Infostealers Weekly Report: 2019-05-13 – 2019-05-19
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 1,148
- #2 Indonesia 654
- #3 Germany 620
- #4 Brazil 557
- #5 United States of America 525
- #6 Canada 400
- #7 United Kingdom 369
- #8 Pakistan 284
- #9 France 241
- #10 Egypt 217
- #11 Philippines 180
- #12 Algeria 149
- #13 Poland 138
- #14 Mexico 118
- #15 Australia 107
- #16 Bangladesh 104
- #17 Turkey 98
- #18 Colombia 91
- #19 Romania 91
- #20 Argentina 80
- #21 Malaysia 78
- #22 Vietnam 76
- #23 Morocco 68
- #24 Iraq 65
- #25 Iran 65
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 4,997 users
-
#2
facebook.com 4,255 users
-
#3
live.com 2,529 users
-
#4
twitter.com 1,266 users
-
#5
paypal.com 1,159 users
-
#6
netflix.com 1,050 users
-
#7
yahoo.com 1,024 users
-
#8
instagram.com 911 users
-
#9
amazon.com 894 users
-
#10
epicgames.com 866 users
-
#11
roblox.com 861 users
-
#12
discordapp.com 859 users
-
#13
843 users
-
#14
twitch.tv 741 users
-
#15
steampowered.com 722 users
-
#16
mega.nz 708 users
-
#17
steamcommunity.com 680 users
-
#18
linkedin.com 674 users
-
#19
dropbox.com 591 users
-
#20
apple.com 585 users
-
#21
192.168.1.1 504 users
-
#22
minecraft.net 491 users
-
#23
spotify.com 444 users
-
#24
sonyentertainmentnetwork.com 442 users
-
#25
ea.com 442 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
POP3://pop.gmail.com:995 28 employees
-
#2
rediff.com 27 employees
-
#3
o2.pl 21 employees
-
#4
icicibank.com 20 employees
-
#5
interia.pl 19 employees
-
#6
confused.com 18 employees
-
#7
freenet.de 17 employees
-
#8
onet.pl 14 employees
-
#9
uol.com.br 14 employees
-
#10
freemail.hu 12 employees
-
#11
digimail.in 10 employees
-
#12
accenture.com 10 employees
-
#13
10 employees
-
#14
onlinesbi.com 9 employees
-
#15
iinet.net.au 9 employees
-
#16
rmunify.com 9 employees
-
#17
netpnb.com 8 employees
-
#18
abv.bg 8 employees
-
#19
pdsb.org 8 employees
-
#20
globo.com 8 employees
-
#21
mail.de 8 employees
-
#22
alberta.ca 7 employees
-
#23
imagexapp.com 7 employees
-
#24
tcdsb.org 7 employees
-
#25
hargray.com 7 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
centurylink.com 7 employees
-
#2
cognizant.com 5 employees
-
#3
publix.com 3 employees
-
#4
apple.com 2 employees
-
#5
jetblue.com 2 employees
-
#6
twc.com 1 employees
-
#7
paypal.com 1 employees
-
#8
pepsico.com 1 employees
-
#9
harman.com 1 employees
-
#10
rockwellautomation.com 1 employees
-
#11
microsoft.com 1 employees
Compromised users
-
#1
google.com 4,997 users
-
#2
facebook.com 4,255 users
-
#3
paypal.com 1,159 users
-
#4
netflix.com 1,050 users
-
#5
amazon.com 894 users
-
#6
apple.com 585 users
-
#7
ebay.com 397 users
-
#8
walmart.com 77 users
-
#9
capitalone.com 60 users
-
#10
oracle.com 51 users
-
#11
adp.com 48 users
-
#12
ups.com 47 users
-
#13
hp.com 39 users
-
#14
att.com 39 users
-
#15
wellsfargo.com 39 users
-
#16
westernunion.com 38 users
-
#17
target.com 38 users
-
#18
bestbuy.com 34 users
-
#19
bankofamerica.com 32 users
-
#20
americanexpress.com 29 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 6,247hits
- #2 sso 2,362hits
- #3 webmail 849hits
- #4 imap 804hits
- #5 adfs 440hits
- #6 ftp 299hits
- #7 owa 254hits
- #8 cpanel 208hits
- #9 github 191hits
- #10 zendesk 178hits
- #11 sts 168hits
- #12 oracle 160hits
- #13 sap 158hits
- #14 st 140hits
- #15 kaspersky 102hits
- #16 extranet 80hits
- #17 ping 57hits
- #18 zimbra 53hits
- #19 vpn 47hits
- #20 zoom 40hits
- #21 salesforce 35hits
- #22 roundcube 21hits
- #23 bitbucket 20hits
- #24 citrix 15hits
- #25 jira 15hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-05-11 – 2026-05-18
- 25K machines
- 2K users
- 319K domains
Infostealers Weekly Report: 2026-05-04 – 2026-05-11
- 16K machines
- 4K users
- 200K domains
Infostealers Weekly Report: 2026-04-27 – 2026-05-04
- 14K machines
- 4K users
- 186K domains