Nearly half a million stolen credentials have surfaced across FTSE 100 firms, spanning both the clear and dark web, with a new report giving a stark warning about the rising dangers of infostealer malware and the use of weak passwords.
After analysing the domains of every FTSE 100 company, UK cybersec firm Socura discovered more than 460,000 instances of compromised logins for blue-chip firms, and even evidence of a potential death threat made against one CEO.Â
Produced in partnership with threat management platform Flare, Socura’s report, FTSE 100 For Sale, found that fifteen FTSE companies each had over 10,000 stolen credentials exposed online, with one firm alone linked to as many as 45,000 leaked credentials.
The proliferation of infostealer malware is driving the crisis. Socura and Flare uncovered 28,000 stolen corporate credentials leaked via infostealer logs, which are often traded via darknet forums and shady Telegram channels for as little as $10 (£7.63).
While the sheer volume of infostealer malware found lurking among the FTSE 100 is a serious risk, with stolen passwords opening the door to network-wide ransomware, employees are making things worse in their persistent use of weak passwords.
The report found that 59% of FTSE 100 firms had at least one employee using ‘password’ as their password, while 47% saw ‘Password’ being used, and 28% had some staff using the laughably crackable ‘123456’ as their login.
Added to that, Socura found that more than a quarter of FTSE firms (28%) even see some employees using ‘welcome’ as their login, while 15% had staff who never changed their password past ‘default’.
Though credential leaks and weak passwords pose risks across the board, the problems are worse when senior leaders are the ones compromised.Â
Recommended reading
- Operation Endgame Takes Down Major Cyber-crime Infrastructure
- 53% of Malware-infected Devices are Corporate
- Report: Data-Stealing Malware Threatens Millions Worldwide
From a sample of just twelve FTSE 100 CEOs, Socura uncovered four instances of personal data posted on Doxbin, an illicit site known for exposing cyber-attack targets, and three linked to last year’s DemandScience breach, which compromised data from over 122 million individuals.Â
The study also uncovered the case of an FTSE 100 CEO’s corporate email linked to the infamous MyFitnessPal breach in 2018, alongside a disturbing instance of a potential death threat posted to 4chan.
“Cybercriminals are opportunists. Most won’t waste precious time hacking for credentials when they can easily find or buy them online,” said Anne Heim, threat intelligence lead at Socura.Â
“Implementing Multi-Factor Authentication, using passkeys, monitoring threat exposure for new data leaks, and swiftly detecting and responding to malware and suspicious logins need to be considered part of the baseline that all businesses need to achieve to minimise risks.”
Join the Conversation
Don’t miss DIGIT Expo 2025 on 27 November at the EICC Edinburgh – Scotland’s largest tech showcase featuring 5 stages of keynotes, 60+ exhibitors and networking with 1,700+ IT & digital professionals.
Secure your free ticket now: Register here





