TL;DR: Attackers increasingly value fresh, working credentials over large legacy breach dumps because exposed usernames and passwords are more likely to authenticate before reset, according to Enzoic. That shifts the control problem from password strength alone to continuous exposure monitoring and faster remediation of usable secrets.
NHIMG editorial — based on content published by Enzoic: Cybercriminals Want Fresh Credentials, Not More Data
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: How should security teams respond when a monitored credential appears in breach data?
A: Treat the credential as compromised until proven otherwise.
Q: Why do fresh exposed credentials create more risk than old breach dumps?
A: Fresh exposures are more likely to contain active usernames and current passwords that still work.
Q: What do security teams get wrong about password complexity?
A: They often treat complexity as a proxy for security.
Practitioner guidance
- Prioritise fresh exposure over breach volume Build response queues around recently exposed credentials from breach feeds, infostealer intelligence, and endpoint telemetry.
- Add continuous credential exposure monitoring Track whether employee, contractor, and customer credentials appear in new breach data or malware-derived logs, then trigger resets and verification workflows automatically.
- Shorten the exposure-to-remediation window Measure the time from credential exposure detection to password reset, session revocation, and account validation.
What's in the full article
Enzoic's full article covers the operational detail this post intentionally leaves for the source:
- How fresh credential value changes attacker decision-making across breach dumps, infostealer logs, and password spraying activity.
- The relationship between credential context, including login URLs and recovery details, and successful account takeover attempts.
- Why infostealer malware changes exposure detection and how that alters the defender response timeline.
- How password policy, compromised-password screening, and continuous monitoring fit together in real-world remediation.
👉 Read Enzoic's analysis of why fresh credentials matter more than breach size →
Fresh credentials and account takeover risk: what IAM teams need now?
Explore further
Fresh credential trust debt is the real control gap: Organisations still behave as if credential risk is created at password issuance and resolved at password reset. That assumption fails when credentials are harvested from breach feeds or infostealers and remain valid long enough to be used. The implication is that exposure monitoring has become a first-class IAM control, not a secondary detective input.
A few things that frame the scale:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when account takeover exposes sensitive data?
A: Accountability sits across identity, security operations, and data governance because the incident spans authentication, access enforcement, and data protection. Frameworks such as OWASP NHI and NIST CSF both support the view that compromise response must include fast privilege restriction, not just detection and ticketing.
👉 Read our full editorial: Fresh credentials, not big breaches, now drive account takeover risk