Infostealers Weekly Report: 2019-03-25 – 2019-03-31
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 812
- #2 Indonesia 608
- #3 Brazil 513
- #4 Germany 432
- #5 Canada 322
- #6 Poland 223
- #7 United States of America 165
- #8 Pakistan 162
- #9 Philippines 128
- #10 Vietnam 107
- #11 France 101
- #12 Russia 93
- #13 Bangladesh 89
- #14 Egypt 69
- #15 United Kingdom 60
- #16 Colombia 59
- #17 Serbia 58
- #18 Romania 58
- #19 Turkey 50
- #20 Argentina 49
- #21 Mexico 42
- #22 Algeria 40
- #23 Iran 39
- #24 Unknown Region 37
- #25 Hungary 34
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 3,872 users
-
#2
facebook.com 3,350 users
-
#3
live.com 1,803 users
-
#4
twitter.com 965 users
-
#5
yahoo.com 797 users
-
#6
paypal.com 751 users
-
#7
instagram.com 682 users
-
#8
netflix.com 653 users
-
#9
631 users
-
#10
mega.nz 614 users
-
#11
discordapp.com 558 users
-
#12
amazon.com 527 users
-
#13
epicgames.com 525 users
-
#14
dropbox.com 521 users
-
#15
192.168.1.1 519 users
-
#16
steampowered.com 517 users
-
#17
linkedin.com 516 users
-
#18
twitch.tv 494 users
-
#19
roblox.com 493 users
-
#20
apple.com 488 users
-
#21
steamcommunity.com 467 users
-
#22
minecraft.net 357 users
-
#23
ea.com 348 users
-
#24
sonyentertainmentnetwork.com 327 users
-
#25
192.168.0.1 324 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
interia.pl 30 employees
-
#2
o2.pl 27 employees
-
#3
POP3://pop.gmail.com:995 24 employees
-
#4
rediff.com 22 employees
-
#5
onet.pl 19 employees
-
#6
icicibank.com 13 employees
-
#7
11 employees
-
#8
netpnb.com 11 employees
-
#9
onlinesbi.com 7 employees
-
#10
secureserver.net 7 employees
-
#11
freenet.de 7 employees
-
#12
digimail.in 6 employees
-
#13
ig.com.br 6 employees
-
#14
dpcdsb.org 6 employees
-
#15
freemail.hu 6 employees
-
#16
alberta.ca 5 employees
-
#17
accenture.com 5 employees
-
#18
POP3://pop3.web.de:995 5 employees
-
#19
tlen.pl 5 employees
-
#20
telecom.pt 5 employees
-
#21
globo.com 5 employees
-
#22
confused.com 4 employees
-
#23
POP3://pop.gmx.net:995 4 employees
-
#24
tcdsb.org 4 employees
-
#25
abacom.com 4 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
cognizant.com 3 employees
-
#2
johnsoncontrols.com 1 employees
-
#3
starwoodhotels.com 1 employees
-
#4
sysco.com 1 employees
-
#5
aecom.com 1 employees
-
#6
twc.com 1 employees
-
#7
morganstanley.com 1 employees
-
#8
microsoft.com 1 employees
-
#9
hp.com 1 employees
Compromised users
-
#1
google.com 3,871 users
-
#2
facebook.com 3,350 users
-
#3
paypal.com 751 users
-
#4
netflix.com 653 users
-
#5
amazon.com 527 users
-
#6
apple.com 488 users
-
#7
ebay.com 251 users
-
#8
oracle.com 48 users
-
#9
hp.com 37 users
-
#10
ups.com 30 users
-
#11
adp.com 30 users
-
#12
americanexpress.com 27 users
-
#13
walmart.com 25 users
-
#14
microsoft.com 24 users
-
#15
capitalone.com 23 users
-
#16
nike.com 22 users
-
#17
ibm.com 20 users
-
#18
westernunion.com 19 users
-
#19
bestbuy.com 18 users
-
#20
wellsfargo.com 16 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 3,989hits
- #2 sso 1,616hits
- #3 imap 508hits
- #4 webmail 423hits
- #5 adfs 278hits
- #6 ftp 231hits
- #7 owa 162hits
- #8 github 139hits
- #9 sap 134hits
- #10 cpanel 132hits
- #11 oracle 121hits
- #12 zendesk 116hits
- #13 sts 116hits
- #14 st 74hits
- #15 extranet 71hits
- #16 kaspersky 59hits
- #17 vpn 58hits
- #18 zimbra 35hits
- #19 ping 30hits
- #20 citrix 26hits
- #21 bitbucket 25hits
- #22 salesforce 24hits
- #23 zoom 18hits
- #24 roundcube 17hits
- #25 webex 15hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-18 – 2026-05-25
- 14K machines
- 4K users
- 187K domains
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains