Approximately half of the accounts that have been compromised in phishing attacks are used within 12 hours of the username and password leak, as hackers try to exploit the stolen credentials as quickly as possible.

See also: Russian hackers behind massive spear-phishing campaign that hit Ukraine
Cybersecurity researchers at Agari planted thousands of credentials that were crafted to look like they belonged to real users, but were actually under the researchers' control.
The fake credentials were designed to resemble compromised connections for known cloud software applications.
The researchers found that access to accounts by hackers becomes active within a few hours from the date the login credentials are posted on phishing sites and forums.
“About half of the accounts were accessible within 12 hours of us putting up the alleged websites. 20% were accessible within an hour and 40% within six hours. This really shows how quickly a compromised account is exploited,” said the senior manager of threat research at Agari.
See also: Navistar: Military vehicle manufacturer victim of data breach
Most accounts were compromised manually. This method proves useful for cybercriminals as they can accurately check whether the credentials actually work.

For example, with access to an account, an intruder can try to find sensitive information in users' incoming emails or even in cloud storage software that could be stolen or used to facilitate further attacks.
There is also the possibility that hackers will use compromised accounts to carry out other attacks, such as phishing or BEC, using the compromised account to launch further campaigns.
However, in this case, because the fake credentials were being checked by researchers, no attack attempt actually reached its target.
While access to compromised accounts is quick, the research found that accounts are often abandoned after about a week.
See also: NSW Health: Data breach through vulnerability in Accellion system
Organizations can take precautions to defend their credentials, cloud applications, and the broader network from phishing and other attacks. One of these is proper defense, such as antivirus protection software or a spam filter.
Meanwhile, using multi-factor authentication can help prevent the exploitation of compromised accounts, as it makes it much harder for an attacker to use them, while also notifying the victim that something is going wrong.
