How Credential Theft Fuels Most South African Business Breaches

By Ubuntu Guard | 15 June 2026 TLP:CLEAR

Most South African business breaches do not announce themselves with a ransom note or a phone call. They start with a stolen password on a personal laptop, bundled with thousands of others in a broker's database, then tried against your company's login page until something works. By the time you discover the breach, the credential was harvested months ago, sold twice, and used by someone who has never heard of your organisation.

I have run credential exposure audits for South African businesses for more than twenty years, and the pattern is almost always the same. The compromised account was not the IT administrator's. It was the operations manager's personal Gmail, whose password matched their work account. The personal account was in an infostealer log from eighteen months ago. Nobody knew.

How the infostealer supply chain operates

The market that produces stolen credentials runs in three layers, and each is more industrialised than most organisations realise.

Layer 1
Harvesters — the infection point

Infostealer malware families like Redline, Lumma, StealC, Vidar, and Atomic spread through cracked software downloads, fake browser update prompts, and malicious search ads. The malware runs for under a minute, harvests every saved browser credential and session cookie, then deletes itself. The output is a stealer log: 30 to 200 credentials per device, from thousands of devices every month.

Layer 2
Brokers — the sorting house

Brokers buy stealer logs in bulk, sort them, and resell. High-value targets (corporate Office 365 accounts, banking credentials) are extracted and sold individually. Lower-value credentials are bundled by geography or domain and sold by the thousand. The marketplace is mostly Telegram and dedicated dark-web forums.

Layer 3
End users — the buyers

Buyers include business email compromise operators, ransomware groups seeking initial access, and hacktivist crews repackaging material as "breach" claims. The Nullsec Nigeria OpSouthAfrica campaign of May 2026 appears to have drawn from this layer: brokered credentials with South African government email domains, repackaged for political purposes.

Three SA businesses that learned this the hard way

These composite profiles draw on patterns from Ubuntu Guard engagements during 2025 and 2026. Names and identifying details have been changed.

12-staff accounting firm, Durban
Signal Client called to report wrong banking details on an invoice
Vector Personal Gmail password matched work Office 365. Gmail compromised in stealer log 8 months earlier.
Gap found MFA on Office 365 admin ✓ — MFA on partner mailboxes ✗
Duration Mailbox silently accessed for 11 days
Lesson: The credential supply chain targets the accounts that were not in the MFA rollout. Partner mailboxes, not admin accounts.
220-staff retailer, Joburg
Signal Three months of POS refund fraud, initially attributed to insider
Vector Store manager credential reused from a 2023 personal email breach. POS admin interface had no IP restriction.
Gap found No IP restriction on POS admin interface, accessible from anywhere
Duration ~130 fraudulent refunds processed before detection
Lesson: Sector-specific platforms (POS, booking systems, practice management) skip the identity controls used in enterprise IT.
65-staff professional services firm, Cape Town
Signal Associate's calendar showing meetings they did not schedule — all with firm clients
Vector Work Office 365 credential in stealer log for 14 months. Harvested from a family laptop that downloaded cracked software.
Gap found Work account used on unmanaged personal device
Duration 14 months from harvest to use
Lesson: Personal device hygiene is a business problem. The associate did nothing wrong. A family member installed a cracked tool.

Why credential hygiene is now your most important security control

The three profiles above share one characteristic: none came from a targeted attack. Each came from credentials harvested months earlier, sold quietly, and tried at scale until something matched.

The standard South African MFA posture is "enabled on the obvious accounts": Office 365 admin, banking, maybe cloud infrastructure. The credential supply chain targets the accounts that were not considered obvious. CRM platforms, accounting software, retail POS systems, supplier portals, personal email connected to work calendars. Every account that can initiate a payment, access client data, or reach a supplier system is in scope.

Personal device hygiene is an enterprise security problem. The infection happens on a family laptop, on a home network, on a device the employee considered personal and therefore safe. By the time the credential reaches your environment, the original infection is long gone and untraceable.

What South African businesses should do right now

  1. Run a credential exposure audit against your primary email domains. Have I Been Pwned offers free domain-wide monitoring. Commercial services cover dark-web infostealer markets the free tools do not index.
  2. Force password resets through the platform, not by asking staff. Block the old credential hash at the identity provider level. Staff-requested resets frequently result in minor variations on the same password.
  3. Audit MFA coverage across all business-critical accounts. Write down every account that can initiate a payment, access client data, or reach supplier systems. Mark which ones have MFA. The unmarked ones are your priority.
  4. Invalidate active session tokens monthly across Office 365 and Google Workspace. Stealer logs harvest session cookies that bypass MFA. Forcing a full re-authentication defeats this.
  5. Brief staff on the personal device rule: work accounts stay off family laptops. The Cape Town profile shows why. The associate did nothing wrong, and the credential was still in circulation for over a year.
  6. Run a quarterly supplier exposure check. Their stealer logs become your risk when their staff log into your systems.

Where Ubuntu Guard fits

Ubuntu Guard credential exposure audits are built for SA businesses that want to know exactly where they are exposed before an attacker finds out first. We work across public breach indexes and dark-web infostealer marketplaces, produce a full inventory of exposed accounts with a rotation priority list, and build a 12-month monitoring plan. If your MFA coverage map has gaps, this is where they surface.

Reach us at [email protected]

Frequently asked questions

How do I find out if my business credentials have been compromised?

Start with Have I Been Pwned (haveibeenpwned.com), which offers free domain-wide monitoring for business email addresses. For broader coverage including infostealer log marketplaces that free services do not index, a specialist credential exposure audit will give you a complete picture of what is currently in circulation across dark-web broker markets.

What is infostealer malware?

Infostealer malware is software designed to run silently on an infected device, harvest browser-saved passwords, session cookies, and wallet files, and transmit them to a remote collection point before deleting itself. It spreads primarily through cracked software downloads, fake browser update prompts, and malicious search ads. The infection is frequently on a device the user considered personal rather than a work asset.

Is password reuse dangerous for businesses?

The credential aggregation supply chain is built specifically around it. When a personal account is compromised in an unrelated breach, the harvested credential is tested automatically against hundreds of other services. If the password matches a work account, the attacker has access without ever targeting the business directly.

Sources

  • Have I Been Pwned: haveibeenpwned.com — domain monitoring reference
  • MyBroadband: OpSouthAfrica credential dump reporting (May 2026)
  • Brinztech: Credential aggregation analysis (May 2026)
  • SABRIC: 2025 Annual Banking Crime Report

© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Are your staff credentials already for sale?

Ubuntu Guard's credential exposure audit searches public breach indexes and dark-web infostealer markets for your organisation's email domains. You get a full inventory of exposed accounts and a prioritised rotation plan.

Book a Credential Exposure Audit

Questions? Reach us at [email protected]