| Measure | A | B |
|---|
| Login URL | Type | Machines | Next step |
|---|
Infostealer malware copies saved passwords, cookies and autofill data from a browser and uploads the bundle (a log) to the operator. Logs are sold and shared, and threat intelligence firms index which domains appear inside.
Data comes from Hudson Rock's free Cavalier OSINT API, requested through pwnsy.com and cached for six hours. pwnsy shows only aggregate counts and login URLs. Email lookups are not offered because they return data about one person.
An employee is a machine that held a login to the domain's staff systems; a user held a login to its customer service. A zero means this one source has no matching logs. Dates are infection dates, often weeks before the log surfaces. One person can own several machines.
Login types come from pwnsy's URL rules (SSO, VPN, mail, engineering, admin, business app, portal). Background: what an infostealer takes, how dark web monitoring works, why a stolen cookie gets past MFA.