bg
Cybersecurity
13:00, 27 July 2026
views
17

Hackers Turn Leaked VPN Passwords Into Corporate Breach Tools

Hackers are exploiting credentials stolen from free VPN services to break into corporate systems, according to an analysis by Russian leak and dark web monitoring service DLBI.

DLBI experts analyzed more than 200 data breaches and created test "honeypots" simulating corporate VPN environments. The experiment revealed that more than 35% of login attempts relied on credentials that had already been compromised, while another 20% consisted of automatically generated variations of those usernames and passwords. The primary threat lies in password reuse. Even a breach at a third-party service can be linked to a specific company and then used to attempt access to its internal infrastructure.

Risk Factor for Business

DLBI's research is significant for the cybersecurity market because it demonstrates that user behavior has become a direct business risk. A successful login through a corporate VPN can give attackers access to internal systems, documents, personal data, and critical business services.

For individual users, the findings serve as a warning about the risks of relying on unverified free VPN services and reusing the same passwords across multiple accounts. More broadly, reducing these risks strengthens the resilience of businesses, government agencies, and critical infrastructure operators.

Growing Demand for Behavioral Analytics

The findings suggest that organizations should strengthen account security by implementing multi-factor authentication, prohibiting password reuse, monitoring suspicious login activity, and tracking whether employee credentials appear in data breaches.

Another promising direction is integrating leak and dark web monitoring with identity and access management systems. If a password is found to have been compromised, access can be blocked automatically while forcing a credential reset. That trend is driving demand for IAM, PAM, SIEM, Threat Intelligence, and behavioral analytics platforms.

Notably, password reuse was identified in 20% of security assessment projects conducted in 2025, while weak or default passwords appeared in 53%. In 2026, approximately 24% of attacks targeting user accounts involved credential stuffing.

The export potential lies in threat monitoring and access management technologies, which are in demand across CIS markets and countries with extensive remote access infrastructure.

A Shadow Market for Corporate Credentials

In 2023, F.A.C.C.T. identified the compromise of remote access services – primarily RDP and VPN – as one of the leading methods attackers used to penetrate corporate networks. That year, 246 databases belonging to Russian companies appeared in public and underground sources. During the same period, Kaspersky reported a 33% increase in data leaks and noted that stolen credentials were being used to gain access to corporate resources.

The trend intensified in 2024. According to Positive Technologies, the share of leaked corporate credentials rose to 21% – up 9 percentage points year over year – including usernames and passwords for VPN, RDP, SSH, and email accounts. At the same time, F.A.C.C.T. documented campaigns by the Shadow and Twelve groups, which relied on credentials purchased from underground marketplaces and externally accessible remote access services. Between February 2023 and July 2024, at least 50 Russian organizations were affected.

During 2025-2026, analyses of domains belonging to major companies uncovered thousands of accounts that had been exposed in data breaches together with passwords or password hashes. Taken together, these findings point to the emergence of a mature underground market for corporate credentials that fuels automated attacks.

Employee Training and Multi-Factor Authentication for VPNs

Data leaks originating from free VPN services are evolving from an isolated consumer issue into one link in the attack chain targeting businesses. In many cases, attackers do not need sophisticated exploits. Obtaining a password from a third-party service and testing it against corporate resources is often enough.

According to industry forecasts, organizations will increasingly move beyond password-only protection toward continuous verification of digital identity. Multi-factor authentication for VPN access, leak monitoring, least-privilege access controls, and detection of suspicious logins are expected to become the primary security measures.

Employee awareness training may also assume a particularly important role, as using personal services – including free VPNs – with work-related data significantly increases risks to corporate security.

Until recently, one of the biggest challenges for attackers was linking leaked credentials to specific companies. They have now learned to solve that problem by using data leaked from government agencies, as well as by taking advantage of users who register for various online services with their corporate email addresses. Today, companies need to pay maximum attention to the risk posed by password reuse and deploy specialized services that can detect when credentials appear in data breaches and automatically reset those credentials or lock the affected account
quote
like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next