How Credentials Became the New Gold
Understand why credentials have become the most valuable commodity in the cybercriminal economy
In this lesson, you will learn to:
- Explain why credentials have become the most valuable commodity in the cybercriminal economy and describe the shift from ransomware to infostealers.
How Credentials Became the New Gold
This lesson explores the shift in the cybercriminal economy from ransomware to infostealers, explaining why credentials have become more valuable than Bitcoin or direct ransom payments.
The Ransomware to Infostealer Shift
In 2024, ransomware was the dominant threat. By 2025, infostealers had taken over. This shift did not happen by accident—it was driven by economics, risk, and the changing nature of the cybercriminal market.
Why ransomware is losing its appeal
Ransomware was once the most profitable malware category. Attackers would encrypt files, demand payment, and hope the victim would pay. But over time, the model has become less attractive.
Consider the risks:
- Payment can be traced and seized by law enforcement
- Ransomware operations are high-profile and attract attention
- Victims are increasingly refusing to pay
- The technical complexity is high
- The operational risk is significant
Attackers have realized that ransomware is a high-risk, high-effort activity with diminishing returns.
Why infostealers are winning
Infostealers offer a fundamentally better business model from the attacker’s perspective:
- Lower risk: Infostealers operate silently. There is no demand, no negotiation, no conversation with the victim. The victim often does not even know they have been compromised.
- Lower effort: Infostealer-as-a-service means you do not need to build the malware yourself. You rent it.
- Higher volume: A single infostealer infection can yield dozens of credentials.
- Reusable value: Stolen credentials are sold multiple times to different buyers.
- Less legal exposure: There is no direct demand for payment, which means fewer legal hooks for law enforcement.
The economics of stolen credentials
Let us look at the numbers from the underground markets.
A single credential can sell for:
- $1-5 for a generic social media account
- $10-50 for a streaming service account
- $50-200 for a corporate email account
- $200-500 for a financial services account
- $1,000+ for privileged access to a high-value corporate system
One infected device can yield:
- 10-50 credentials from browser password managers
- 5-20 cookies and session tokens
- 1-3 cryptocurrency wallets
- Various system and personal documents
A single infection can generate $100-$500 in stolen data value on the open market. The attacker invests almost nothing beyond the cost of the infostealer service.
This is why 11.1 million devices were infected in 2025. The economics are simply too attractive.
The evolution of the market
The market has evolved from ransomware to infostealers because it is more efficient. Attackers have followed the path of least resistance. Credentials are the new gold because they are:
- Easy to steal
- Easy to sell
- Easy to reuse
- Almost impossible to trace
In the next module, we will look inside the infostealer itself and understand the technical mechanisms that make these attacks so successful. But before we do, ask yourself: if you were an attacker, would you choose the noisy, high-risk ransomware approach, or the silent, low-risk infostealer approach? The numbers tell us the answer.
The Economics of Stolen Credentials
Stolen credentials are valuable because they are reusable access, not merely strings in a database. A criminal can test a username and password against several services, use a session cookie to bypass a password prompt, or sell access to a corporate account to another criminal. This creates a chain in which one infection can support many independent crimes.
The price of a record depends on freshness, geography, account type, access privileges, and whether the buyer can verify that it still works. A corporate identity with access to cloud applications is more valuable than an old personal password. This is also why password reuse is dangerous: one low-value breach can become the starting point for a high-value takeover.
Defenders should think in terms of exposure reduction. Password resets, session revocation, phishing-resistant MFA, device isolation, and monitoring for unusual sign-ins break different parts of the criminal chain. The goal is not to predict an exact resale price; it is to understand why stolen data remains useful after the original infection.