When a password of yours turns up in a breach dump, it does not feel like an emergency. Nothing breaks. No alert fires. The account still works. That is exactly what makes it dangerous, and there is now a number that shows why.
In the 2026 Verizon Data Breach Investigations Report, researchers took organisations that were later published as ransomware victims and looked backwards. 73% of them had a credential leak or infostealer event in the year before the attack. Of those, half had it within 95 days of being hit.
A leaked credential is not the end of an incident. It is the start of a countdown.
How your password ends up for sale
Three routes, and only one of them is your fault:
- Somebody else got breached. A shop, a forum, a service you signed up to in 2017. Their database leaks and your email and password go with it. You did nothing wrong and you probably will not be told.
- An infostealer ran on a machine. A family laptop, a personal phone, a download that seemed fine. This malware exists to harvest saved browser passwords, session cookies and tokens, and it sends them straight to a market. Cookies matter here: with a valid session token, an attacker can sometimes skip your multifactor prompt entirely.
- Reuse. The leak was from an unimportant site, but the password is the same one guarding your email.
Why attackers wait
They usually are not the same people. Credentials get harvested by one group, packaged, and sold to another that does the intrusion. That handover is what puts weeks or months between the leak and the attack, and it is the window you get for free if you are watching.
It also explains why the leak feels harmless. Nothing happens for a while precisely because the person who took it has not decided what to do with it yet.
What to do, in order
- Find out. Check whether your address appears in known breaches. Ours is free and does not ask you to register: check for leaked credentials. Do it for your work address and for the staff who handle payments.
- Change the password that matters most first. Your email account, not the site that leaked. Whoever controls your inbox can reset everything else.
- Kill the sessions, not just the password. This is the step most people skip. Changing a password does not always log out an attacker who holds a live session cookie. In Microsoft 365 and Google Workspace there is a “sign out everywhere” action. Use it.
- Turn on multifactor everywhere it is offered, starting with email, remote access and anything that touches money. An app code beats an SMS code.
- Stop reusing. A password manager is not about strong passwords, it is about different ones, so that one leak stays one leak.
- Assume the machine, not just the account. If the credential came from an infostealer, the password was taken off a computer, and that computer is still there. Scan it or rebuild it.
What “monitoring” should actually mean
Checking once is a snapshot. The leak that matters is the one that happens next March. Continuous monitoring means somebody watches for your domain appearing in new dumps and tells you which account to change, which is what our exposure and dark web work covers.
And because that credential is often the first step of a ransomware chain, the other half of the answer is being able to recover if it goes all the way: copies an attacker cannot reach and a restore that has actually been tested. That is continuity and recovery. If you want to see who is being hit right now, our ransomware tracker is public and free to search by industry.
The honest summary
You cannot stop other companies from leaking your data. You can find out quickly, close the door properly rather than half way, and make sure one exposed password does not become an encrypted business.
Ninety five days is not a long warning. It is enough, if somebody is looking.
Sources: Verizon 2026 Data Breach Investigations Report.
