Infostealers Weekly Report: 2020-07-27 – 2020-08-02
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 3,281
- #2 Brazil 584
- #3 Spain 445
- #4 Indonesia 393
- #5 France 372
- #6 Germany 310
- #7 India 285
- #8 Egypt 185
- #9 Canada 160
- #10 United Kingdom 158
- #11 Argentina 113
- #12 Bangladesh 112
- #13 Colombia 107
- #14 Australia 86
- #15 Chile 80
- #16 Israel 75
- #17 Pakistan 69
- #18 Sweden 67
- #19 Philippines 64
- #20 Ecuador 57
- #21 Belgium 56
- #22 Hungary 52
- #23 Algeria 51
- #24 Italy 43
- #25 Vietnam 41
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,723 users
-
#2
facebook.com 5,371 users
-
#3
live.com 4,571 users
-
#4
amazon.com 3,001 users
-
#5
netflix.com 2,493 users
-
#6
twitter.com 2,335 users
-
#7
paypal.com 2,224 users
-
#8
twitch.tv 1,788 users
-
#9
instagram.com 1,746 users
-
#10
yahoo.com 1,654 users
-
#11
discordapp.com 1,614 users
-
#12
roblox.com 1,559 users
-
#13
minecraft.net 1,524 users
-
#14
epicgames.com 1,514 users
-
#15
apple.com 1,512 users
-
#16
steampowered.com 1,453 users
-
#17
spotify.com 1,366 users
-
#18
steamcommunity.com 1,334 users
-
#19
linkedin.com 1,327 users
-
#20
mega.nz 1,265 users
-
#21
dropbox.com 1,238 users
-
#22
ebay.com 1,184 users
-
#23
1,171 users
-
#24
com.facebook.katana 1,118 users
-
#25
com.netflix.mediaclient 1,112 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
publix.com 52 employees
-
#2
37 employees
-
#3
twc.com 25 employees
-
#4
spectrum.net 18 employees
-
#5
ovh.net 16 employees
-
#6
icicibank.com 16 employees
-
#7
one.com 14 employees
-
#8
k12.fl.us 14 employees
-
#9
abv.bg 12 employees
-
#10
accenture.com 12 employees
-
#11
bluehost.com 12 employees
-
#12
peoplematter.com 11 employees
-
#13
roadrunner.com 11 employees
-
#14
freemail.hu 11 employees
-
#15
browardschools.com 11 employees
-
#16
aruba.it 11 employees
-
#17
frontier.com 11 employees
-
#18
rediff.com 10 employees
-
#19
lausd.net 10 employees
-
#20
1and1.com 10 employees
-
#21
ionos.com 10 employees
-
#22
1and1.es 9 employees
-
#23
laccd.edu 9 employees
-
#24
maccabi4u.co.il 9 employees
-
#25
earthlink.net 9 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 52 employees
-
#2
twc.com 25 employees
-
#3
frontier.com 11 employees
-
#4
rockwellautomation.com 6 employees
-
#5
microsoft.com 4 employees
-
#6
hp.com 3 employees
-
#7
jbhunt.com 2 employees
-
#8
ge.com 2 employees
-
#9
chs.net 2 employees
-
#10
csc.com 2 employees
-
#11
dish.com 2 employees
-
#12
marriott.com 2 employees
-
#13
aa.com 2 employees
-
#14
rockwellcollins.com 2 employees
-
#15
cognizant.com 2 employees
-
#16
bakerhughes.com 1 employees
-
#17
anadarko.com 1 employees
-
#18
johnsoncontrols.com 1 employees
-
#19
salesforce.com 1 employees
-
#20
ups.com 1 employees
Compromised users
-
#1
google.com 6,722 users
-
#2
facebook.com 5,370 users
-
#3
amazon.com 3,001 users
-
#4
netflix.com 2,493 users
-
#5
paypal.com 2,224 users
-
#6
apple.com 1,512 users
-
#7
ebay.com 1,183 users
-
#8
walmart.com 677 users
-
#9
capitalone.com 430 users
-
#10
att.com 395 users
-
#11
target.com 373 users
-
#12
ups.com 361 users
-
#13
adp.com 361 users
-
#14
bestbuy.com 325 users
-
#15
wellsfargo.com 322 users
-
#16
fedex.com 252 users
-
#17
bankofamerica.com 243 users
-
#18
oracle.com 224 users
-
#19
americanexpress.com 210 users
-
#20
costco.com 203 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 24,075hits
- #2 sso 7,461hits
- #3 adfs 2,032hits
- #4 webmail 1,531hits
- #5 zoom 1,131hits
- #6 github 796hits
- #7 owa 674hits
- #8 zendesk 571hits
- #9 ftp 537hits
- #10 oracle 496hits
- #11 cpanel 479hits
- #12 imap 455hits
- #13 sts 412hits
- #14 ping 395hits
- #15 sap 376hits
- #16 vpn 283hits
- #17 salesforce 261hits
- #18 extranet 236hits
- #19 st 196hits
- #20 okta 178hits
- #21 webex 163hits
- #22 kaspersky 155hits
- #23 roundcube 128hits
- #24 dana-na 96hits
- #25 citrix 89hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains