Infostealers Weekly Report: 2020-09-14 – 2020-09-20
InfoStealers Weekly Report – In this comprehensive report, we provide you with valuable insights into the most pressing threats facing organizations today. As cyberattacks continue to grow in…
Threat Geography
Where infections came from
Compromised machines distributed by country of infection — hover any region to inspect.
Top 25 countries
- #1 United States of America 2,148
- #2 Spain 1,113
- #3 France 771
- #4 Germany 693
- #5 Canada 461
- #6 Australia 296
- #7 Belgium 213
- #8 India 57
- #9 Switzerland 35
- #10 Israel 34
- #11 United Kingdom 30
- #12 Brazil 26
- #13 Indonesia 26
- #14 Philippines 21
- #15 Italy 21
- #16 Myanmar (Burma) 18
- #17 Mexico 15
- #18 Sweden 13
- #19 Pakistan 13
- #20 Egypt 12
- #21 Turkey 12
- #22 Vietnam 11
- #23 Poland 11
- #24 Portugal 10
- #25 Nigeria 10
Top Compromised Domains
Where users had active sessions
Domains where infected users had active sessions and saved credentials at the time of infection.
-
#1
google.com 6,707 users
-
#2
live.com 4,093 users
-
#3
facebook.com 3,960 users
-
#4
amazon.com 2,571 users
-
#5
paypal.com 2,499 users
-
#6
twitch.tv 2,257 users
-
#7
netflix.com 2,256 users
-
#8
twitter.com 2,128 users
-
#9
epicgames.com 1,861 users
-
#10
roblox.com 1,860 users
-
#11
instagram.com 1,723 users
-
#12
discordapp.com 1,627 users
-
#13
minecraft.net 1,618 users
-
#14
steampowered.com 1,599 users
-
#15
steamcommunity.com 1,579 users
-
#16
discord.com 1,547 users
-
#17
spotify.com 1,375 users
-
#18
apple.com 1,348 users
-
#19
sonyentertainmentnetwork.com 1,222 users
-
#20
riotgames.com 1,180 users
-
#21
mega.nz 1,148 users
-
#22
com.spotify.music 1,143 users
-
#23
dropbox.com 1,080 users
-
#24
battle.net 1,074 users
-
#25
com.contextlogic.wish 1,068 users
Top Compromised Corporate Domains
Employees caught in the logs
Domains where compromised users were employees, surfaced via business email and credentials.
-
#1
ovh.net 23 employees
-
#2
publix.com 22 employees
-
#3
vic.edu.au 21 employees
-
#4
21 employees
-
#5
mail.de 19 employees
-
#6
movistar.es 17 employees
-
#7
strato.com 16 employees
-
#8
one.com 14 employees
-
#9
jcyl.es 13 employees
-
#10
cned.fr 12 employees
-
#11
orange.es 12 employees
-
#12
freenet.de 12 employees
-
#13
engelbert-strauss.de 12 employees
-
#14
k12.fl.us 11 employees
-
#15
ionos.es 11 employees
-
#16
ovh.com 11 employees
-
#17
bluehost.com 10 employees
-
#18
epost.de 9 employees
-
#19
dadeschools.net 9 employees
-
#20
webmail.es 9 employees
-
#21
vic.gov.au 9 employees
-
#22
ky.gov 9 employees
-
#23
browardschools.com 9 employees
-
#24
senecacollege.ca 8 employees
-
#25
k12.ca.us 8 employees
Fortune 500 Exposure
Top S&P companies hit this week
Top S&P companies with compromised employees and customers detected this week.
Compromised employees
-
#1
publix.com 22 employees
-
#2
frontier.com 4 employees
-
#3
rockwellautomation.com 4 employees
-
#4
microsoft.com 3 employees
-
#5
ibm.com 2 employees
-
#6
manpowergroup.com 2 employees
-
#7
disney.com 2 employees
-
#8
ebay.com 1 employees
-
#9
wfscorp.com 1 employees
-
#10
exxonmobil.com 1 employees
-
#11
oracle.com 1 employees
-
#12
hp.com 1 employees
-
#13
bestbuy.com 1 employees
-
#14
ford.com 1 employees
-
#15
homedepot.com 1 employees
-
#16
google.com 1 employees
-
#17
xerox.com 1 employees
-
#18
emc.com 1 employees
-
#19
jetblue.com 1 employees
-
#20
goodyear.com 1 employees
Compromised users
-
#1
google.com 6,707 users
-
#2
facebook.com 3,960 users
-
#3
amazon.com 2,571 users
-
#4
paypal.com 2,499 users
-
#5
netflix.com 2,256 users
-
#6
apple.com 1,348 users
-
#7
ebay.com 845 users
-
#8
walmart.com 389 users
-
#9
ups.com 279 users
-
#10
capitalone.com 245 users
-
#11
att.com 215 users
-
#12
bestbuy.com 213 users
-
#13
adp.com 193 users
-
#14
target.com 179 users
-
#15
wellsfargo.com 159 users
-
#16
oracle.com 152 users
-
#17
hp.com 150 users
-
#18
nike.com 148 users
-
#19
fedex.com 147 users
-
#20
bankofamerica.com 117 users
Targeted Application Keywords
What attackers grep for
The most common application keywords seen across credential logs — auth, sso, vpn, and more.
- #1 auth 20,697hits
- #2 sso 6,126hits
- #3 adfs 2,086hits
- #4 webmail 1,273hits
- #5 zoom 1,050hits
- #6 github 633hits
- #7 ftp 563hits
- #8 zendesk 479hits
- #9 sts 429hits
- #10 owa 418hits
- #11 imap 407hits
- #12 sap 376hits
- #13 oracle 356hits
- #14 extranet 352hits
- #15 ping 319hits
- #16 zimbra 275hits
- #17 vpn 245hits
- #18 cpanel 225hits
- #19 st 148hits
- #20 kaspersky 132hits
- #21 webex 129hits
- #22 salesforce 126hits
- #23 roundcube 111hits
- #24 dana-na 95hits
- #25 okta 94hits
Cavalier · Continuous monitoring
Get this depth of insight on your own organization.
Cavalier turns this same intelligence into a continuous real-time feed of compromised employees, customers and third-party vendors for your business.
More reports
Previous weekly briefings
Infostealers Weekly Report: 2026-06-08 – 2026-06-15
- 9K machines
- 2K users
- 125K domains
Infostealers Weekly Report: 2026-06-01 – 2026-06-08
- 16K machines
- 2K users
- 273K domains
Infostealers Weekly Report: 2026-05-25 – 2026-06-01
- 18K machines
- 4K users
- 259K domains