Common signs include unusual logins from new devices or geographies, repeated MFA prompts, account recovery attempts, password resets you did not initiate, and session activity that does not match normal user behavior. Security teams should also watch for leaked browser stored secrets, suspicious token use, and access to services the user rarely touches.
What to Look for When Credentials Have Been Exposed
When credentials are sold or shared through a fraud marketplace, or harvested by infostealer malware, the first signs usually show up as access anomalies rather than a clean “breach” event. New device fingerprints, unfamiliar geographies, repeated MFA prompts, and account recovery attempts often appear before an attacker tries to move laterally or change the account profile.
A second pattern is mismatch between the account’s normal usage and what the activity logs show. That includes sessions starting at unusual times, access to services the user rarely touches, token use that does not match the expected client, and browser-stored secrets or session material appearing in places they should not be.
For practitioners, the important signal is correlation: a single odd login may be noise, but multiple weak indicators across authentication, session use, and recovery workflows strongly suggest the credential has left trusted control. Review account telemetry alongside endpoint data, browser artefacts, and password manager or vault events where available.
Why Infostealer Exposure Often Looks Like “Normal” Access at First
Infostealer campaigns are designed to harvest usable authentication material quietly, which means the victim may still sign in successfully while an attacker reuses stolen passwords, cookies, or tokens elsewhere. That is why exposed credentials frequently show up as valid logins from a new environment rather than outright authentication failure.
In fraud-marketplace cases, the exposed material may be resold or combined with other stolen data, so the first abuse can be a password reset, an MFA fatigue attempt, or a recovery flow takeover. If the account has long-lived sessions or weak token hygiene, an attacker may not need the password again after initial access.
For that reason, the strongest evidence is often behavioural drift: access from new infrastructure, a different browser or operating system profile, unusual API or console activity, and access patterns that do not fit the account’s historical role. NHIMG’s Guide to the Secret Sprawl Challenge is useful background on how exposed secrets and credential sprawl create these downstream signals, and CircleCI Breach shows how stolen session material can translate into broader access.
Risk and Threat Considerations
Exposed credentials are risky because the attacker does not need to break the account, only reuse what was already trusted. Once a credential, token, or browser session is in circulation, the compromise can persist across password changes if the attacker also captured session material or recovery paths.
Failure mechanism: Infostealer malware, phishing, or repository leakage captures reusable secrets, then an attacker tests them quietly against common services, often using residential infrastructure or rotating proxies to reduce detection.
Impact: The account may be used for fraud, data theft, mailbox or SaaS takeover, privilege escalation, and further credential harvesting, especially when the exposed secret grants access beyond the original user’s normal scope.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Exposed credentials and stolen tokens are central to this sign-of-compromise question. |
| NHI-05 — Discovery and Visibility | Detection depends on spotting anomalous logins, session use, and secret leakage. | |
| NHI-08 — Lifecycle and Offboarding | Stolen credentials remain dangerous when sessions and access paths are not invalidated. | |
| Recommendation — Inventory, rotate, and revoke exposed secrets and tokens quickly. Monitor identity and session telemetry for deviations from normal access patterns. Revoke active access paths and stale sessions as soon as exposure is suspected. | ||
| CIS Controls v8 | 5 — Account Management | This topic depends on detecting and responding to compromised accounts and recovery abuse. |
| 6 — Access Control Management | Credential exposure often enables unauthorized access that access controls must limit. | |
| 8 — Audit Log Management | Anomalous login, token, and recovery events are the primary evidence here. | |
| Recommendation — Review account usage and disable compromised accounts promptly. Restrict access paths and enforce least privilege for exposed credentials. Collect and review authentication, session, and recovery logs for anomalies. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Attackers commonly reuse stolen credentials, tokens, or sessions as valid access. |
| T1110 — Brute Force | Marketplace-listed credentials are often tested at scale against services and recovery flows. | |
| T1555 — Credentials from Password Stores | Infostealers commonly harvest browser-stored secrets and other credential material. | |
| Recommendation — Hunt for authenticated activity that uses compromised valid accounts. Detect repeated authentication and recovery attempts against user accounts. Search endpoints for credential theft from browsers, stores, and local secret caches. | ||
| NIST CSF 2.0 | DE.CM — Continuous Monitoring | The answer relies on spotting anomalous behaviour in logins, sessions, and access use. |
| Recommendation — Continuously monitor authentication and session activity for abnormal patterns. | ||
Practitioner Guidance
What to verify: Treat login anomalies as evidence of possible exposure only after checking whether the session, device, and token lineage fit the account’s normal pattern. If the account can authenticate from an unfamiliar device but also shows recovery attempts, repeated MFA prompts, or browser secret leakage, prioritise containment over user reassurance.
Decision rule: If you can confirm that the exposed material includes a password, refresh token, session cookie, API key, or browser-stored secret, assume the attacker may have more than one path back into the account. Rotate the credential, revoke active sessions, and invalidate related tokens before you spend time proving how the initial exposure occurred.
Practitioner takeaway: The most reliable sign is not a single alert, but a cluster of small mismatches that indicate the account is being used with trusted material outside its normal context.
Related resources from NHI Mgmt Group
- What are the signs that stolen credentials from infostealer malware are being used in real attacks?
- Why do exposed credentials matter more when attackers use AI-assisted malware?
- Why do browser-stored credentials increase the impact of infostealer malware?
- Who is accountable when mobile malware exposes enterprise credentials through a compromised device?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org