
Enterprise identity credentials remain a prime target for infostealer malware.
This report by Flare analyzes 18.7 million infostealer logs collected between January and November 2025, with a focus on enterprise identity provider credential exposure.
In this report, you will learn:
Why enterprise identity credentials remain a prime target for infostealer malware
About malware families: who’s harvesting enterprise credentials
The impact of credentials and session cookies on attacker speed and effectiveness
The future of enterprise infostealer infections
How compound identity exposure (a single log with multiple points of failure) is manifesting in enterprise SSO/IdPs