---
title: 4 Million Passwords Tied to Fortune 1000 Companies Are Available on the Dark Web, Research Shows
description: A snapshot of the breach exposure affecting major enterprises has revealed 23 million pairs of credentials containing Fortune 1000 corporate email addresses and plaintext passwords.
image: https://businessinsights.bitdefender.com/hubfs/bank-password-security-1024x538.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

 By [**Filip Truta**](https://businessinsights.bitdefender.com/author/filip-truta) / Mar 26, 2020

# 4 Million Passwords Tied to Fortune 1000 Companies Are Available on the Dark Web, Research Shows

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows&utm_medium=social&utm_source=facebook)

A snapshot of the breach exposure of major enterprises has revealed 23 million pairs of credentials containing Fortune 1000 corporate email addresses and plaintext passwords.

SpyCloud’s database of nearly 100 billion breach assets shows that many employees at Fortune 1000 companies have signed up for a breached third-party site using their corporate email address. Using this data, researchers tied the resulting breach record to their employer – specifically, over 412 million breach assets.

According to the research, over 23 million plaintext credentials tied to Fortune 1000 employees are currently available to cybercriminals on the Dark Web. Some 4 million of them also contain plaintext passwords.

“While not every credential pair will match corporate login details, the ones that do match represent substantial risk for these enterprises—and their customers and partners,” SpyCloud researchers [said](https://spycloud.com/spycloud-research-breach-exposure-of-the-fortune-1000/).

A bird’s eye view by sector quickly reveals some of the industries most affected by this syndrome: Aerospace & Defense, Business Services, Energy, Financials, Healthcare, Technology, Media, and Telecommunications, and many others.

“In theory, corporate passwords should be strong given the importance of the assets they protect and the robust guidance often provided by corporate security teams. In practice, many employees practice bad password hygiene at work,” researchers said.

Across those exposed credentials, employees reused passwords at a rate of 76.5%. That includes C-level executives’ credentials. Passwords for more than 120,000 C-level Fortune 1000 executives are available on the criminal underground, researchers warned. Executives are a prime target for whaling campaigns and Business Email Compromise.

Favorite passwords of the Fortune 1000 include, unsurprisingly, 123456, password, and 123456789, as well as “plenty of expletives,” researchers said.

A key finding reveals the Telecommunications sector as the worst offender – its breach exposure far outstripped every other sector examined, with more than 5.5 million exposed credentials.

Researchers reasoned that employee tenure could have something to do with the sector’s high exposure levels.

“Employees who have owned their corporate email accounts for many years would have had plenty of opportunities to use them on third-party sites,” the SpyCloud report says. “Conversely, high levels of churn could also potentially play a part, with many short-term employees racking up a few exposures each before moving on.”

The Technology sector takes second place, and has the highest number of potentially infected employees. Beyond exposed passwords and potentially compromised users, cybercriminals have access to over 200 million pieces of Personally Identifiable Information (PII) tied to Fortune 1000 employees, all of which can be used in targeted attacks.

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/gao-us-federal-agencies-need-to-fully-establish-risk-management-programs?hsLang=en-us>

### [GAO: US Federal Agencies Need to Fully Establish Risk Management Programs](https://businessinsights.bitdefender.com/gao-us-federal-agencies-need-to-fully-establish-risk-management-programs?hsLang=en-us)

<https://businessinsights.bitdefender.com/cisco-webex-chrome-extension?hsLang=en-us>

### [Corporations at risk of malware attack via Cisco’s WebEx Chrome extension](https://businessinsights.bitdefender.com/cisco-webex-chrome-extension?hsLang=en-us)

<https://businessinsights.bitdefender.com/compromised-employee-accounts-inflicted-the-costliest-data-breaches-over-the-past-year?hsLang=en-us>

### [Compromised Employee Accounts Inflicted the Costliest Data Breaches Over the Past Year](https://businessinsights.bitdefender.com/compromised-employee-accounts-inflicted-the-costliest-data-breaches-over-the-past-year?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Filip Truta",
    "url" : "https://businessinsights.bitdefender.com/author/filip-truta"
  },
  "dateModified" : "2020-03-26T15:28:07.079Z",
  "datePublished" : "2020-03-26T14:51:53.000Z",
  "headline" : "4 Million Passwords Tied to Fortune 1000 Companies Are Available on the Dark Web, Research Shows",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/bank-password-security-1024x538.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/4-million-passwords-tied-to-fortune-1000-companies-are-available-on-the-dark-web-research-shows",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```