Initial Access Brokers are deliberately selling stolen SME access credentials on the darknet because these companies are often inadequately protected despite generating substantial revenues.
A publicly accessible Elasticsearch server stored 24 billion credentials from infostealer malware collections, placing millions of accounts without MFA at acute risk.