According to Verizon, “use of stolen credentials” has been one of the most popular methods for gaining initial access over recent years. The use of stolen credentials appeared in a third (32%) of data breaches last year, its report notes. Infostealers are thought to have been responsible for 75% of compromised credentials last year. Infostealers are thought to have been responsible for 75% of compromised credentials last year. The gang leveraged a set of stolen credentials to remotely access a server that did not have multifactor authentication (MFA) turned on.