The underground cybercrime economy is evolving fast with millions of endpoint logs listed on underground markets. Logs are underground slang for username, passwords, and occasionally cookies extracted from a victim endpoint with stealer malware. Threat actors can purchase these logs on the underground and use them to access confidential accounts and data and even to deploy further attacks, such as ransomware. Contact us for a detailed analysis tailored to your company—covering endpoint logs, stolen credentials, and strategies to protect your extended attack surface. Below, explore endpoint log statistics from 2025-2026, updated monthly.
Endpoint log victims by country
In the past 12 months, India led all countries with 332707 endpoint logs, or 12.9% of the total. Below are the top endpoint log victims per country.
Top 10 countries
More signal, less noise. Latest cyber threat headlines from Bitsight Pulse.
-
2026-06-13 | Sale of access to German financial domain user accountThe post on the underground forum advertises the sale of access to a domain user account related to a financial entity in Germany…
-
2026-06-13 | Underground forum post offering various cyber exploits and data for saleThe post on an underground forum advertises several cyber exploits and data for sale. It includes a Prestashop shell with databas…
-
2026-06-12 | Sale of admin rights to AU Wordpress shopThe post discusses the sale of admin rights to an AU Wordpress shop, detailing the number of payments received over several month…
-
2026-06-12 | Underground forum post offers shell access for financial transactionsThe post on an underground forum discusses the sale of shell access for conducting financial transactions in various countries, i…
-
2026-06-12 | Underground forum post offers shell access for financial transactionsThe post on an underground forum discusses the sale of shell access for conducting financial transactions in various countries, i…
Bitsight Pulse consolidates the latest cybersecurity news, ransomware events and data breaches from hundreds of deep web, dark web, social and OSINT sources. Using Bitsight AI, Bitsight Pulse filters and personalizes these news events to your interests.
Latest cyber threat blogs
Featured blog
NoName057(16) remains an active pro-Russian DDoS threat despite Operation Eastwood. Learn how Bitsight helps organizations detect, monitor, and respond.
Free Benchmark Report
Free, customized cyber risk benchmark report
This custom report provides key takeaways regarding your company’s cybersecurity posture (likelihood of breach, industry benchmarks, and threat insights) using Bitsight data that has been independently verified to have the strongest correlation to the likelihood of a cyber incident.