October 2024 Threat Intelligence Summary
October 2024 numbers from the Revealer.US corpus: more breach records, more stealer logs, more combo lists than September. The rest of the report is where those records came from and who was using them.
Key Statistics
| Metric | October 2024 | September 2024 | Change |
|---|---|---|---|
| New breach records surfaced | 847M | 623M | +36% |
| Unique stealer log entries | 12.4M | 9.8M | +27% |
| New combo lists identified | 156 | 134 | +16% |
| Underground forum posts monitored | 45K | 41K | +10% |
Every number above moved in the same direction: more records, more logs, more chatter. If you want to check whether a specific address shows up in the new material, run it through the data breach lookup.
Major Breach Events
Healthcare Sector Under Siege
Healthcare stayed the loudest vertical:
Notable Incidents:
- Regional hospital chain: 2.3M patient records
- Health insurance provider: 890K member records
- Medical laboratory network: 450K records including test results
Pattern Analysis:
- Primary vector: Compromised VPN credentials
- Ransomware groups claiming responsibility: BlackCat, LockBit
- Average time to detection: 23 days
Twenty-three days is the number worth sitting with. That is three weeks of quiet access before anyone noticed.
E-Commerce Breaches
Holiday prep did not go quietly:
- Three major retailers experienced Magecart-style attacks
- Estimated 340K payment cards harvested
- Increase in checkout page skimmers detected
Infostealer Trends
Lumma Stealer Dominance
Lumma led the family mix in October:
Distribution by Family:
- Lumma: 34%
- RedLine: 28%
- Raccoon: 19%
- Vidar: 12%
- Other: 7%
Stealer output is where most corporate account takeovers now begin, so it pays to know what has already been dumped. Our stealer logs search covers that material directly.
Notable Lumma Capabilities
What the current Lumma builds actually do:
- Browser cookie extraction (including Chrome's encrypted cookies)
- Cryptocurrency wallet targeting (expanded to 40+ wallet types)
- Session token harvesting for SaaS applications
- Anti-analysis techniques to evade sandboxes
Session token theft is the part defenders keep underestimating. A stolen token walks straight past MFA because the login already happened.
Distribution Campaigns
Observed vectors this month:
- Fake CAPTCHA pages: Users tricked into running PowerShell commands
- Cracked software: Adobe, Microsoft Office, gaming tools
- YouTube tutorials: Links to "tools" in video descriptions
- Discord malware: Compromised game modifications
Credential Intelligence
Exposed Corporate Credentials
Corporate credentials in the October dump:
- Fortune 500 companies: 12% showed new credential exposure
- Technology sector most affected (34% of corporate exposures)
- Average of 2,100 new corporate credentials surfacing daily
Checking a single work address against known breach datasets takes seconds with an email lookup, and it is the cheapest control most teams still skip.
Password Analysis
From October's breach data:
Most Common Passwords:
- password123 (still!)
- Company name + year
- Qwerty variations
- Welcome1
- Seasonal passwords (Fall2024)
Positive Trends:
- Slight increase in password manager adoption indicators
- More unique passwords in newer breaches
Threat Actor Activity
Ransomware Groups
Most Active Groups (by victim count):
- LockBit 3.0 - 89 claimed victims
- BlackCat/ALPHV - 67 claimed victims
- Play - 45 claimed victims
- Akira - 38 claimed victims
Initial Access Broker Activity
Increased activity from Initial Access Brokers (IABs) selling:
- VPN credentials: Average price $2,400
- RDP access: Average price $1,800
- Web shell access: Average price $650
Those prices are the honest market value of a reused password on your VPN.
Nation-State Activity
Observed campaigns attributed to:
- APT groups: Targeting defense contractors, think tanks
- Focus areas: Intellectual property, policy documents
- TTPs: Supply chain compromise, watering hole attacks
Geographic Trends
Most Affected Regions (by breach volume)
- United States: 42%
- European Union: 23%
- United Kingdom: 8%
- India: 7%
- Brazil: 5%
Emerging Targets
Increased targeting observed in:
- Southeast Asian financial services
- Middle Eastern energy sector
- Latin American government entities
Recommendations
Immediate Actions
- Review VPN security: Implement MFA, monitor for credential exposure
- Employee awareness: Alert staff to ongoing phishing campaigns
- E-commerce monitoring: Extra vigilance during holiday preparation
- Healthcare sector: Prioritize network segmentation
Strategic Priorities
- Implement continuous credential monitoring
- Enhance detection for stealer malware
- Review third-party access controls
- Tabletop exercises for ransomware scenarios
If you are still checking exposures by hand, start from the OSINT tools list. One Revealer.US search (email, username, phone, name, or address) hits 800+ platforms, public records, and known breach datasets. Free tier, paid self-serve from $12.99/mo, custom Enterprise. Revealer is not a consumer reporting agency and must not be used for employment, tenant, or credit decisions.
Looking Ahead: November Predictions
What November is likely to look like, based on this month:
- Increased holiday-themed phishing: Black Friday, Cyber Monday lures
- Retail targeting: Point-of-sale and e-commerce focus
- Tax preparation: Early tax-related phishing (some regions)
- Year-end ransomware push: Groups seeking to meet quotas
About This Report
Counts in this report come from what Revealer.US actually monitors:
- 200+ platforms
- Real-time breach data monitoring
- Underground forum analysis
- Stealer log coverage
For detailed indicators of compromise (IOCs) from this month's threats, contact your Revealer.US account representative or reach out to our team.