SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Compromised credential monitoring lags threat awareness

Compromised credential monitoring lags threat awareness

Wed, 29th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Enzoic has published a survey on compromised credentials in organisations. The study found that 73% of respondents had discovered employee credentials in breach data, dark web sources or infostealer logs over the past year.

The findings point to a wide gap between awareness of credential risk and routine monitoring inside companies. While 85% of respondents viewed compromised credentials as a primary attack path, only 19% said they continuously monitored credential exposure and automatically remediated it.

Authentication failures were also common. The survey found that 71% of organisations experienced an authentication-related security incident in the past year, while 66% said hackers used valid credentials in the most recent attack.

This suggests that exposed passwords and logins are not an isolated problem, but part of a wider chain of account abuse. Many organisations are dealing with credentials that have already appeared outside their control while remaining trusted inside their systems.

One issue highlighted by the survey was the speed at which stolen credentials circulate. Enzoic cited external research indicating that exposed credentials can appear on dark web forums within 24 hours.

Monitoring gap

The survey found that 13% of organisations do not monitor for credential exposure at all, while 6% said they were unsure whether they had any visibility. Only 8% said they actively monitored and had found no exposed credentials.

Infostealer logs emerged as a specific blind spot. Thirty-nine per cent of respondents said they had found employee passwords in infostealer data, but 43% said they do not monitor that source or are unsure whether they do.

The results also showed that concern is widespread even where monitoring is limited. Some 82% of respondents said they were worried that previously compromised credentials might already be present in their environment.

Security controls appear to be concentrated at the start of the password lifecycle rather than during ongoing use. The survey found that 49% screen credentials at creation or reset, 37% at login, 33% at step-up authentication, and 20% when a long-lived session re-authenticates.

That pattern matters because password risk often emerges after the credential is created. A password may later be reused, phished, exposed in a third-party breach or taken from an infected device while the related account still appears legitimate.

MFA limits

The survey also examined how companies view multi-factor authentication. Only 13% of respondents said MFA adequately addresses credential risk on its own.

At the same time, fallback to passwords remains common. Sixty-two per cent said they still allow password fallback when MFA is unavailable, while 17% said they had eliminated that route.

Respondents identified several ways attackers can still exploit accounts where MFA is in place. The survey found that 66% were concerned about bypass through adversary-in-the-middle kits, SIM swaps and push fatigue; 48% pointed to users who never enrolled or later disabled MFA; 46% cited password fallback; and 41% said credentials could be used before MFA is triggered.

Plans to invest in monitoring appear to be outpacing formal ownership of the issue. The survey found that 41% plan to implement compromised credential monitoring, but only 29% treat automated credential abuse as a defined strategic priority.

Ken O'Brien, Chief Technology Officer at Enzoic, commented on the results.

"Our survey underscores that hackers are currently winning the credential battle. By recognizing the dangers but not investing in technology to combat them, companies are essentially inviting cybercriminals to continue their exploits. But organizations can win the war if they abandon their passive approach and act on Dark Web intelligence before threat actors can," said O'Brien.

The study was conducted by Cybersecurity Insiders and focused on how organisations detect and respond to exposed workforce credentials. Its findings suggest that many companies recognise the threat from stolen logins, but far fewer have embedded continuous monitoring into day-to-day security operations.

Among the clearest figures in the report is the imbalance between concern and action: 85% of respondents regard compromised credentials as a primary attack path, while 19% continuously monitor their integrity and automatically remediate exposure.