External credential telemetry reveals hundreds of thousands of employee-domain exposure events and millions of session and credential artifacts circulating outside enterprise perimeters, often without any corresponding public breach disclosure.

NEW YORK – Investors evaluating enterprise risk traditionally encounter cybersecurity incidents only after an intrusion is confirmed, becomes financially material, or triggers mandatory regulatory reporting. However, critical access artifacts, ranging from active session cookies and API keys to direct corporate login credentials frequently circulate across illicit channels months before an incident is detected or disclosed.
A technical assessment conducted by cybersecurity intelligence firm Lunar Cyber highlights this operational reality, demonstrating that external credential exposure represents an overlooked quantitative signal for assessing corporate risk. Analyzing public Domain Exposure telemetry across ten major corporations spanning technology, financial services, retail, media, manufacturing, and energy, Lunar Cyber documented 747,485 credential exposure events directly tied to accounts operating under the organizations’ own primary domains. Across all analyzed domains, the dataset registered 63,421,021 total exposure events, with every company in the evaluation exhibiting direct exposure to infostealer malware logs.
External Exposure as an Early Risk Signal
In the public markets, material breach notifications generally serve as lagging indicators of risk. By the time a corporation issues a regulatory filing, unauthorized third parties may have leveraged compromised access materials to navigate enterprise infrastructure, extract intellectual property, or deploy disruptive payloads.
The findings indicate that external exposure intelligence can provide earlier visibility into potential access risks that may otherwise remain outside an organization’s security perimeter. Modern corporate authentication relies heavily on continuous sessions and federated identity providers. When these access tokens escape the perimeter, they expose organizations to systemic risk without triggering typical internal monitoring alerts or indicating a direct breach of core company servers.
Employee vs. Consumer Exposure Profiles
The dataset draws a distinction between company-domain exposures, which involve accounts associated with an organization’s own domain and may provide access to corporate systems, and client or service exposures, where the company’s platform is the login destination for external users.
- High-Volume Consumer Targets: Technology and consumer platforms showed massive aggregate numbers driven almost entirely by external customer credentials. Apple registered 46,192,884 total events, yet only 209,767 involved @apple.com company-domain accounts. Similarly, OpenAI accounted for 11,104,624 total events, with just 531 tied directly to @openai.com corporate accounts.
- High-Proportion Enterprise Exposure: Conversely, enterprise-focused operations exhibited exposure patterns overwhelmingly weighted toward company-domain accounts. At Owens Corning, 52,003 out of 55,561 total events (93.6%) involved company-domain accounts. Energy provider Eversource reflected 44,349 employee-domain events out of 83,098 total records (53.4%), while Mastercard registered 37,629 employee-domain events out of 145,765 total exposures (25.8%).
While consumer exposures indicate platform targeting and account-takeover liabilities, exposed employee accounts pose direct risks to internal systems, software-as-a-service (SaaS) environments, source-code repositories, and virtual private networks (VPNs).
Infostealers and the Erosion of Perimeter Defenses
A key driver behind these exposed credentials is the proliferation of infostealer malware, including families such as LummaC2, Rhadamanthys, RedLine, Vidar, and Acreed. Rather than harvesting static credentials from historical database breaches, infostealers execute directly on compromised endpoints, extracting active browser cookies, authenticated sessions, API tokens, and machine-level credentials.
Across the ten analyzed enterprises, Lunar Cyber identified 10,760,892 infostealer-derived events, accounting for 17.0% of the entire sample. The concentration varied widely by organization:
- Disney: 38.2% of all exposures derived from infostealer logs (1,178,498 events)
- Broadcom: 29.9% infostealer share (146,842 events)
- OpenAI: 26.8% infostealer share (2,970,498 events)
- Mastercard: 13.5% infostealer share (19,624 events)
- Apple: 13.4% infostealer share (6,197,100 events)
- Interactive Brokers: 13.4% infostealer share (37,395 events)
- Chewy: 11.6% infostealer share (31,475 events)
- Target: 10.1% infostealer share (172,666 events)
- Eversource: 6.0% infostealer share (4,981 events)
- Owens Corning: 3.3% infostealer share (1,813 events)
Unlike traditional static passwords, which are often mitigated by multi-factor authentication (MFA), stolen authenticated session cookies can allow attackers to bypass the normal login process, including MFA in some circumstances. Stolen API tokens and service-account keys can similarly provide automated access to production environments, developer pipelines, and cloud resources without requiring an interactive human login.
Gateways to Enterprise Infrastructure
The analysis revealed that exposed credentials routinely correlated with critical enterprise identity and infrastructure gateways. Telemetry across the sample captured access materials associated with Okta, Microsoft, Citrix, Git, Jira, Salesforce, OneLogin, Cisco AnyConnect, Fortinet VPN, F5, and Pulse Secure.
Broadcom’s telemetry included credentials tied to Okta, Jira, Microsoft, OneLogin, Salesforce, and Git. Apple’s records reflected access artifacts connected to Citrix, Git, Cisco AnyConnect, Fortinet VPN, and Microsoft. Disney’s data encompassed exposures across Microsoft, Citrix, F5, Okta, Git, Pulse Secure, and Jira.
These exposure records do not mean that any of the companies analyzed suffered a breach. They indicate that credentials or authentication artifacts associated with their domains appeared in external telemetry, often because an endpoint used to access the company was infected or otherwise compromised.
Rethinking Diligence and Risk Assessment
Because most corporate security controls focus inward on internal networks, identity repositories, and corporate-managed endpoints, organizations can have limited or no visibility into access data circulating on external underground marketplaces or peer-to-peer distribution networks. An infection on an unmanaged personal device used by a remote employee or third-party contractor can export valid corporate session tokens without triggering an alert inside an internal Security Operations Center (SOC).
For investors, risk officers, and boards, credential exposure telemetry provides another measurable signal that can be evaluated alongside breach disclosures, security ratings, regulatory filings, and other indicators of cyber risk.
Research Methodology
The research was compiled through Lunar Cyber’s Domain Exposure intelligence engine, which continuously monitors open sources, infostealer telemetry, and unauthorized data releases over rolling 12-month periods. The assessment analyzed ten enterprise domains: Apple, Mastercard, Disney, OpenAI, Interactive Brokers, Chewy, Owens Corning, Eversource, Broadcom, and Target. Exposure events reflect recorded instances where domain-associated identifiers appeared in telemetry, rather than deduplicated individuals, distinct passwords, or confirmed security breaches.
Organizations and analysts can review their domain telemetry, including breakdown by employee accounts, client footprints, and active infostealer families, at https://lunarcyber.com/domain-exposure.
About Lunar Cyber
Lunar Cyber provides enterprise visibility and threat intelligence solutions focused on mapping external identity risks and credential compromise. By tracking infostealer output, illicit marketplaces, and distributed exposure events outside corporate perimeters, Lunar Cyber enables security teams, risk managers, and enterprise leaders to identify and revoke compromised access artifacts before they can be leveraged in operational intrusions.
For more information, visit https://lunarcyber.com.