Attack vector
Stolen credentials cost $4.67M a breach, and open the front door.
A breach whose initial vector was stolen or compromised credentials, a valid username and password used by the wrong person, averaged $4.67M per incident in the IBM Cost of a Data Breach Report 2025. For years it was the single most common way attackers got in; in 2025 phishing overtook it to become the most common initial vector (16% of breaches). It remains one of the costliest and most dangerous, because a stolen login is not an intrusion the perimeter can see: it is authorised access in the wrong hands.
Average cost
$4.67M
IBM 2025, Figure 9
Historic rank
#1
Long the commonest vector
Cost premium
+5%
vs $4.44M all-breach avg
Now behind
Phishing
Overtaken in 2025 (16%)
Section CT.1
Why a stolen password is so expensive
Every other vector has to defeat a control to get in. Stolen credentials defeat nothing. The login is valid, the session looks legitimate, and to the systems watching the door, an attacker with your password is simply you.
When an attacker signs in with real credentials, there is no exploit to catch, no malware to detonate, and no forced entry to flag. The authentication succeeds because it is supposed to. That is what makes the vector both common and costly: credentials leak constantly, through infostealer malware, reused passwords exposed in unrelated breaches, phishing, and dark-web dumps, and once a valid pair is in an attacker's hands, the single control that reliably stops them is multi-factor authentication. Where MFA is missing, a username and password are the whole lock.
The cost follows from the invisibility. IBM's data is consistent across every edition: the longer a breach goes unidentified and uncontained, the more it costs. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (29%) premium. An attacker moving through systems with legitimate credentials generates none of the signals detection tooling is tuned to catch, so the incident tends to run long, and a long incident is an expensive one.
Section CT.2
Credential theft against the other initial vectors
IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Stolen credentials sit in the costly cluster near the top, close behind malicious insider, supply chain, and phishing, and no vector on the chart is cheap.
The dollar figures are the IBM 2025 initial-vector averages. Stolen credentials land at $4.67M, above the $4.44M all-breach average and only $0.13M below phishing, the vector that displaced it as the commonest. The spread from top to bottom is narrow, which is the point: attackers pick the credential path not because it is cheapest for the victim, but because it is the easiest way in.
Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector). Stolen or compromised credentials averaged $4.67M.
Section CT.3
Two cases: the leaked password and the never-rotated logins
Credential theft is rarely sophisticated. It usually comes down to one valid login that should have had a second factor and did not. Two disclosed cases show the pattern at both ends of scale.
Colonial Pipeline 2021 / one password
$4.4M
Ransom paid; a single VPN login, no MFA
The DarkSide group reached Colonial Pipeline through one compromised VPN account. The credential had turned up in a batch of leaked passwords on the dark web, the account was unused but still active, and it was not protected by multi-factor authentication, so a valid password was the entire barrier. The attackers exfiltrated roughly 100GB of data and Colonial paid a $4.4M ransom. The fuel-supply shutdown that followed made it the case that proved a single stolen credential can halt critical infrastructure.
Snowflake 2024 / UNC5537
~165
Customer accounts targeted; none with MFA
No Snowflake system was breached. Attackers tracked as UNC5537 logged into roughly 165 Snowflake customer accounts using credentials harvested from infostealer-malware infections, some dating back to 2020. The stolen logins were still valid because they had never been rotated, and the targeted accounts lacked MFA, so a username and password were enough. Downstream victims included some of the largest data holders in the US. It is the defining modern credential-theft case: the platform was secure; the customers' passwords were not.
Primary source:Colonial Pipeline: DarkSide intrusion via a single compromised VPN account without MFA; ~100GB exfiltrated; $4.4M ransom paid (Mandiant/Bloomberg, 2021). Snowflake: Mandiant/Google Threat Intelligence attribution to UNC5537, ~165 customer accounts accessed with infostealer-harvested credentials, targeted accounts lacked MFA (2024).
Section CT.4
The 2026 update
In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026) the overall global average rose to a record $4.99M and the US average to $11.5M, and AI moved to the centre of the attacker's toolkit: roughly one in four malicious breaches now involves attacker use of AI, and an AI-enabled breach averaged $6M. Credential theft is where that shift bites first. The same generative tools that mass-produce phishing lures also industrialise credential harvesting and the automated testing of stolen logins at scale, while most breached organisations, IBM found, still lack the AI governance and access controls that would contain the fallout. The $4.67M figure on this page is the 2025 report's per-vector average, the edition in which IBM ranked initial vectors most explicitly; the lever it points to, multi-factor authentication and fast containment, is the same one every case on this page confirms.
Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): global average $4.99M, US average $11.5M, AI-enabled breach average $6M, roughly 1 in 4 malicious breaches AI-enabled. Credential-theft initial-vector cost ($4.67M) from the IBM Cost of a Data Breach Report 2025, Figure 9.
Cross-references
Vector / Phishing
→$4.8M average, the most common initial vector (16%). The vector that overtook stolen credentials, and a leading way they get stolen.
Vector / Malicious insider
→$4.92M average, the costliest initial vector. Authorized access abused from the inside.
Vector / Supply chain
→$4.91M average, 267-day lifecycle, the slowest to contain. MOVEit and SolarWinds blast radius.
Case / Snowflake 2024
→~165 customer accounts, infostealer-harvested logins, no MFA. The defining modern credential-theft breach.
Case / Colonial Pipeline 2021
→$4.4M ransom from one leaked VPN password without MFA. Critical infrastructure halted.
Prevention / Control ROI
→Where MFA, IAM, and identity controls rank on cost saved per breach.
Reference / Global statistics
→Full attack-vector cost table, lifecycle data, year-over-year trends.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Credential-theft initial-vector cost and the under/over-200-day lifecycle premium from the IBM Cost of a Data Breach Report 2025 (Figures 9 and 12); the phishing-overtakes-credentials shift from the IBM 2025 report; 2026 headline figures from the IBM Cost of a Data Breach Report 2026; Colonial Pipeline and Snowflake case facts as cited above.