VendorsSpyCloud
SpyCloud
Cybersecurity reports and statistics published by SpyCloud
8 categories1 reports
Recent Statistics & Reports
SpyCloud's 2024 research reveals the staggering scale of exposed credentials circulating within the criminal underground: 3.1+ billion total passwords recaptured.
4/8/2025•
CredentialsCriminal undergroundDark web
By using holistic identity matching for an individual employee, the average exposure increases to 146 records per employee, 22 unique usernames, 13 total usernames, 89 unique emails, 141 total emails, 57 credential pairs, and 8 unique sources. This represents more than 12x the exposed data compared to the traditional view.
4/8/2025•
ExposureRecordsCredentials
97% of the phished records SpyCloud collected in 2024 contain at least one email address.
4/8/2025•
PhishingRecordsEmail address
74% of recaptured consumer records contain a physical or IP address.
4/8/2025•
ExposureRecordsAddress
The average exposure for a single employee identity in 2024, under a traditional exposure model, shows 11 records per employee, 1 unique username, 1 total username, 1 unique email, 11 total emails, 7 credential pairs, and 7 unique sources (breach, malware, or phish).
4/8/2025•
ExposureRecordsCredentials
There was an average of 44 exposed credentials per malware infection.
4/8/2025•
MalwareCredentialsExposure
On average, a single malware infection could expose access to 10 to 25 third-party business applications.
4/8/2025•
MalwareThird-partyThird-party app
About one in every two corporate users was already the victim of an infostealer infection on a personal or corporate system in 2024.
4/8/2025•
MalwareInfostealer
An alarming 70% of users exposed in breaches last year reused previously-exposed passwords across multiple accounts, an increase from 61% in 2023.
4/8/2025•
CredentialsPasswordPassword reuse
SpyCloud recaptured over 1.7 million phished records between the ONNX and Caffeine PhaaS platforms in the second half of 2024.
4/8/2025•
PhishingRecords
There were 895,802 stolen credential records for enterprise AI tools observed by SpyCloud in 2024.
4/8/2025•
CredentialsAI AI tools
SpyCloud found 159,313 stolen credential records from popular password managers in 2024.
4/8/2025•
CredentialsPassword manager
There were 2.2 billion credential pairs (username/email + password) recaptured.
4/8/2025•
CredentialsCriminal undergroundDark web
Endpoint Detection and Antivirus Solutions miss 66% of malware infections.
4/8/2025•
EDREndpoint detectionAV
SpyCloud recaptured 7 million stolen credential records for third-party applications in 2024, a 48% increase from the year prior.
4/8/2025•
CredentialsExposureLogin
93% of the recaptured passwords were cracked by SpyCloud and delivered as plaintext.
4/8/2025•
CredentialsPasswordPlaintext
SpyCloud's research shows that 66% of malware infections occur on devices with endpoint security solutions installed.
4/8/2025•
MalwareEndpoint protectionEndpoint
About half of the recaptured phished data included specific city or postal code information.
4/8/2025•
PhishingRecordsLocation
Nearly one in two corporate users were already the victim of a malware infection in 2024.
4/8/2025•
Malware
In the year prior to 2024, malware was the cause of 61% of all breaches.
4/8/2025•
MalwareBreaches
Showing first 20 results