Security experts are warning the UK 's largest companies that they are at risk of being hacked after hundreds of thousands of corporate credentials were found on cybercrime sites.

Socura partnered with Flare to monitor “ cybercrime communities ” on the clear and dark web for corporate FTSE 100 domains. The resulting report, FTSE 100 for Sale , revealed 460,000 compromised credentials belonging to employees of these companies.
Some companies had up to 45,000 exposed credentials, while 15 companies had more than 10,000 each. While this is a problem in many sectors, financial services (70,000+) was particularly affected.
See also: Remcos RAT C2 activity mapped
Much of the problem stems from the increased use of info-stealer malware. Socura and Flare found 28,000 corporate credentials in stealer logs – which equates to an average of 280 per FTSE 100 company.
"However, this number may only be the tip of the iceberg, as these are only the credentials we know from public leaks, dark web areas, and criminal channels," the report warned.

«A company could have many more stolen credentials that have not yet been sold, actively used, or distributed through channels unknown to us.».
The study also revealed that “poor password hygiene” continues to be a significant security challenge even for the country’s largest and most well-equipped organizations.
See also: Lazarus' new ScoringMathTea RAT allows remote command execution
Over half (59%) of FTSE 100 companies have at least one employee using the term “password” as a password. Password reuse was also common. One employee had three variations of the same password across six known breaches.
The report's authors also found CXO email addresses and passwords shared on dark web sites like Doxbin.
Credential leak to cybercrime sites – Protection
Socura's head of threat analysis, Anne Heim, explained that cybercriminals are essentially opportunists.
"Most people won't waste valuable time hacking credentials when they can easily find or buy them online," he said.
See also: UNC1549 targets aerospace and defense systems
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Implementing multi-factor authentication (MFA) with passkeys, monitoring threat exposure for new data breaches, and rapidly detecting and responding to malware and suspicious connections should be considered part of the baseline that all businesses must achieve to minimize risks.“.
The report's authors recommended:
- Implement strong password policies, use password managers , and train employees accordingly.
- Implement phishing-resistant MFA and passkeys across all devices and services
- Use access policies conditionalto grant access based on authentication strength, device compliance status, user risk level, and other factors.
- Proactively monitor the corporate attack surface, regularly checking for credential leaks and resetting passwords for compromised accounts.
- Implement a clear “Bring Your Own Device” (BYOD) policy that requires MFA to access any corporate services.
- Implement robust detection controls to identify and flag suspicious behavior, such as unusual connections and information-stealing malware.
Source: www.infosecurity-magazine.com
