This website uses cookies

Read our Privacy policy and Terms of use for more information.

THE HYPE INDEX · EDITION 005 · SEPTEMBER 3, 2026

The number is real and enormous. Divide it by the other number in the same report and it turns into something the headlines are not telling you.

THE CLAIM

1.7 billion passwords were stolen in six months, and yours is probably one of them.

The figure comes from Flashpoint's midyear threat report, published August 2026. The personal-warning framing comes from everywhere else, and it is not new. A nearly identical headline ran a year earlier on a different vendor's number.

VERDICT

Overstated

A real industrial-scale problem, dressed up as a personal headcount.

HYPE INDEX

69 / 100

Higher means more distance between what the evidence supports and how the claim is used.

The 1.7 billion counts records in stealer logs, not people. The measured number that deserves the headline is 7.4 million infected machines.

THE NUMBER

230

Credentials per infected machine, dividing 1.7 billion by 7.4 million. A stealer grabs every saved login, cookie and autofill on a device in one pass. This is a count of records, not of victims.

What Flashpoint actually counted

The primary source is specific about what it measured. The headlines are not.

Flashpoint's 2026 Global Threat Intelligence Report, Midyear Edition, covers January through June 2026. It counts 7.4 million unique compromised hosts infected with infostealer malware, up 27 percent on the prior six months, and 1.7 billion credentials harvested from them. The counts come from Flashpoint's own monitoring of illicit sources, which it describes as more than 3.9 petabytes of collected material. Vidar, StealC and Lumma were the most prolific stealer families.

A credential here is a record in a stealer log, typically a username and password pair lifted from an infected machine. The public materials do not define how duplicates, stale accounts, or the same login saved in three browsers are handled, and they publish no count of unique, current, working accounts. That is not a hidden flaw. It is simply not what this dataset measures.

Credentials are not people

The division the headlines skip is the one that explains the number.

1.7 billion divided by 7.4 million machines is roughly 230 credentials per infection. That ratio is what a stealer log looks like. One compromised laptop yields every saved login in the browser, work and personal, active and abandoned, plus session cookies and autofill data. The haul is enormous per victim precisely because the victim count is so much smaller than the record count.

So the honest reading runs backward from the headline. If you are not one of the 7.4 million infected machines, your password is not in this dataset because of this dataset. If you are, then hundreds of your credentials are, all at once, and no single password reset fixes that. The framing that should scare you is per-device totality, not global volume.

The same headline keeps coming back

An almost identical 1.7 billion ran a year earlier, from different data.

In 2025, coverage of Fortinet's threat landscape research put 1.7 billion stolen credentials from infostealer infections in front of consumers under a headline warning that yours is at risk. That figure described 2024 activity, measured by a different vendor with different methods. The match with this year's number is coincidence, but the framing is identical, and each recurrence resets the fear clock without adding any new evidence about any individual reader.

When the same round number can headline two different years from two different vendors, the number has stopped informing and started performing. The measured trend line worth tracking is the one inside a single vendor's consistent method, and there it is the infected-device count, up 27 percent in six months, that is doing the moving.

What holds up, and it is serious

The verdict is about the framing. The underlying problem is real and getting worse.

Infostealers are the commodity front end of real intrusions. Stolen credentials get sorted, resold and fed into automated pipelines that Flashpoint describes as autonomous credential processing engines, testing logins at machine speed. The report's core argument, that digital identity is now the main entry point for enterprise intrusions, survives every caveat in this edition.

And 7.4 million infected devices in six months, growing 27 percent, is a measured count of machines from a consistent method. That number needs no inflation, no division and no dressing up. It is the strongest fact in the report and the one the coverage mostly skipped.

What would change our mind

We are telling you in advance what evidence would move this score.

A published deduplication method with a unique-account figure, or independent research measuring what share of stealer-log credentials are current and working, would move Sample and method and Drift down and could shift the verdict. So would coverage that consistently reported the device count alongside the credential count.

How it scored

Five components, each scored against a published rubric band. They sum to the Index. If you disagree, you can point at the component you think is wrong, which is the entire design.

Component

Score

Why it landed there

Source quality

12

Rubric 10 to 14: a vendor threat report built on disclosed, large-scale primary collection. Not peer reviewed, but the collection is the vendor's actual business and the report says what it drew from.

Sample and method

14

Rubric 10 to 14: observed records from monitored illicit sources, honestly counted, with no published handling of duplicates or stale accounts. The device count is solid. The credential count is raw.

Independence

15

Rubric 15 to 17: the publisher sells threat intelligence built on exactly this collection, and the figures cannot be audited from outside. Disclosed sourcing keeps it at the bottom of the band.

Replication

12

Rubric 10 to 14: not independently reproduced. Other vendors report the same direction and similar magnitudes, but they measure different collections with different methods, which is corroboration of the trend, not the number.

Drift

16

Rubric 15 to 17: credentials become passwords, records become people, and a six-month collection total becomes a personal warning that your password is out there. The same framing ran a year earlier on a different vendor's number.

Hype Index

69

Overstated. A real industrial-scale problem, dressed up as a personal headcount.

THE CALL, RESOLVES MARCH 2027

The next edition of this report will publish a larger raw credential total, still without a unique-account figure, and coverage will again render it as a count of people at risk.

Resolves HELD if the next Flashpoint Global Threat Intelligence Report publishes a credential total larger than 1.7 billion with no published unique-account methodology, and at least one major consumer outlet presents it as passwords or people exposed. Resolves MISSED if the report publishes a deduplicated unique-account figure or method, whatever the coverage does. Resolves VOID if no such report is published by March 31, 2027.

It gets marked held or missed on that date either way, and it stays on the record. See the record.

What to do with this

  • If 1.7 billion goes in a deck, label it stealer-log records and put 7.4 million infected machines next to it. The second number is the measured one, and it is the one growing 27 percent per half year.

  • Treat any infected endpoint as a bulk credential event, not a single bad password. Every saved login on that machine is gone at once, so respond by hunting stealer infections and revoking sessions, not by resetting one account at a time.

  • Move the accounts that matter to passkeys or hardware keys. A harvested password that cannot log in on its own is a record in someone's log, not a working key to your business.

Learn AI in 5 minutes a day

You don't have to scroll every AI thread, track every new tool, or watch every demo. 

The Rundown AI breaks it all down for you — the latest AI news, tools, and tutorials in one free 5-minute email every morning. 

Trusted by 2M+ professionals at Apple, Google, and NASA.

Sources

CITE THIS

The Hype Index, Edition 005, September 3, 2026. Claim: 1.7 billion passwords were stolen in six months, and yours is probably one of them. Verdict: Overstated, 69 out of 100. Primary source: Flashpoint 2026 Global Threat Intelligence Report, Midyear Edition, August 2026. Editor: Mark Lynd. https://thehypeindex.com/editions/1-7-billion-stolen-passwords/

Every claim we have scored, with its components and its call, is at https://thehypeindex.com/record/. Think a component is wrong? Challenge it. Every challenge gets a published outcome, including the ones we decline.

Mark Lynd, Editor

Recommended for you

View all
caret-right