Infostealers are changing the way organizations need to think about identity risk.
A compromised device can expose far more than a username and password. Infostealer malware can capture browser data, credentials, device information, and authentication artifacts that provide attackers with a much broader view of an individual’s digital identity.
Constella Intelligence’s latest Quarterly Identity Breach Report highlights the scale of this growing threat. During Q2 2026, Constella registered 5.53 million devices with infostealer infection dates, an increase of 99.53% from Q1.
In the video below, Constella CEO Andres Andreu and Alberto Casares, VP of Threat Research, discuss the evolving infostealer landscape and what these exposures mean for organizations trying to protect employees, customers, and digital identities.
What Infostealers Can Reveal About an Identity
The risk from infostealers is not limited to stolen passwords.
Constella’s Q2 analysis found web addresses in 99.75% of infostealer records, passwords in 94.97%, usernames in 46.95%, email addresses in 46.05%, and hardware IDs in 22.62%. Together, these artifacts can reveal which services a victim uses, connect activity back to an identity or device, and help attackers determine where stolen access may be valuable.
This creates an important visibility challenge for security teams. An organization may have strong controls around its corporate network and managed endpoints, while an employee’s identity is exposed through an infection on a personal or otherwise unmanaged device.
The organization may never have seen the original infection, but it can still face the consequences of the stolen identity data.
The Risk Can Extend Beyond the Initial Login
Infostealers can also capture browser cookies, session tokens, browsing data, cached credentials, and device information.
That matters because authentication does not always begin again with a username and password. If a stolen authenticated session remains valid, an attacker may potentially reuse it without completing the normal login process again. The effectiveness of this type of attack depends on factors such as token validity, platform controls, and whether compromised sessions are detected and revoked.
This is one reason organizations need to look beyond traditional credential monitoring and understand the broader context surrounding an exposed identity.
External Identity Exposure Requires Broader Visibility
Constella’s Quarterly Identity Breach Report shows how significant that external exposure has become.
The Constella Data Lake closed Q2 with 72.95 billion records, an increase of 14.07% from Q1. Email addresses appeared in 51.07% of curated Hacked Leaked and Combo records, while plaintext passwords appeared in 50.90%.
The challenge for security teams is connecting these individual signals.
A password may indicate compromised access. An email address provides an identity anchor. URLs can reveal services associated with the victim. Device information and other attributes can add further context.
Viewed individually, each is a data point. Connected together, they can provide a much clearer picture of what an attacker may already know about an identity.
What Security Teams Can Do
Constella recommends that organizations expand identity risk management beyond internal systems and take a more comprehensive approach to external exposure. This includes correlating exposure across identities, treating confirmed plaintext credentials as immediately actionable, investigating infostealer infections beyond password resets, reviewing active sessions and authentication artifacts where supported, strengthening authentication controls, and continuously monitoring external identity exposure.
See the Latest Identity Threat Data
Explore the complete Constella Intelligence Quarterly Identity Breach Report for the latest research on breach activity, infostealers, exposed identity data, and the actions security teams can take to reduce risk.