Infostealers Are Reshaping the Identity Threat Landscape
Infostealers are exposing far more than passwords. Constella’s Q2 2026 Quarterly Identity Breach Report examines the credentials, sessions, browser data, identity information, and other artifacts circulating across criminal ecosystems, and how attackers are putting that information to use.
Download the Report Now
What the Data Shows
Constella’s Q2 2026 findings show both the scale and growing identity value of exposed data. The Data Lake closed the quarter with 72.95 billion records, up 14.07% from Q1, while 5.53 million devices were identified with Q2 infostealer infection dates, nearly twice the Q1 total. More than half of curated Hacked Leaked and Combo records contained an email address, strengthening the connections between exposed credentials, identities, devices, and online services that attackers can use to target individuals and organizations.
Inside the Report
- 72.95 billion records in the Constella Data Lake, an increase of 14.07% from Q1, including 10.82 billion verified records ingested during Q2.
- 5.53 million devices with Q2 infostealer infection dates, up 99.53% from Q1, demonstrating the expanding scale of device-level identity exposure.
- What infostealers reveal beyond passwords, including URLs associated with online services, usernames, email addresses, device identifiers, and other information that can reveal which accounts and services matter to a victim.
- Why stolen sessions can create risk beyond the initial login, including how valid session data may allow attackers to access already-authenticated accounts and services.
- How exposed data builds a more complete identity, with email addresses appearing in 51.07% and plaintext passwords in 50.90% of curated Hacked Leaked and Combo records.
- Where identity exposure was concentrated, including the countries and industries represented most heavily in Constella’s attributed Hacked Leaked breach intelligence.
- Five actions security teams can take now, from correlating exposure across identities and responding to infostealers beyond password resets to continuously monitoring external identity exposure.
Why Constella?
Constella collects breach and infostealer intelligence across the surface, deep, and dark web, then applies verification, deduplication, quality controls, and expert analysis before data enters the Constella Data Lake. The result is identity risk intelligence designed to help organizations connect fragmented exposure, understand potential risk, and take action.
Insights from the Front Lines of Identity Risk
Stay ahead of emerging threats with proprietary research and actionable analysis from the Constella Intelligence Team.