Info-Stealers Statistics Weekly Report: 2022-05-02 – 2022-05-08
Info-Stealers Statistics Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 Brazil 6,521
- #2 India 5,398
- #3 Indonesia 4,379
- #4 Vietnam 4,321
- #5 Philippines 3,467
- #6 Egypt 2,297
- #7 Thailand 2,238
- #8 Pakistan 2,145
- #9 Mexico 2,121
- #10 United States of America 1,820
- #11 Peru 1,563
- #12 Colombia 1,477
- #13 Argentina 1,192
- #14 Algeria 1,180
- #15 Turkey 1,116
- #16 Morocco 1,013
- #17 Poland 864
- #18 Germany 836
- #19 Bangladesh 752
- #20 Malaysia 739
- #21 Ecuador 733
- #22 France 716
- #23 Italy 705
- #24 Venezuela 682
- #25 Spain 654
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
37,020 users
-
#2
google.com 26,023 users
-
#3
facebook.com 22,365 users
-
#4
live.com 19,619 users
-
#5
discord.com 11,866 users
-
#6
roblox.com 11,637 users
-
#7
instagram.com 9,960 users
-
#8
netflix.com 9,583 users
-
#9
com.facebook.katana 9,060 users
-
#10
twitter.com 9,001 users
-
#11
amazon.com 7,950 users
-
#12
steampowered.com 7,943 users
-
#13
twitch.tv 7,597 users
-
#14
riotgames.com 7,028 users
-
#15
paypal.com 6,985 users
-
#16
mega.nz 6,187 users
-
#17
epicgames.com 6,036 users
-
#18
com.instagram.android 5,762 users
-
#19
microsoftonline.com 5,703 users
-
#20
com.netflix.mediaclient 5,670 users
-
#21
steamcommunity.com 5,554 users
-
#22
com.discord 5,035 users
-
#23
spotify.com 4,861 users
-
#24
apple.com 4,666 users
-
#25
com.spotify.music 4,618 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
470 employees
-
#2
icicibank.com 95 employees
-
#3
rediff.com 76 employees
-
#4
163.com 55 employees
-
#5
sp.gov.br 53 employees
-
#6
interia.pl 50 employees
-
#7
o2.pl 46 employees
-
#8
onet.pl 45 employees
-
#9
aruba.it 45 employees
-
#10
telecom.pt 44 employees
-
#11
utp.edu.pe 43 employees
-
#12
qq.com 42 employees
-
#13
accenture.com 41 employees
-
#14
hostinger.com 40 employees
-
#15
deped.gov.ph 37 employees
-
#16
tim.it 37 employees
-
#17
netpnb.com 33 employees
-
#18
jwpub.org 33 employees
-
#19
digimail.in 32 employees
-
#20
pec.it 32 employees
-
#21
secureserver.net 32 employees
-
#22
aiou.edu.pk 31 employees
-
#23
bcb.gov.br 29 employees
-
#24
secop.gov.co 28 employees
-
#25
britanico.edu.pe 28 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
microsoft.com 20 employees
-
#2
rockwellautomation.com 14 employees
-
#3
publix.com 11 employees
-
#4
netflix.com 9 employees
-
#5
apple.com 5 employees
-
#6
hp.com 4 employees
-
#7
cbre.com 4 employees
-
#8
amazon.com 4 employees
-
#9
ibm.com 3 employees
-
#10
csc.com 3 employees
-
#11
newmont.com 2 employees
-
#12
tjx.com 2 employees
-
#13
westrock.com 2 employees
-
#14
cognizant.com 2 employees
-
#15
aramark.com 2 employees
-
#16
ups.com 2 employees
-
#17
dupont.com 1 employees
-
#18
rgare.com 1 employees
-
#19
paccar.com 1 employees
-
#20
cisco.com 1 employees
Compromised users
-
#1
google.com 26,023 users
-
#2
facebook.com 22,365 users
-
#3
netflix.com 9,583 users
-
#4
amazon.com 7,950 users
-
#5
paypal.com 6,985 users
-
#6
apple.com 4,666 users
-
#7
ebay.com 1,147 users
-
#8
oracle.com 845 users
-
#9
cisco.com 611 users
-
#10
nike.com 577 users
-
#11
microsoft.com 474 users
-
#12
hp.com 463 users
-
#13
walmart.com 270 users
-
#14
intel.com 260 users
-
#15
ibm.com 214 users
-
#16
ups.com 172 users
-
#17
westernunion.com 156 users
-
#18
bestbuy.com 149 users
-
#19
fedex.com 141 users
-
#20
adp.com 125 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 89,087hits
- #2 sso 25,953hits
- #3 zoom 10,378hits
- #4 github 3,932hits
- #5 adfs 3,782hits
- #6 webmail 3,038hits
- #7 oracle 1,944hits
- #8 zendesk 1,292hits
- #9 cpanel 1,225hits
- #10 owa 1,129hits
- #11 sap 1,106hits
- #12 vpn 1,085hits
- #13 sts 981hits
- #14 webex 956hits
- #15 ping 845hits
- #16 kaspersky 672hits
- #17 ftp 663hits
- #18 st 636hits
- #19 extranet 605hits
- #20 roundcube 383hits
- #21 okta 261hits
- #22 salesforce 256hits
- #23 gitlab 208hits
- #24 twilio 206hits
- #25 jira 150hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains