Research notes on exposure, stealers, and ransomware. Written for people who respond to incidents.
A stealer log is session material (cookies, tokens, often wallets), not a password spreadsheet. Reset without revoke leaves the door open.
In DBIR 2026, 73% of ransomware victims already had a stealer or credential leak. The warning usually comes before the extortion site.