Wealth management

Your firm's stolen login sells for $10 on the dark web

Microsoft published research in June that puts a price on your firm's credentials.

1 min readOriginally posted on LinkedIn

Microsoft published research in June that puts a price on your firm's credentials: $10 to $50 for a stolen login on a criminal marketplace, $100 and up if it opens a bank or corporate account.

Here's what bothers me about that number. Those logins usually aren't stolen from the firm. They're stolen from one laptop. Someone clicks a search ad for a PDF tool, or pastes a command a fake error page told them to paste, and malware quietly copies every saved password, cookie and session token in the browser. The session tokens are the ugly part — a stolen live session can be replayed without ever asking for MFA.

From there the credentials get resold to brokers who test them and sell working access on. The gap between the infection and someone actually using it is often months. Nothing on your end looks wrong.

The part most firms don't know: Microsoft already runs a credential-scanning pipeline across dark web forums, breach dumps, paste sites and law enforcement seizure data, and checks what it finds against the passwords live in your tenant right now. When it matches, your tenant raises a flag. That signal is sitting in most Microsoft 365 tenants with nobody watching it.

For a wealth management firm, one replayed session is a bad week — calls you don't want to make, work stopped, and a cyber renewal that suddenly gets complicated.

Worth finding out who's watching that flag.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions