Identity Protection
Compromised credentials and infostealer infections are the most common way into an organisation. KELA intercepts stolen identities where they are traded, validates which ones still open a door, and gets them closed before they are used.
What is an identity, to an attacker?
Far more than a password. Everything below is harvested by infostealers, sold in the underground and used to impersonate an employee or a customer.
Why valid accounts are the attacker’s first choice
A working login does not trip an alarm. It is cheaper than brute force, more reliable than credential stuffing, and it arrives ready to use from an infostealer log. In IBM X-Force’s 2025 data, exploiting public-facing applications led initial access at 40%, and compromised accounts, meaning valid accounts, external remote services and phishing together, made up 52%. IBM puts the average cost of a breach that starts with a valid account at 4.81 million dollars.
Sources: IBM X-Force Threat Intelligence Index 2025; IBM Cost of a Data Breach 2025.
How a stolen password becomes a breach
1. Infection
An employee’s laptop, at work or at home, picks up an infostealer through a phishing email, malvertising, a cracked download or a fake update.
2. Harvest
The malware silently collects saved passwords, session cookies, autofill data, wallets and system details, then ships them out in a log.
3. Sale
Within hours the log is on offer: private sales, cybercrime forums, automated markets, Telegram subscriptions and ULP lists.
4. Intrusion
An initial access broker or a ransomware affiliate buys the login, walks in through VPN, email or SaaS, and the real attack begins.
Endpoint protection covers the first step and incident response the last. KELA works in the middle, where the credential is traded, which is the only stage an organisation can see from outside.
The underground cybercrime, in KELA’s numbers
Compromised credentials and ransomware victims: January to August 2026 against the same period of 2025. Source: KELA data lake.
Where stolen identities are sold
KELA collects from every one of these channels. That is what makes interception possible.
Private sales
One-off packs of credentials offered directly by the actor who collected them.
Cybercrime forums
Listings and auctions on Russian-language and English-language forums.
Automated markets
Shops with filters by company, country and service, buy in seconds.
Subscriptions
Telegram and cloud channels that deliver fresh logs daily for a monthly fee.
ULP lists
Bulk URL, login and password files traded across mediums.
What KELA does about it
Identity Protection intercepts compromised employee and customer identities from the cybercrime underground, tells you which ones are live, and pushes the fix into the tools you already run.
Intercept compromised identities in real time
Continuous monitoring of botnet markets, cybercrime forums, Telegram channels and infostealer log clouds, matched to your domains, VPNs, SaaS and customer portals the moment a log appears.
Validate which credentials still work
KELA tests intercepted credentials against the login they belong to and classifies each one: critical when it works with no MFA, high when it works behind MFA, low when it no longer works, and flagged when the account is locked or the portal cannot be reached. Teams act on confirmed entry points, not on a list.
Act before the login is used
Alerts by severity and business context, with password resets, session revocation and MFA enforcement pushed through your SIEM, SOAR, identity provider and ticketing tools.
Read more on infostealers and compromised credentials
Book a Demo
Prefer to schedule a meeting right now? Click here.
FAQ
What is identity protection?
Identity protection finds employee and customer identities that have already been stolen, before they are used. KELA’s version watches the places infostealer logs and credential dumps are sold, matches them to your organisation, checks whether each credential still works and drives the reset. It complements endpoint protection and identity providers, which cannot see the underground.
What is the difference between leaked credentials and compromised accounts?
Leaked credentials come from a breach of a third-party service and are often old or reused. A compromised account comes from an infostealer on a machine and usually includes a fresh password, the session cookie and the exact login URL, which makes it far more dangerous. KELA tracks both and treats infostealer output as the higher risk.
How do infostealer infections happen?
Through phishing emails, malicious adverts, cracked or pirated software, fake updates and drive-by downloads. Traffers, actors paid per infection, push these lures at scale. Personal machines that hold work logins are a common route into a company.
Does multi-factor authentication stop this?
It removes the easiest path, and KELA classifies a working credential without MFA as critical for that reason. It does not remove the risk: infostealers also take session cookies that bypass MFA, and actors use MFA fatigue and social engineering to get through. Resetting the credential and revoking the session closes both.
How fast are stolen credentials sold?
Often within a day. Logs are pushed to automated markets and subscription channels shortly after collection, which is why interception has to be continuous rather than periodic.
What does KELA validate, and how?
Each intercepted credential is tested against the authentication system it belongs to and classified as critical (valid, no MFA), high (valid behind MFA), low (no longer valid) or informational (account locked or portal unreachable). Security teams act on confirmed entry points instead of on every match.











