Infostealers Weekly Report: 2020-09-07 – 2020-09-13
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 India 2,554
- #2 United States of America 1,280
- #3 Spain 511
- #4 Germany 352
- #5 France 259
- #6 Indonesia 234
- #7 Canada 197
- #8 Israel 183
- #9 United Kingdom 153
- #10 Australia 84
- #11 Brazil 79
- #12 Philippines 73
- #13 Russia 64
- #14 Belgium 59
- #15 Pakistan 51
- #16 Sweden 49
- #17 Turkey 46
- #18 Mexico 40
- #19 Japan 38
- #20 Egypt 34
- #21 Argentina 29
- #22 Thailand 29
- #23 Vietnam 28
- #24 Algeria 25
- #25 Morocco 25
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,215 users
-
#2
facebook.com 4,360 users
-
#3
live.com 3,634 users
-
#4
amazon.com 2,509 users
-
#5
netflix.com 1,843 users
-
#6
twitter.com 1,827 users
-
#7
paypal.com 1,685 users
-
#8
instagram.com 1,611 users
-
#9
1,241 users
-
#10
linkedin.com 1,189 users
-
#11
twitch.tv 1,183 users
-
#12
yahoo.com 1,139 users
-
#13
epicgames.com 1,139 users
-
#14
com.facebook.katana 1,129 users
-
#15
apple.com 1,120 users
-
#16
com.spotify.music 1,035 users
-
#17
discordapp.com 996 users
-
#18
amazon.in 990 users
-
#19
steampowered.com 989 users
-
#20
roblox.com 958 users
-
#21
mega.nz 952 users
-
#22
com.netflix.mediaclient 935 users
-
#23
minecraft.net 924 users
-
#24
spotify.com 917 users
-
#25
steamcommunity.com 902 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
rediff.com 91 employees
-
#2
icicibank.com 54 employees
-
#3
accenture.com 36 employees
-
#4
digimail.in 34 employees
-
#5
onlinesbi.com 31 employees
-
#6
netpnb.com 27 employees
-
#7
publix.com 27 employees
-
#8
secureserver.net 22 employees
-
#9
22 employees
-
#10
confused.com 20 employees
-
#11
cognizant.com 13 employees
-
#12
unionbankonline.co.in 11 employees
-
#13
bluehost.com 10 employees
-
#14
tcs.com 10 employees
-
#15
idbibank.co.in 10 employees
-
#16
indusind.com 9 employees
-
#17
maccabi4u.co.il 9 employees
-
#18
freenet.de 9 employees
-
#19
ky.gov 8 employees
-
#20
one.com 8 employees
-
#21
icai.org 8 employees
-
#22
spectrum.net 8 employees
-
#23
k12.fl.us 8 employees
-
#24
jcyl.es 8 employees
-
#25
aruba.it 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 27 employees
-
#2
cognizant.com 13 employees
-
#3
twc.com 7 employees
-
#4
microsoft.com 6 employees
-
#5
frontier.com 6 employees
-
#6
att.com 3 employees
-
#7
tenethealth.com 2 employees
-
#8
oracle.com 2 employees
-
#9
google.com 2 employees
-
#10
amazon.com 2 employees
-
#11
aflac.com 2 employees
-
#12
disney.com 2 employees
-
#13
pepsico.com 2 employees
-
#14
intel.com 1 employees
-
#15
iheartmedia.com 1 employees
-
#16
assurant.com 1 employees
-
#17
apple.com 1 employees
-
#18
nike.com 1 employees
-
#19
hp.com 1 employees
-
#20
quintiles.com 1 employees
Compromised users
-
#1
google.com 6,215 users
-
#2
facebook.com 4,360 users
-
#3
amazon.com 2,509 users
-
#4
netflix.com 1,843 users
-
#5
paypal.com 1,685 users
-
#6
apple.com 1,120 users
-
#7
ebay.com 710 users
-
#8
walmart.com 355 users
-
#9
capitalone.com 244 users
-
#10
ups.com 226 users
-
#11
att.com 222 users
-
#12
adp.com 204 users
-
#13
bestbuy.com 192 users
-
#14
oracle.com 189 users
-
#15
target.com 164 users
-
#16
wellsfargo.com 161 users
-
#17
americanexpress.com 150 users
-
#18
fedex.com 144 users
-
#19
hp.com 131 users
-
#20
bankofamerica.com 123 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 15,480hits
- #2 sso 5,361hits
- #3 adfs 1,436hits
- #4 zoom 1,248hits
- #5 webmail 1,027hits
- #6 github 671hits
- #7 owa 509hits
- #8 sap 450hits
- #9 oracle 421hits
- #10 ftp 331hits
- #11 sts 329hits
- #12 zendesk 308hits
- #13 vpn 295hits
- #14 ping 256hits
- #15 webex 244hits
- #16 st 218hits
- #17 imap 212hits
- #18 cpanel 196hits
- #19 salesforce 194hits
- #20 extranet 166hits
- #21 kaspersky 139hits
- #22 zimbra 120hits
- #23 okta 90hits
- #24 dana-na 81hits
- #25 jira 76hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains