Infostealers Weekly Report: 2020-07-13 – 2020-07-19
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 4,924
- #2 Spain 1,255
- #3 Germany 793
- #4 France 477
- #5 Canada 424
- #6 United Kingdom 297
- #7 Australia 169
- #8 Israel 160
- #9 India 147
- #10 Belgium 143
- #11 Sweden 130
- #12 Philippines 128
- #13 Brazil 89
- #14 Japan 80
- #15 Pakistan 78
- #16 Indonesia 74
- #17 Turkey 37
- #18 Ireland 37
- #19 Italy 36
- #20 Vietnam 35
- #21 Mexico 34
- #22 Switzerland 34
- #23 Egypt 30
- #24 Poland 24
- #25 Argentina 20
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 9,104 users
-
#2
facebook.com 6,458 users
-
#3
live.com 6,209 users
-
#4
amazon.com 4,396 users
-
#5
paypal.com 3,798 users
-
#6
netflix.com 3,545 users
-
#7
twitter.com 3,215 users
-
#8
twitch.tv 2,864 users
-
#9
minecraft.net 2,365 users
-
#10
epicgames.com 2,353 users
-
#11
discordapp.com 2,332 users
-
#12
instagram.com 2,308 users
-
#13
roblox.com 2,219 users
-
#14
apple.com 2,164 users
-
#15
steampowered.com 2,147 users
-
#16
steamcommunity.com 2,033 users
-
#17
yahoo.com 2,032 users
-
#18
spotify.com 1,951 users
-
#19
ebay.com 1,858 users
-
#20
dropbox.com 1,713 users
-
#21
sonyentertainmentnetwork.com 1,608 users
-
#22
com.netflix.mediaclient 1,541 users
-
#23
linkedin.com 1,537 users
-
#24
1,534 users
-
#25
com.spotify.music 1,508 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 56 employees
-
#2
confused.com 33 employees
-
#3
twc.com 31 employees
-
#4
k12.fl.us 31 employees
-
#5
spectrum.net 28 employees
-
#6
one.com 22 employees
-
#7
21 employees
-
#8
roadrunner.com 20 employees
-
#9
secureserver.net 19 employees
-
#10
bluehost.com 19 employees
-
#11
rr.com 19 employees
-
#12
rmunify.com 19 employees
-
#13
ovh.net 19 employees
-
#14
mail.de 18 employees
-
#15
ionos.es 16 employees
-
#16
snhu.edu 15 employees
-
#17
dadeschools.net 15 employees
-
#18
1and1.es 14 employees
-
#19
hcps.net 14 employees
-
#20
jwpub.org 14 employees
-
#21
browardschools.com 14 employees
-
#22
ionos.com 14 employees
-
#23
hidemyass.com 14 employees
-
#24
movistar.es 13 employees
-
#25
maccabi4u.co.il 13 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 56 employees
-
#2
twc.com 31 employees
-
#3
bestbuy.com 8 employees
-
#4
frontier.com 5 employees
-
#5
verizon.com 5 employees
-
#6
microsoft.com 5 employees
-
#7
xerox.com 4 employees
-
#8
cognizant.com 4 employees
-
#9
ibm.com 4 employees
-
#10
ups.com 4 employees
-
#11
rockwellautomation.com 4 employees
-
#12
att.com 3 employees
-
#13
statefarm.com 3 employees
-
#14
delta.com 3 employees
-
#15
disney.com 3 employees
-
#16
charter.com 2 employees
-
#17
libertymutual.com 2 employees
-
#18
marriott.com 2 employees
-
#19
cablevision.com 2 employees
-
#20
nike.com 2 employees
Compromised users
-
#1
google.com 9,104 users
-
#2
facebook.com 6,458 users
-
#3
amazon.com 4,396 users
-
#4
paypal.com 3,798 users
-
#5
netflix.com 3,545 users
-
#6
apple.com 2,164 users
-
#7
ebay.com 1,858 users
-
#8
walmart.com 1,022 users
-
#9
capitalone.com 653 users
-
#10
att.com 598 users
-
#11
ups.com 594 users
-
#12
adp.com 583 users
-
#13
bestbuy.com 521 users
-
#14
target.com 513 users
-
#15
wellsfargo.com 455 users
-
#16
fedex.com 417 users
-
#17
bankofamerica.com 376 users
-
#18
costco.com 356 users
-
#19
americanexpress.com 332 users
-
#20
homedepot.com 317 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 32,824hits
- #2 sso 10,228hits
- #3 adfs 3,158hits
- #4 zoom 1,808hits
- #5 webmail 1,762hits
- #6 github 1,041hits
- #7 owa 1,009hits
- #8 zendesk 756hits
- #9 sts 725hits
- #10 sap 628hits
- #11 imap 582hits
- #12 ping 519hits
- #13 oracle 489hits
- #14 vpn 488hits
- #15 ftp 482hits
- #16 cpanel 388hits
- #17 okta 282hits
- #18 st 268hits
- #19 extranet 267hits
- #20 salesforce 250hits
- #21 webex 198hits
- #22 kaspersky 184hits
- #23 dana-na 166hits
- #24 roundcube 147hits
- #25 zimbra 136hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains