New data from Check Point has revealed an alarming surge in compromised credentials this year, with a staggering 160% increase compared to 2024, accounting for one-in-five data breaches.
The cyber firm’s latest report, The Rise of Leaked Credentials, puts the increase down to the increasing use of AI by threat actors, which has allowed for more sophisticated phishing attempts by less experienced attackers, as well as several new infostealer ‘families’ entering the scene.
This is creating a larger problem than ever for firms, with Check Point reporting 14,000 cases in which employee credentials were exposed in data breaches in just a single month late last year, and stolen credentials originating from GitHub repositories taking more than three months on average for businesses to remediate.
Websites and domains owned by Discord, Microsoft and Facebook were the most frequently impacted by leaked credential attacks, though Roblox is among the top five URLs targeted, suggesting that cyber-criminals are extending their reach.
Google accounts, however, are particularly at risk, with Gmail being a top attack vector for credential-stealing crooks, accounting for 68% of exposures involving email hostnames, compared to just 9% for Hotmail and 2% for Outlook.
Check Point said that while far more personal email accounts are targeted by stolen credential attacks than work accounts, this means breaches focus more on consumers rather than employees, leaving businesses at risk of compromised customer accounts.
Key findings from the latest Gen Threat Report, released earlier this year, illustrate the problem, with individual breached records surging by more than 186% over the first quarter of 2025, compared to a 36% increase in the number of breaches faced by companies.
However, despite the increase in credential attacks, Check Point’s figures indicate that UK businesses and consumers are perhaps not cyber-criminals first choice of victim, with the data showing them most frequently targeting densely populated countries with generally lower cybersecurity awareness.
Brazil and India, for example, face especially high rates of credential theft, accounting for more than 7% of cyber-attacks, while others like Indonesia (4.28%), Vietnam (4.23%), Pakistan (4.13%) and Egypt (3.89%) are also most at risk.
One outlier to this trend is the US, which appeared in Check Point’s top ten countries for credential theft both in 2024 and this year, but the rate of attacks has halved, which could indicate that American companies are introducing better protections, forcing threat actors to turn their attention elsewhere.
Recommended reading
- Darcula Phishing Scam Claims 800K+ Victims
- Deepfake Fraud Explodes 2,000% In Three Years
- NCSC Warns Fancy Bear Malware Hijacking Email Accounts
“Despite extensive cybersecurity protections and training, attackers still may manage to break into databases or use phishing to trick even the most savvy employees into revealing login information, a risk made all the worse by AI, which helps attackers execute sophisticated phishing breaches at scale,” says the report.
“So, rather than investing in prevention alone, businesses must also ensure that when passwords associated with their employees, customers or brand are leaked, they know right away.”
According to Check Point, to guard against these threats, organisations should look to introduce robust password management policies, including enforcing regular password updates, prohibiting password reuse, as well as using MFA to make it harder for attackers to log in with just a username and password.
They should also look to put limits on login attempts to prevent brute force attacks, restrict user access rights to the bare minimum necessary, block access to third-party websites that may have weaker security, and, most importantly, continually train employees to recognise the latest phishing tactics.





