence · Proprietary collection

Forty thousand leaked credentials, or the eight that still work?

ShadowMap runs its own stealer-log collection rather than reselling a feed, and keeps the raw source material permanently. That means two things a feed cannot do: it tells you which credentials still open something, and it improves your history every time our extraction improves.

12B+
Breach and credential records
~41TB
Raw source material retained
200–800

Stealer-log credentials surfaced in a first scan

A typical band, not a promise — the honest answer depends on your headcount, your sector and how long your people have been reusing passwords. What matters is not the count. It is how few of them still work, and which of those reach production.

The mechanism

One infected machine, seven kinds of evidence

A row-per-credential view loses the machine. We assemble the artefacts belonging to a single compromised device into one case, so you can tell a stale password from a live session.

  • Credentials
  • Session cookies
  • OAuth tokens
  • Payment cards
  • Wallet files
  • Autofill entries
  • Browser history

All of the above were recovered from one infected machine and are held as a single compromise case rather than as separate rows. The source material is retained in raw form, not just a supplier's parsed output, so an archive captured NaN months ago can be run through improved extraction at any point across the NaN months of retained material — which is how a machine compromised well before today surfaces as a new case this month.

Artefacts recovered from one infected device, assembled into a single compromise case The corpus band shows why retention matters: a machine compromised eighteen months ago can surface an artefact this month because the parser improved — not because anything new was stolen.

What you act on

Every credential carries its state

Volume is not a finding. A credential is probed and given one of four explicit states, so your queue is the ones that still open something rather than the ones that exist.

Every credential carries its state
StateWhat it meansWhat follows
Confirmed Working Probed and it authenticated. The account is reachable with this credential now. Rotate today, and check for session persistence.
Maybe Working Probing was inconclusive — rate limiting, an MFA interstitial, or an ambiguous response. Treat as live until you have checked it yourself.
Not Working Probed and rejected. The credential is stale against this service. Still evidence of a compromised device. Investigate the endpoint.
Not Tested Outside authorised scope, or no safe probe exists for the service. Verify internally. We never imply validation we did not perform.
Key
  • Act now
  • Assume live
  • Lower urgency
  • Needs your check

Why a feed cannot do this

We keep the raw material, so old data gets better

A reseller only ever has what its supplier chose, or was able, to parse at the time. We retain the source archives permanently and re-run improved parsers against them.

Worked example

A machine compromised eighteen months ago

What was extracted at the time
Usernames and passwords. The archive was password-protected and partially malformed, so everything past the credential block was skipped.
What was actually in it
Session cookies, an OAuth refresh token, autofill data including a corporate address, and browser history showing which internal tools the machine reached.
What changed
Our extraction improved. Because we still held the archive, we re-ran it — and the token was still valid. Nothing new was stolen; we simply became able to read what we already had.

Where it goes next

A credential is a lead, not a conclusion

Dark-web findings are most useful when something tests them. Leaked credentials are probed against the access paths that actually matter to you.

Questions buyers actually ask

Before you evaluate this

Everyone claims billions of records. Why is yours different?

Agreed, and the number is not the argument. Most vendors licence the same aggregated corpora, so the count mostly measures who they bought from. Two things separate ours: we keep the raw material, so when our extraction improves our history improves with it; and what we hand you is not a row count but a compromised device, with the credentials, cookies, tokens and access paths that belong together. The closing question for any incumbent is whether they can reprocess their own history. Most cannot, because they never had it.

Do you test the credentials you find?

Where it is safe and authorised, yes — and every credential carries an explicit state so you can see exactly what was and was not tested. Confirmed Working means it authenticated. Not Tested means we did not probe it, and we never imply validation we did not perform.

Which sources do you collect from?

We describe the collection at the level of what it does — automated source discovery across thousands of groups and sources, automated and password-protected archive handling, broad artefact extraction, and correlation to your identities and assets. We do not publish source names, channel topology or collection methods, because publishing them is how collection gets blocked.

Find out how many of your credentials still work

One apex domain, two business days, a written snapshot. No call required.