Most South African business breaches do not announce themselves with a ransom note or a phone call. They start with a stolen password on a personal laptop, bundled with thousands of others in a broker's database, then tried against your company's login page until something works. By the time you discover the breach, the credential was harvested months ago, sold twice, and used by someone who has never heard of your organisation.
I have run credential exposure audits for South African businesses for more than twenty years, and the pattern is almost always the same. The compromised account was not the IT administrator's. It was the operations manager's personal Gmail, whose password matched their work account. The personal account was in an infostealer log from eighteen months ago. Nobody knew.
How the infostealer supply chain operates
The market that produces stolen credentials runs in three layers, and each is more industrialised than most organisations realise.
Infostealer malware families like Redline, Lumma, StealC, Vidar, and Atomic spread through cracked software downloads, fake browser update prompts, and malicious search ads. The malware runs for under a minute, harvests every saved browser credential and session cookie, then deletes itself. The output is a stealer log: 30 to 200 credentials per device, from thousands of devices every month.
Brokers buy stealer logs in bulk, sort them, and resell. High-value targets (corporate Office 365 accounts, banking credentials) are extracted and sold individually. Lower-value credentials are bundled by geography or domain and sold by the thousand. The marketplace is mostly Telegram and dedicated dark-web forums.
Buyers include business email compromise operators, ransomware groups seeking initial access, and hacktivist crews repackaging material as "breach" claims. The Nullsec Nigeria OpSouthAfrica campaign of May 2026 appears to have drawn from this layer: brokered credentials with South African government email domains, repackaged for political purposes.
Three SA businesses that learned this the hard way
These composite profiles draw on patterns from Ubuntu Guard engagements during 2025 and 2026. Names and identifying details have been changed.
Why credential hygiene is now your most important security control
The three profiles above share one characteristic: none came from a targeted attack. Each came from credentials harvested months earlier, sold quietly, and tried at scale until something matched.
The standard South African MFA posture is "enabled on the obvious accounts": Office 365 admin, banking, maybe cloud infrastructure. The credential supply chain targets the accounts that were not considered obvious. CRM platforms, accounting software, retail POS systems, supplier portals, personal email connected to work calendars. Every account that can initiate a payment, access client data, or reach a supplier system is in scope.
Personal device hygiene is an enterprise security problem. The infection happens on a family laptop, on a home network, on a device the employee considered personal and therefore safe. By the time the credential reaches your environment, the original infection is long gone and untraceable.
What South African businesses should do right now
-
Run a credential exposure audit against your primary email domains. Have I Been Pwned offers free domain-wide monitoring. Commercial services cover dark-web infostealer markets the free tools do not index.
-
Force password resets through the platform, not by asking staff. Block the old credential hash at the identity provider level. Staff-requested resets frequently result in minor variations on the same password.
-
Audit MFA coverage across all business-critical accounts. Write down every account that can initiate a payment, access client data, or reach supplier systems. Mark which ones have MFA. The unmarked ones are your priority.
-
Invalidate active session tokens monthly across Office 365 and Google Workspace. Stealer logs harvest session cookies that bypass MFA. Forcing a full re-authentication defeats this.
-
Brief staff on the personal device rule: work accounts stay off family laptops. The Cape Town profile shows why. The associate did nothing wrong, and the credential was still in circulation for over a year.
-
Run a quarterly supplier exposure check. Their stealer logs become your risk when their staff log into your systems.
Where Ubuntu Guard fits
Ubuntu Guard credential exposure audits are built for SA businesses that want to know exactly where they are exposed before an attacker finds out first. We work across public breach indexes and dark-web infostealer marketplaces, produce a full inventory of exposed accounts with a rotation priority list, and build a 12-month monitoring plan. If your MFA coverage map has gaps, this is where they surface.
Reach us at [email protected]
Frequently asked questions
How do I find out if my business credentials have been compromised?
Start with Have I Been Pwned (haveibeenpwned.com), which offers free domain-wide monitoring for business email addresses. For broader coverage including infostealer log marketplaces that free services do not index, a specialist credential exposure audit will give you a complete picture of what is currently in circulation across dark-web broker markets.
What is infostealer malware?
Infostealer malware is software designed to run silently on an infected device, harvest browser-saved passwords, session cookies, and wallet files, and transmit them to a remote collection point before deleting itself. It spreads primarily through cracked software downloads, fake browser update prompts, and malicious search ads. The infection is frequently on a device the user considered personal rather than a work asset.
Is password reuse dangerous for businesses?
The credential aggregation supply chain is built specifically around it. When a personal account is compromised in an unrelated breach, the harvested credential is tested automatically against hundreds of other services. If the password matches a work account, the attacker has access without ever targeting the business directly.
Sources
- Have I Been Pwned: haveibeenpwned.com — domain monitoring reference
- MyBroadband: OpSouthAfrica credential dump reporting (May 2026)
- Brinztech: Credential aggregation analysis (May 2026)
- SABRIC: 2025 Annual Banking Crime Report
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za