Before Ransomware Hits, a Password Gets Stolen. The 2026 Verizon Report Shows You Have About 95 Days to Stop It.
Verizon’s 2026 Data Breach Investigations Report covered more than 12,000 confirmed breaches. The headline figure most security folks focused on was the ransomware number: it showed up in 48% of all analyzed breaches, up from 44% the year before.[1] That’s bad. But there’s a detail buried further in the data that should change how small businesses think about this entire problem.
73% of ransomware victims had a documented infostealer infection or credential leak event in the 12 months before the attack. Half of those events happened within 95 days.[2]
The passwords went out first. The ransomware came later.
How the Pipeline Actually Works
Infostealers are a category of malware that does exactly what the name says. They get onto a device, usually through a phishing email, a malicious browser extension, or cracked software downloaded from a sketchy site. Once installed, they quietly pull saved passwords, session cookies, and autofill credentials from browsers and dump everything into a log file. That log gets sold on criminal marketplaces, sometimes for as little as $10, sometimes for much more depending on what accounts are inside.
Researchers found that infostealer campaigns are surfacing roughly 2,362 breached corporate credentials per month from organizational email domains in stealer log datasets.[3] The people buying those logs aren’t random. They’re testing credentials against VPNs, Microsoft 365 logins, accounting platforms, remote desktop services. They have time, and they have automation.
For small businesses specifically, the report found that most attacks are opportunistic. Attackers aren’t picking you because they know your revenue or your industry. They’re picking you because your credentials surfaced in a log and your firewall hasn’t been patched. 38% of SMB ransomware cases in the report started with compromised credentials. Another 29% started with an unpatched vulnerability in an internet-facing device.[1]
That’s 67% of attacks with a known, preventable starting point.
The 95-Day Window
The 95-day figure is the part I keep thinking about. It suggests there’s a gap between when credentials get compromised and when ransomware actually deploys. The attacker buys the logs, validates the credentials, establishes access, pokes around the network, and eventually decides when to pull the trigger. That process takes time.
If a company can find out their credentials have leaked and rotate the affected passwords before that window closes, they can cut off one of the most common ransomware entry paths. The problem is that most small businesses have no way of knowing their credentials are circulating. They find out when the ransom note shows up.
Small businesses in the DBIR dataset had a median of 7 credential leak events per year.[2] Seven. Most of those went undetected.
What You Can Actually Do About This
A few things that have a real impact:
Check if your credentials are already out there. Have I Been Pwned (haveibeenpwned.com) lets anyone search an email address against known breach databases for free. It’s not exhaustive, but it’s a starting point. Some Microsoft 365 business plans and most reputable password managers also include dark web monitoring that checks credential leak databases on an ongoing basis.
Stop reusing passwords across accounts. Infostealer logs are most useful when the same credential opens multiple doors. A unique, random password for every account means a stolen credential from one site doesn’t cascade into everything else. A password manager makes this manageable. Without one, it’s nearly impossible.
Turn on MFA for anything that matters remotely. VPN access, email, remote desktop, accounting software. Even if an attacker has valid credentials, MFA adds a step they can’t get past without physical access to the device. This is the single highest-leverage security control for most small businesses.
Patch the devices that face the internet. Firewalls, VPN concentrators, remote access gateways. These are the edge devices the report specifically calls out. When a patch drops for one of those, it’s not optional maintenance. It’s closing a door that attackers are actively testing.
The Numbers in Context
Small businesses accounted for 96% of ransomware victims in this year’s report.[4] The median ransom payment was $139,875, down slightly from $150,000 the prior year, and 69% of victims didn’t pay.[1] Whether you pay or not, the downtime and recovery cost hit either way. For a business without dedicated IT staff and a tested backup plan, recovery from ransomware can take weeks.
October is Cybersecurity Awareness Month, which is as good an excuse as any to take stock of where your business stands. But honestly, the credential question doesn’t need a calendar event. If you don’t know whether your employees’ passwords are sitting in a stealer log somewhere, that’s worth finding out today.
Not sure where to start with credential monitoring or MFA? Reach out here or call us at (412) 307-8313. We help small businesses across Pittsburgh close the gaps before attackers find them.
- Verizon, “2026 Data Breach Investigations Report,” verizon.com
- SpyCloud, “2026 Verizon DBIR: Key Takeaways for Identity Threat Protection and Defense,” spycloud.com
- Stingrai, “Compromised Credential Statistics 2026: Stealers and ATO,” stingrai.io
- Cyber Readiness Institute, “Verizon DBIR 2026: Small-businesses face escalating cyber threats,” cyberreadinessinstitute.org