Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Stolen or misused login credentials are a leading way attackers gain initial access to organizations, but they are not the only major route in—and the available figures do not show that they cause every breach or are always the single largest cause. The practical takeaway is to make credentials harder to steal and reuse, add phishing-resistant multifactor authentication (MFA), and be ready to revoke access quickly if an account or device is compromised.

How often are credentials involved in breaches?

Several recent reports show how important identity-based attacks are, but their figures describe different datasets and measures. They should not be combined into a single rate.

Report and measure Finding How to interpret it
Verizon Business, 2025 Data Breach Investigations Report (DBIR): credential abuse among breaches 22% of breaches A broad breach-level measure of credential abuse. In the same report, vulnerability exploitation accounted for 20% of breaches.
Verizon Business, 2025 DBIR: Basic Web Application Attack pattern About 88% of breaches in this pattern involved stolen credentials This is a particular attack pattern, not a rate for all breaches.
IBM X-Force, 2025 report: abuse of user identities in 2024 30% of cases This is IBM’s case measure, with a different scope and denominator from Verizon’s breach statistics.
Verizon Business, 2024 DBIR: Basic Web Application Attack pattern Credentials were 71% of compromised data This describes the compromised data in that pattern, not the share of all breaches caused by credentials.
Verizon Business, 2024 DBIR: non-malicious human element 68% of breaches This category includes human involvement such as social engineering or error; it is not a credential-abuse rate.

Together, the reports support treating account security as a core part of breach prevention. They do not establish that credential abuse is always the top entry point: Verizon’s 2025 report also puts vulnerability exploitation close to credential abuse.

How do attackers obtain or misuse credentials?

“Compromised credentials” can result from several different mechanisms. Phishing is one, but password reuse, automated guessing, and malware can expose credentials without a user knowingly handing them over.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Phishing and pretexting

An attacker may impersonate a trusted person or service and persuade someone to enter credentials into a fake sign-in page, disclose them in a message, or approve a deceptive request. Verizon identifies phishing and pretexting as leading contributors to costly breaches. A stolen password can then be used to attempt access to the real service.

Password reuse, guessing, spraying, and stuffing

Attackers may try default or easy-to-guess passwords, test a small set of common passwords against many accounts (password spraying), or use username-and-password pairs exposed elsewhere (credential stuffing). Reuse makes an account vulnerable even when the password was not stolen directly from that service. Verizon’s 2024 DBIR describes attackers taking advantage of default, simplistic, easily guessed, bought, or reused credentials.

Rank #2
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Infostealer malware

Infostealer malware can collect saved credentials and other account data from an infected device. IBM X-Force reported that phishing emails delivering infostealer malware and credential phishing fueled identity abuse in 2024. This matters because changing a password alone may not address the compromised endpoint or already active sessions.

Human error and social engineering

A mistaken disclosure, unsafe action, or response to social engineering can help an attacker obtain access. Verizon’s 2024 finding about non-malicious human involvement is broader than credential theft: it includes human error and social engineering, so it should not be read as saying that every such breach involved a stolen password.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Why a valid login can be especially useful to an attacker

Authentication often makes an intruder’s activity resemble ordinary work by a legitimate user. Depending on the account and its permissions, a successful login may expose email, web applications, cloud consoles, VPN access, or administrative workflows. An account with extensive privileges can create more risk than an ordinary user account, which is why administrator access deserves particular care.

Credentials are one route into a system, not a substitute for every other attack method. A valid password does not necessarily defeat a well-protected service, and credential controls do not prevent attackers from exploiting an unpatched public-facing application. Identity defenses and vulnerability remediation address different risks and need to work together.

Rank #4
OnlyKey Duo - The Best Protection for All of Your USB-C and USB-A Devices
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Which defenses reduce credential risk?

Use layered controls. When choosing or improving them, assess phishing resistance, coverage for workforce and administrator accounts, the ability to revoke sessions and recover accounts, deployment friction, compatibility with legacy systems, and visibility into exposed credentials.

Require phishing-resistant MFA for important accounts

MFA makes a password alone less useful to an attacker. For high-value accounts, prefer phishing-resistant methods such as FIDO2/WebAuthn security keys or passkeys where supported. MFA is not a guarantee against account takeover: coverage gaps, compromised devices, stolen sessions, or recovery weaknesses can still matter. Apply the strongest available method to administrators and other accounts with broad access, not only to a subset of employees.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Use unique passwords and remove shared defaults

Generate long, unique passwords for each service and store them in a reputable password manager. This prevents a password exposed on one service from automatically unlocking another. Disable default passwords and avoid shared credentials; shared accounts make it harder to limit access to an individual or determine who used it.

Monitor exposure and reset confirmed compromised credentials

Use credential-exposure monitoring where available, and make a forced reset when exposure is confirmed. A reset should be paired with session and token revocation where supported; otherwise, an attacker with an existing authenticated session may retain access after the password changes.

Patch exposed applications as well as protecting accounts

Prioritize remediation of vulnerabilities in public-facing systems. Credential defenses do not replace patching, and patching does not prevent stolen credentials from being reused against an otherwise secure login.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if credentials may have been compromised

Respond based on what may have been exposed. If only a password is suspected, reset it and review access. If an infostealer infection is possible, treat the device itself as compromised; changing passwords from that device may expose the new credentials too.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Contain a suspected infected device. Isolate it from the network and do not use it to change passwords or sign in to sensitive accounts.
  2. Use a clean device to secure accounts. Change exposed passwords to unique ones, starting with email, administrator, cloud, VPN, and other accounts that can unlock additional services.
  3. Revoke active access. Sign out existing sessions and revoke tokens or application access where the service supports it. Resetting a password may not invalidate every existing session.
  4. Review account activity and permissions. Look for unfamiliar sign-ins, forwarding rules, recovery changes, new authentication methods, or unauthorized applications. Remove access that should not be present.
  5. Investigate and remediate the endpoint. Determine how the infostealer or other compromise occurred, remove persistence, and restore the device safely before using it for sensitive sign-ins again.
  6. Notify the appropriate security or IT team. For a work account, involve the organization’s incident-response process so related accounts, devices, and access paths can be checked.

Does MFA stop a credential breach?

No single MFA method eliminates credential risk. MFA can prevent a stolen password from being sufficient for access, and phishing-resistant MFA is the stronger choice for high-value accounts. It cannot by itself remove an attacker who already has a valid session, fix an infected endpoint, or address a vulnerable application. Pair MFA with unique passwords, session revocation, endpoint response, and prompt patching.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.