Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Vector File CT / Stolen & Compromised CredentialsIBM 2025, Figure 9

Attack vector

Stolen credentials cost $4.67M a breach, and open the front door.

A breach whose initial vector was stolen or compromised credentials, a valid username and password used by the wrong person, averaged $4.67M per incident in the IBM Cost of a Data Breach Report 2025. For years it was the single most common way attackers got in; in 2025 phishing overtook it to become the most common initial vector (16% of breaches). It remains one of the costliest and most dangerous, because a stolen login is not an intrusion the perimeter can see: it is authorised access in the wrong hands.

Average cost

$4.67M

IBM 2025, Figure 9

Historic rank

#1

Long the commonest vector

Cost premium

+5%

vs $4.44M all-breach avg

Now behind

Phishing

Overtaken in 2025 (16%)

Section CT.1

Why a stolen password is so expensive

Every other vector has to defeat a control to get in. Stolen credentials defeat nothing. The login is valid, the session looks legitimate, and to the systems watching the door, an attacker with your password is simply you.

When an attacker signs in with real credentials, there is no exploit to catch, no malware to detonate, and no forced entry to flag. The authentication succeeds because it is supposed to. That is what makes the vector both common and costly: credentials leak constantly, through infostealer malware, reused passwords exposed in unrelated breaches, phishing, and dark-web dumps, and once a valid pair is in an attacker's hands, the single control that reliably stops them is multi-factor authentication. Where MFA is missing, a username and password are the whole lock.

The cost follows from the invisibility. IBM's data is consistent across every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (29%) premium. An attacker moving through systems with legitimate credentials generates none of the signals detection tooling is tuned to catch, so the incident tends to run long, and a long incident is an expensive one.

Section CT.2

Credential theft against the other initial vectors

IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Stolen credentials sit in the costly cluster near the top, close behind malicious insider, supply chain, and phishing, and no vector on the chart is cheap.

Malicious Insider$4.92M
Supply Chain Compromise$4.91M
Phishing$4.80M
Credential Theft$4.67M
Denial-of-Service$4.41M
Vulnerability Exploitation$4.24M

The dollar figures are the IBM 2025 initial-vector averages. Stolen credentials land at $4.67M, above the $4.44M all-breach average and only $0.13M below phishing, the vector that displaced it as the commonest. The spread from top to bottom is narrow, which is the point: attackers pick the credential path not because it is cheapest for the victim, but because it is the easiest way in.

Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector). Stolen or compromised credentials averaged $4.67M.

Section CT.3

Two cases: the leaked password and the never-rotated logins

Credential theft is rarely sophisticated. It usually comes down to one valid login that should have had a second factor and did not. Two disclosed cases show the pattern at both ends of scale.

Colonial Pipeline 2021 / one password

$4.4M

Ransom paid; a single VPN login, no MFA

The DarkSide group reached Colonial Pipeline through one compromised VPN account. The credential had turned up in a batch of leaked passwords on the dark web, the account was unused but still active, and it was not protected by multi-factor authentication, so a valid password was the entire barrier. The attackers exfiltrated roughly 100GB of data and Colonial paid a $4.4M ransom. The fuel-supply shutdown that followed made it the case that proved a single stolen credential can halt critical infrastructure.

Snowflake 2024 / UNC5537

~165

Customer accounts targeted; none with MFA

No Snowflake system was breached. Attackers tracked as UNC5537 logged into roughly 165 Snowflake customer accounts using credentials harvested from infostealer-malware infections, some dating back to 2020. The stolen logins were still valid because they had never been rotated, and the targeted accounts lacked MFA, so a username and password were enough. Downstream victims included some of the largest data holders in the US. It is the defining modern credential-theft case: the platform was secure; the customers' passwords were not.

Primary source:Colonial Pipeline: DarkSide intrusion via a single compromised VPN account without MFA; ~100GB exfiltrated; $4.4M ransom paid (Mandiant/Bloomberg, 2021). Snowflake: Mandiant/Google Threat Intelligence attribution to UNC5537, ~165 customer accounts accessed with infostealer-harvested credentials, targeted accounts lacked MFA (2024).

Section CT.4

The 2026 update

In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026) the overall global average rose to a record $4.99M and the US average to $11.5M, and AI moved to the centre of the attacker's toolkit: roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M. Credential theft is where that shift bites first. The same generative tools that mass-produce phishing lures also industrialise credential harvesting and the automated testing of stolen logins at scale, while most breached organisations, IBM found, still lack the AI governance and access controls that would contain the fallout. The $4.67M figure on this page is the 2025 report's per-vector average, the edition in which IBM ranked initial vectors most explicitly; the lever it points to, multi-factor authentication and fast containment, is the same one every case on this page confirms.

Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): global average $4.99M, US average $11.5M, AI-enabled breach average $6M, roughly 1 in 4 malicious breaches AI-enabled. Credential-theft initial-vector cost ($4.67M) from the IBM Cost of a Data Breach Report 2025, Figure 9.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Credential-theft initial-vector cost and the under/over-200-day lifecycle premium from the IBM Cost of a Data Breach Report 2025 (Figures 9 and 12); the phishing-overtakes-credentials shift from the IBM 2025 report; 2026 headline figures from the IBM Cost of a Data Breach Report 2026; Colonial Pipeline and Snowflake case facts as cited above.