Infostealers Weekly Report: 2020-06-22 – 2020-06-28
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 4,144
- #2 India 1,331
- #3 Spain 1,184
- #4 France 1,178
- #5 Germany 831
- #6 Indonesia 488
- #7 Brazil 409
- #8 Pakistan 342
- #9 Vietnam 290
- #10 Canada 271
- #11 Philippines 255
- #12 Turkey 205
- #13 Egypt 199
- #14 Thailand 199
- #15 Australia 182
- #16 Algeria 138
- #17 Mexico 125
- #18 United Kingdom 113
- #19 Malaysia 109
- #20 Poland 103
- #21 Bangladesh 96
- #22 Morocco 94
- #23 Sri Lanka 93
- #24 Belgium 90
- #25 Colombia 85
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 12,704 users
-
#2
facebook.com 8,735 users
-
#3
live.com 7,685 users
-
#4
amazon.com 4,346 users
-
#5
twitter.com 4,063 users
-
#6
netflix.com 3,946 users
-
#7
paypal.com 3,904 users
-
#8
twitch.tv 3,483 users
-
#9
minecraft.net 3,210 users
-
#10
roblox.com 3,208 users
-
#11
discordapp.com 3,169 users
-
#12
instagram.com 3,145 users
-
#13
epicgames.com 3,100 users
-
#14
steampowered.com 2,666 users
-
#15
steamcommunity.com 2,485 users
-
#16
yahoo.com 2,354 users
-
#17
mega.nz 2,260 users
-
#18
apple.com 2,121 users
-
#19
spotify.com 2,022 users
-
#20
1,915 users
-
#21
com.facebook.katana 1,860 users
-
#22
linkedin.com 1,850 users
-
#23
riotgames.com 1,835 users
-
#24
sonyentertainmentnetwork.com 1,792 users
-
#25
dropbox.com 1,735 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 58 employees
-
#2
k12.fl.us 36 employees
-
#3
icicibank.com 35 employees
-
#4
ovh.net 34 employees
-
#5
34 employees
-
#6
rediff.com 33 employees
-
#7
twc.com 24 employees
-
#8
jcyl.es 19 employees
-
#9
secureserver.net 18 employees
-
#10
freenet.de 18 employees
-
#11
qq.com 17 employees
-
#12
browardschools.com 17 employees
-
#13
spectrum.net 17 employees
-
#14
163.com 17 employees
-
#15
dadeschools.net 17 employees
-
#16
interia.pl 16 employees
-
#17
ovh.com 14 employees
-
#18
http://localhost/wordpress/wp-admin/install.php 14 employees
-
#19
vic.edu.au 13 employees
-
#20
digimail.in 13 employees
-
#21
peoplematter.com 13 employees
-
#22
cned.fr 12 employees
-
#23
lausd.net 12 employees
-
#24
ocps.net 12 employees
-
#25
houstonisd.org 12 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 58 employees
-
#2
twc.com 24 employees
-
#3
frontier.com 8 employees
-
#4
rockwellautomation.com 6 employees
-
#5
microsoft.com 5 employees
-
#6
amazon.com 4 employees
-
#7
netflix.com 4 employees
-
#8
cbre.com 4 employees
-
#9
aa.com 3 employees
-
#10
disney.com 3 employees
-
#11
bestbuy.com 3 employees
-
#12
costco.com 3 employees
-
#13
xerox.com 3 employees
-
#14
ford.com 3 employees
-
#15
jetblue.com 2 employees
-
#16
emc.com 2 employees
-
#17
uhsinc.com 2 employees
-
#18
jbhunt.com 2 employees
-
#19
statefarm.com 2 employees
-
#20
honeywell.com 2 employees
Compromised users
-
#1
google.com 12,701 users
-
#2
facebook.com 8,733 users
-
#3
amazon.com 4,345 users
-
#4
netflix.com 3,946 users
-
#5
paypal.com 3,903 users
-
#6
apple.com 2,120 users
-
#7
ebay.com 1,482 users
-
#8
walmart.com 767 users
-
#9
att.com 446 users
-
#10
capitalone.com 445 users
-
#11
target.com 428 users
-
#12
adp.com 406 users
-
#13
bestbuy.com 392 users
-
#14
ups.com 390 users
-
#15
wellsfargo.com 359 users
-
#16
oracle.com 355 users
-
#17
fedex.com 290 users
-
#18
bankofamerica.com 283 users
-
#19
nike.com 215 users
-
#20
hp.com 214 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 32,096hits
- #2 sso 10,348hits
- #3 adfs 2,929hits
- #4 webmail 1,942hits
- #5 zoom 1,938hits
- #6 github 1,276hits
- #7 owa 914hits
- #8 oracle 717hits
- #9 sap 638hits
- #10 sts 633hits
- #11 zendesk 623hits
- #12 imap 578hits
- #13 ping 512hits
- #14 ftp 502hits
- #15 cpanel 453hits
- #16 extranet 357hits
- #17 vpn 353hits
- #18 zimbra 337hits
- #19 webex 281hits
- #20 st 275hits
- #21 okta 204hits
- #22 salesforce 201hits
- #23 kaspersky 179hits
- #24 citrix 139hits
- #25 roundcube 127hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains