On 24 June 2026, Europol announced that police from six countries, working with Microsoft and private cybersecurity firms, had recovered about 27 million stolen login credentials from the infrastructure behind the StealC and Amadey malware families. Reaching those credentials in the window between theft and exploitation gave defenders a rare victory. They reclaimed the one advantage artificial intelligence is eroding across the cyber domain: time.
Cyber warfare now unfolds at machine speed. CrowdStrike’s 2026 Global Threat Report found that in 2025 the average criminal intruder broke out from the first compromised host within 29 minutes, and the fastest in 27 seconds. Against that pace, the machinery of modern defence — boards, approval chains, escalation procedures and incident response runbooks — looks obsolete. It was designed for attackers who paused and hesitated. An organisation that expects to contain every intrusion before significant damage occurs is relying on luck.
From Washington to Canberra, the prevailing assumption is that artificial intelligence has handed the advantage to the attacker by eliminating warning time. The evidence suggests that warning time has not vanished; it has moved. It now exists in the gap between compromise and exploitation. Compromised credentials, session cookies and sensitive datasets routinely circulate through criminal marketplaces for days, weeks or even months before they are weaponised. If attackers exploited stolen access immediately, defenders would have no opportunity to act. The evidence suggests a different reality. Verizon’s 2026 Data Breach Investigations Report found that 73 per cent of ransomware victims had suffered an infostealer infection or credential leak in the previous year, half of them within 95 days of exploitation and the rest earlier still. The breach often begins months before the crisis, and defenders lose because they fail to recognise data theft when it arrives.
Call it the window before impact: the gap between compromise and catastrophe. Against an attacker who can move across a network in minutes, 95 days is an extraordinary advantage. It is time to reset credentials, invalidate stolen tokens, hunt adversaries, alert victims and bring law enforcement into the fight. How an organisation uses that time often determines the outcome. One contains the threat before it escalates. The other discovers the breach when the ransom demand arrives.
The window exists because cybercrime has industrialised. Flashpoint’s midyear threat report identified 1.7 billion stolen credentials and identity records harvested from more than 7.4 million infected devices in the first half of 2026. Malware developers, affiliates, access brokers and ransomware crews now operate as specialised suppliers in a mature criminal economy. An infostealer on a contractor’s personal laptop can deliver validated access to a corporate network without an attacker ever coming near its firewall. Every sale and handover takes time and leaves evidence. The attackers’ supply chain is now their greatest vulnerability.
As attacks accelerate, advantage belongs to whoever sees the stolen assets first.
Artificial intelligence is accelerating the entire battlefield. The technology that lets criminals automate reconnaissance and targeting also lets defenders sift billions of stolen records and expose criminal infrastructure at speed. Microsoft’s Digital Crimes Unit used AI-assisted analysis to reveal links across the StealC and Amadey networks in minutes, work that once took hours or days. Neither side holds the advantage by default. As attacks accelerate, advantage belongs to whoever sees the stolen assets first.
In 1940, radar transformed Britain’s defence by revealing threats before they arrived. Commanders could see Luftwaffe formations assembling across the English Channel and position fighters before the battle reached British skies, while those who waited for visual confirmation had already lost. Infostealer logs, access broker marketplaces and stolen credential repositories are the radar stations of the digital age, exposing adversaries while attacks are still being prepared. Organisations that ignore them are choosing to fight blind.
The radar picture also reveals who is providing sanctuary. Amadey is coded to switch itself off on machines set to Russian, Ukrainian, Belarusian and other regional locales, a clear sign its operators know where the boundaries lie. Microsoft reported in December 2024 that a Russian state espionage group had employed Amadey against Ukraine, and the line between cybercrime and national power is artificial intelligence. Access markets operated by criminals now function as strategic reserves of deniable capability for hostile states. Democracies should treat access brokers, credential marketplaces and malware ecosystems as a standing target for allied intelligence services and offensive cyber operations.
Allied police have shown what disruption achieves. Operation Endgame has relentlessly targeted the infostealer economy since 2024. Its November 2025 phase united authorities from eleven nations, including Australia, to dismantle more than 1,000 criminal servers, and its June 2026 phase froze more than €41 million in criminal cryptocurrency while recovered credentials went to notification services so victims could act. Evidence gathered while criminal infrastructure is live can stop attacks and seize proceeds, and evidence gathered after exploitation does little more than explain what went wrong.
Critics rightly note that stolen credentials are no longer the primary entry point for cyber intrusions. Verizon reported that exploitation of software vulnerabilities overtook stolen credentials as the top initial access vector for the first time in the report’s history, and artificial intelligence is making flaws easier to find. The point is fair and narrows the argument less than it appears, because attackers who enter through a flaw often leave with stolen data or privileged access that surfaces on leak sites and in broker listings. The race then turns on who finds it first: the victim or the extortionist, the police or the broker.
Democracies hold a strategic advantage that is rarely counted: trusted intelligence sharing. Every allied government should maintain a national stolen-data watch that hunts for compromised credentials and corporate access and notifies victims within hours, integrated across the Five Eyes so that a credential discovered in one country triggers defensive action across the alliance. Cybercriminals collaborate without borders, and democracies must do the same.
Australia has a ready vehicle. The Horizon 2 Action Plan should establish a National Stolen Data Watch within the Australian Signals Directorate’s Australian Cyber Security Centre, backed by a statutory safe harbour for accredited researchers who handle stolen data to warn its owners. Australian breach victims routinely seek injunctions against anyone accessing their stolen data, and experts warned in October 2025 that such orders bind the researchers best placed to help. Offshore criminals ignore them, which leaves defenders as the only party bound.
Boards need a sharper instrument. Organisations spend hours on patching rates, phishing simulations, maturity scores and compliance dashboards, which show whether an organisation is compliant but say little about whether it is resilient. Every board should ask a harder question: how long were our stolen credentials, session tokens or datasets circulating before we detected them? Organisations that identify compromised access first can revoke it, contain the risk and control the response. Those that learn of a breach through an extortion demand are already operating on the adversary’s timetable.
The lesson extends beyond cybersecurity. Across finance, defence, intelligence and politics, technology is compressing the distance between action and consequence, and machines will eventually defeat humans in any contest decided by response speed alone. The enduring advantage will belong to those who identify threats before they become emergencies.
In 1854, while London officials counted the dead, John Snow stopped a cholera outbreak by tracing the source to the Broad Street pump and removing its handle. Nearly two centuries later, the strategic logic remains unchanged. In an age of machine-speed competition, advantage belongs not to those who react fastest to a crisis, but to those who find the source before the damage spreads.
The Window Before Impact