Here is the asymmetry that should keep finance directors awake: the credential that opens your VPN can be bought inside a stealer log for less than the price of a pub lunch. What it costs you when someone uses it is measured in weeks of downtime, regulatory exposure, and - in the worst UK cases of recent memory - hundreds of millions of pounds.
This post is about the economics: who profits at each step of the stealer-log supply chain, why the sums work so overwhelmingly in the attacker's favour, and where the cheapest place is for a defender to break the chain.
The Supply Chain Behind a Ten-Dollar Log
Credential theft stopped being a cottage industry years ago. What we observe across the marketplaces and Telegram channels we monitor is a mature market with clean division of labour:
- The malware operator writes and rents the stealer - Lumma, Vidar, StealC - as a subscription service, and takes no part in attacks.
- Traffer teams specialise purely in distribution: poisoned ads, cracked software sites, fake-CAPTCHA pages. They're paid per install, and they harvest the logs.
- Log marketplaces and "clouds" aggregate the harvest. Fresh logs are sold individually or by the thousand; older stock is dumped free as advertising.
- Parsers and initial access brokers sift millions of logs for the valuable needles - a working corporate VPN login, an Entra ID session, an admin panel - and resell that access at a hefty markup.
- Ransomware affiliates and fraud crews buy the access and monetise it: encryption and extortion, invoice fraud, customer account takeover.
Every layer profits, nobody needs to be sophisticated, and the raw material - infected home laptops - renews itself daily. Constella Intelligence processed 51.7 million stealer packages in 2025 alone, from nearly 25 million infected devices. That's the scale of the intake funnel pointed at businesses like yours.
Where the Bleeding Actually Happens
The word "breach" suggests one catastrophic event. In practice, stealer-log exposure drains businesses through several taps running at once - most of them quietly.
1. The Headline Event
When parsed access reaches a ransomware crew, you get the version that makes the news. The 2025 attacks on Marks & Spencer (an estimated £300 million in lost profit) and the Co-op (data of 6.5 million members stolen) both began not with elite exploitation but with impersonation - attackers who knew enough about specific employees to talk an IT help desk into resetting credentials. Stealer logs, breach dumps and scraped profiles are precisely how that knowledge gets assembled cheaply.
2. Vendor Invoice Fraud
A stolen mailbox login is all it takes. The criminal reads quietly for weeks, learns your billing rhythms, then sends a genuine-looking "we've changed our bank details" email at exactly the right moment in a real invoice conversation. No malware touches your network; the money simply leaves. This is one of the most common ways UK businesses lose five- and six-figure sums, and it's almost always credential-initiated.
3. Customer Account Takeover
If you run anything customers log into, their reused passwords are in stealer logs and breach dumps, and credential-stuffing tools will try them against your login page around the clock. You carry the cost: fraudulent orders, refunds, chargebacks, support load, and customers who blame you for "being hacked" when the password came from somewhere else entirely.
4. The Regulator
UK GDPR fines can reach 4% of global annual turnover, and the ICO has been consistent on a point that surprises many boards: "the credentials were stolen from an employee's personal laptop" is not a defence. If personal data you control was exposed because access went unmonitored, the liability is yours.
The Uncomfortable Arithmetic
Put the two sides of the ledger next to each other.
The attacker's costs: a stealer subscription measured in hundreds of dollars a month - or just buying finished logs for a few dollars each, filtered by your domain. Their time-to-market: independent lifecycle research puts infection-to-marketplace at 48 hours or less.
Your costs if it lands: incident response consultancy, operational downtime, legal advice, regulatory process, customer notification, insurance excess and rising premiums - before a single pound of fraud or extortion. The Cyber Security Breaches Survey found 43% of UK businesses identified an attack or breach in a single year; the question is not whether you're in the target pool.
Against that: the defender's cheapest intervention point in the whole chain is the moment a credential appears in a log - before a parser flags it, before a broker resells it, before anyone logs in. At that moment the fix costs almost nothing: rotate one password, revoke one session, check one device. Every later stage multiplies the price.
Breaking the Chain Early
A realistic defence programme against stealer-log exposure looks like this, in order of value for money:
- Watch the marketplaces for your own domains. This is exactly what DarkStrata Stolen Data Monitoring does: we continuously index stealer logs, marketplace listings and breach corpora, and alert you when your domain appears - typically with context on which machine was infected, which applications were exposed, and whether session cookies were taken. That context is the difference between a targeted fix and a panicked mass reset.
- Respond to exposure properly. Rotate the credential and revoke sessions; a stolen cookie survives a password change. Then find the infected device - it will keep restocking the criminals otherwise.
- Screen logins against known-compromised credentials. Our Credential Check APIs let you block a known-stolen password at the point of authentication, using k-anonymity so the credential itself never leaves your systems - which shuts the account-takeover tap for customers as well as staff.
- Fix the human pipeline privately. The employee whose personal laptop was infected is a victim, not a culprit. Lens shows staff their own exposure and walks them through remediation without their manager reading their personal credentials - which is both the effective approach and the defensible one under UK data protection law.
The Point
Stealer logs industrialised the theft of access, and the market behind them prices your credentials at pocket change while the damage prices in the millions. You can't change either number. What you control is when you find out - and the earlier in the supply chain you're standing, the cheaper the whole problem becomes. See what's already out there for your domain; most organisations find something.
Sources
- Cyber Security Breaches Survey 2025 - GOV.UK
- Whiteintel / Cybersecurity News: 48 Hours Between Infection and Dark Web Sale
- Computer Weekly: M&S, Co-op attacks a 'Category 2 cyber hurricane', say UK experts
- BleepingComputer: M&S confirms social engineering led to massive ransomware attack
- GDPR Fines and Penalties