Password Theft Is Rising Quietly
Data breaches have long been the headline measure of cybercrime. When companies get hacked, the impact is visible, reported, and often followed by damage control. But recent research suggests the story is shifting. While breaches appear to be declining, a quieter and more personal threat is growing fast.
New findings from NordVPN, in collaboration with NordStellar, show that compromised databases fell by 36 percent between 2024 and 2025. At the same time, infostealer activity surged by 35 percent, jumping from 19.5 million to over 26 million logs. The trend signals not less cybercrime, but a change in method.
Infostealers are a type of malware designed to quietly extract data from infected devices. They collect saved passwords, cookies, autofill details, and session tokens without alerting the user. Unlike breaches, which are loud and traceable, these attacks are silent and continuous.
This reflects a broader shift in attacker strategy. As noted in Cloudflare’s 2026 Threat Report, cybercriminals are now focused on efficiency. Instead of investing in complex exploits, they aim for easier wins. Why break into a system when stolen credentials can grant direct access?
The numbers reinforce this shift. In 2025, breaches exposed nearly 34 million passwords, while infostealers harvested a staggering 624 million. That scale shows how automation and volume are reshaping cyber threats. Attackers are no longer targeting systems alone. They are targeting individuals at scale.
Another key difference is visibility. When a company suffers a breach, users are usually notified and asked to reset credentials. Infostealer victims rarely get that chance. Their data is taken quietly and often sold or reused before they even realize something is wrong.
This makes infostealers more dangerous in practice. They bypass organizational defenses and go straight to the source: the user’s device. In doing so, they blur the line between personal security and enterprise risk. A single compromised device can open doors to larger systems.
The rise of infostealers also exposes a gap in awareness. Many people understand breaches but have never heard of this type of malware. That lack of awareness increases risk, as users may not recognize how easily their data can be captured.
Protection, however, is not complicated. Avoiding pirated software, being cautious with downloads, and resisting phishing attempts can prevent most infections. Using a password manager instead of browser storage, enabling multi-factor authentication, and keeping software updated all add meaningful layers of defense.
The takeaway is simple. Cybercrime is not decreasing. It is evolving. And in this new phase, the weakest point is no longer the company database, but the everyday device.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




