Field notes
Intelligence on exposure, not noise
Field notes on infostealer exposure, session hijacking and defensible incident response, for the teams that have to contain it.

How to Check Your Computer for an Infostealer
Check for an infostealer before you change any passwords. Flashpoint tracked 11.1 million infected devices in 2025. Here is a safe, ordered way to check.

Can a Hacker Bypass Two-Factor Authentication?
Yes, attackers can bypass 2FA by stealing the session after login. SpyCloud recaptured 17.3 billion stolen cookies in 2024. Here is how, and how to stay safe.

Signs your computer has an infostealer
The signs of infostealer infection are often invisible: the malware runs once and exfiltrates in seconds. 80% of breaches now involve stolen credentials.

My Passwords Keep Getting Leaked After I Change Them
If your password keeps getting compromised after you change it, the cause was never removed. 40% of infostealer infections hit devices that ran antivirus.

My password appeared in a data leak: what does it mean?
A Chrome or Apple alert that your password appeared in a data leak means it was found in a known breach corpus. SpyCloud recaptured 3.1B passwords in 2024.

How to log out of all devices after a password leak
After a leak, sign out of all devices to kill stolen sessions a reset leaves alive. Steps for Google, Microsoft, GitHub and AWS. 17.3B cookies stolen in 2024.

How do I know if someone is logged into my account?
Check your account's active-sessions list, then watch for forwarding rules and unknown OAuth apps. SpyCloud found 17.3B stolen session cookies in 2024.

How do I know if my credentials were leaked?
How to know if your credentials were leaked, why a clean checker result is not proof, and the five exposure types tools miss. HIBP indexes 17.6B pwned accounts.

How do I know if my browser cookies were stolen?
You rarely get an alert when browser cookies are stolen. SpyCloud recaptured 17.3 billion stolen session cookies in 2024. Here are the signs to watch.

Have I Been Pwned says I was breached: what should I do?
Have I Been Pwned flagged your email? Here's what to do next: check what leaked, reset reused passwords, and revoke live sessions. HIBP tracks 17.6B accounts.

My email was found in a data breach, but my password wasn't
An email in a breach without your password is the lowest-risk exposure, not zero: 70% of breach victims reused a leaked password. What each case means.

I changed my password after a breach. Am I safe now?
Changed your password after a breach? You may still be exposed: stolen session cookies bypass the reset. SpyCloud recaptured ~17 billion stolen cookies in 2024.

Can hackers access my account without knowing my password?
Yes. Attackers replay stolen session cookies, tokens and hijacked phone numbers to skip your password. SpyCloud recaptured 17.3B stolen cookies in 2024 alone.

Identity exposure management: what it is and how it works
Identity exposure management finds, revokes and rotates leaked credentials before attackers log in. SpyCloud recaptured 17.3B stolen session cookies in 2024.

How to check whether your company credentials have been exposed
A practical method for security teams to check for exposed company credentials across breach data and stealer logs. HIBP alone indexes 17.6B pwned accounts.

Dark web monitoring vs. infostealer monitoring: what each one detects and misses
Dark web monitoring catches breach dumps and forum listings; infostealer monitoring surfaces fresh device logs and live cookies. SpyCloud logged 17.3B cookies.

What is compromised credential monitoring? A guide for security teams
Compromised credential monitoring finds users in breaches and stealer logs before attackers log in. Stolen credentials drove 22% of 2025 breaches (Verizon).

Why a password reset is not enough after an infostealer infection
A password reset won't contain an infostealer: stolen session cookies stay valid until revoked. SpyCloud recaptured 17 billion malware-stolen cookies in 2024.

Infostealer incident response: a step-by-step containment checklist
Infostealer incident response checklist: isolate, revoke live sessions, rotate credentials, scope the blast radius. 276M 2025 creds carried active cookies.

Employee credentials found on the dark web: what security teams should do next
Employee credentials on the dark web signal a live compromise. Here is how to triage in hours: Verizon ties 22% of all breaches to stolen credentials.

Stolen session cookies: how attackers bypass MFA and how to revoke access
Stolen session cookies let attackers replay an authenticated session and skip MFA. SpyCloud recaptured 17.3 billion of them from infected devices in 2024.

Stealer Logs vs. Data Breaches vs. Combolists: What Is the Difference?
Stealer logs, data breaches and combolists are not one threat. Stealer logs are the freshest: 276M carried live session cookies in 2025 (Recorded Future).

What are stealer logs, what they contain and how to respond
A stealer log is everything an infostealer siphons from one infected device: passwords, cookies, tokens. Russian Market listed over 180,000 logs in H1 2025.

What is infostealer malware, and how it steals corporate credentials
Infostealer malware harvests passwords, cookies and tokens from a device, then feeds corporate breaches. SpyCloud recaptured 17.3B stolen cookies in 2024.