Exposed Passwords on Endpoints Are More Common Than You Think

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress scanned over 2 million managed endpoints across 4,000+ partner accounts and found plaintext password files on approximately 1.6% of endpoints — over 32,000 machines total. More than 200 partners had exposed password files on 5% or more of their endpoints. The post outlines the risks of storing unencrypted credentials in files like Notes, Word docs, or Excel sheets, and recommends password managers, MFA, security awareness training, and environment monitoring as mitigations. Huntress has added a 'Credential Reports' feature to its Managed EDR product to alert partners when exposed password files are detected.

5m read timeFrom huntress.com
Post cover image
Table of contents
Files with Exposed Passwords: How Prevalent Are They?How To Protect Against Stolen CredentialsHuntress Can HelpPassword SimulationStart for Free Today