10:40 26 February, 2026Database breaches involving logins and passwords happen regularly, yet many users underestimate how quickly stolen credentials turn into real attack tools. According to Ashot Oganesyan, founder of the leak intelligence service DLBI, leaked passwords begin to be actively used for hacking on average within seven days after publication. When it comes to corporate or government accounts, unauthorized access attempts are typically detected within just three days.
There are two main breach scenarios:
In both cases, the stolen data is quickly sorted. The most valuable credentials are corporate and government accounts, which can be easily identified by email domains such as @gov.ru or @company.com. These logins and passwords are often purchased directly by ransomware operators at high prices — which is why attacks on companies frequently begin within three days.
Other data — personal accounts for social networks, email, forums, and online stores — is compiled into cheaper databases and sold on dark web forums and Telegram channels. These databases typically begin to be exploited about a week after the leak becomes public.
“The difference in how quickly passwords are used depends on market demand. Anything that allows access to corporate infrastructure is bought directly by ransomware groups from infostealer operators at higher prices, rather than through dark web forums or Telegram channels, and is immediately used in attacks against company networks,” Oganesyan explained.
Access to corporate email or VPN services often enables hackers to penetrate a company’s internal network, deploy malware, encrypt data, and demand ransom payments. As a result, such credentials disappear from underground markets almost instantly — they are purchased by actors willing to pay more for fast access.
Personal passwords are also exploited, but usually at a slower pace: for large-scale phishing campaigns, social media account takeovers, financial fraud, or resale to other criminals.
The expert offers simple but effective recommendations:
The key takeaway is simple: a leaked password can become an attack tool within 3 to 7 days. The faster you respond to a breach — by changing your password, enabling 2FA, and revoking active sessions — the fewer opportunities attackers will have.
Leaked passwords are typically exploited within seven days of publication. Corporate and government accounts are targeted even faster — often within three days — because ransomware groups purchase them directly. Personal account data is sold in lower-tier dark web and Telegram databases and used somewhat later. Protection is straightforward: use unique passwords, enable two-factor authentication, rely on a password manager, and regularly monitor for breaches. Speed of response is the decisive factor.