A stealer log is not a data breach in the way most security teams imagine one. There is no perimeter event, no exfiltration alarm and no vendor notification. An employee installs a cracked utility on a personal laptop, and forty seconds later every saved password, session cookie and autofill record on that machine is packaged into an archive and shipped to a collection channel.
We traced one such batch, anonymized and with the victim organization's consent, through its full lifecycle. Collection at 03:12. First listing in a subscription channel at 03:40. Indexed by our pipeline at 03:19, between those two events. First credential-stuffing attempt against the victim's VPN gateway: 10:07 the following morning. Total time from infection to hostile use: 31 hours.
INFECTION → HOSTILE USE · 31 HOURS
one batch, anonymizedThe operational lesson is about where you place your tripwire. Detection at the VPN gateway gives you zero hours of warning, because the attempt is the alarm. Detection at the collection channel gives you the full 31. That gap is the entire economics of credential abuse, and it is why "we monitor for breaches" and "we monitor collection channels" are different capabilities that happen to share a marketing category.
One more number worth sitting with: 14 of the records in that batch carried session cookies that were still valid at index time. A password reset closes one door. The sessions minted before the reset walk through another. We measured that window separately.
RELATED PAPERSession cookies outlive password resets: measuring the window