
By Estelle Ruellan, Threat Intelligence Researcher
Between January 2025 and May 2026, more than 821,000 stealer logs containing fintech credentials appeared on underground forums worldwide. Nearly a quarter of a million of them belonged to devices in EMEA. That means more than one in every four compromised machines with fintech access globally sits in Europe, the Middle East, or Africa. The exposure spans every layer of the financial stack: consumer bank accounts, payment platforms, cross-border transfer services, and, most critically, the core banking engines that process transactions for entire institutions. Monthly volumes are climbing, not shrinking, and the credentials are already circulating.
Key Insights of Fintech Stealer Logs in EMEA
- Over one in four fintech-exposed devices globally is in EMEA. Over the past 18 months, EMEA accounted for 231,672 out of 821,492 fintech credential logs worldwide, 28.21% of global exposure.
- Monthly exposure is climbing in 2026. EMEA fintech logs averaged 13,410 per month in 2025. In the first five months of 2026, that figure has risen to 14,150.
- The top five Western European markets account for 28.6% of all EMEA fintech exposure, nearly three in 10 logs. France tops the EMEA chart at approximately 15,000 logs, narrowly ahead of the UK (14,600), Germany (14,200), and Italy (13,100).
- Seven out of 10 compromised devices contained fintech/specialist platform credentials. Fintech specialist platforms like Wise, Stripe, Klarna, and Adyen dominate the dataset at 181,469 logs (70.9%), far outpacing traditional banks (18.3%), challenger banks (10.5%), and banking infrastructure (0.3%).
- 728 logs exposed the infrastructure that powers banks themselves. While a fraction of the dataset, 728 logs contained credentials to core banking platforms like Thought Machine, Temenos, Finastra, and FIS Global, the engines that process transactions and manage accounts for some of the world’s largest financial institutions.
Identity Intelligence for Financial Services
Find Your Organization’s Compromised Credentials Before Threat Actors Use Them
231,000 EMEA devices with fintech credentials surfaced on underground forums in the past 18 months — and monthly volumes are climbing. Flare continuously monitors stealer log marketplaces to detect when your employees’ or customers’ banking and fintech credentials appear, giving your team the window to remediate before account takeover occurs.
The Scale of EMEA Exposure
Over the past 18 months, 821,492 stealer logs containing fintech access credentials were shared on underground forums worldwide. EMEA accounted for 231,672 of them, or 28.21% of the global total. Put simply, over one in every four compromised devices with fintech access globally originates from the EMEA region.

This regional exposure is not new. Across Flare’s entire collection, 801,192 EMEA-based infected devices have yielded fintech credentials, and over a quarter (28.91%) of that total surfaced in the last 18 months alone.
The trend seems to be accelerating. In 2025, over 160,922 EMEA fintech logs appeared on underground forums, averaging around 13,410 per month. In the first five months of 2026, that monthly average has climbed to roughly 14,150, representing a 6% increase, with 70,751 logs already shared as of late May.

The figure above shows the monthly volume of EMEA fintech credential logs from January 2025 to May 2026. Volumes peaked sharply in January 2025 at over 24,000 logs before declining through the summer to a low of around 7,600 in August 2025, then stabilizing into a steadier range of 11,000 to 17,000 logs per month from September 2025 onward.
Geographic Distribution Within EMEA

The above horizontal bar chart displays the top 25 sources of EMEA fintech logs. The geographic distribution of EMEA fintech logs reveals that exposure is spread broadly across the region. France leads with approximately 15,000 logs, closely followed by the UK at around 14,600, then Germany at 14,200 and Italy at 13,100. Spain rounds out the top five at around 9,300. Together, these five Western European markets account for 28.6% of EMEA fintech exposure: nearly three in 10 EMEA fintech logs originate from these five Western European countries.
Beyond Western Europe, the data shows significant volumes from Africa and the Middle East. Nigeria ranks 6th at 8,421 logs, ahead of every European country outside the top five. Egypt and Algeria follow at 6,100 and 5,800 respectively, with the UAE (5,235), Kenya (5,029), and Morocco (4,818) also featuring prominently.
From South Africa onward, the chart flattens into a long tail of countries each contributing around 1,200 to 2,200 logs, including Angola (2,163), Ghana (2,058), Hungary (1,885), Saudi Arabia (1,788), Belgium (1,749), Tunisia (1,415), Greece (1,230), and the Czech Republic (1,195). This broad distribution underscores that fintech credential theft is not confined to a handful of high-profile markets but is a region-wide issue, touching countries across every corner of Europe, the Middle East, and Africa.
Banking and Fintech Services Compromised
A breakdown by service category reveals that specialist fintech platforms dominate the credential dataset by a wide margin. The horizontal bar chart below illustrates the volume of logs per service category.

Fintech and Specialist Platforms: 181,469 Logs (70.9%)
Platforms like Wise, Stripe, Klarna, GoCardless, Adyen, and Zilch are not banks. They don’t hold deposits or offer current accounts. Each one is built around a specific financial function, international money transfers, payment processing, buy-now-pay-later credit, direct debit collection, or open banking connectivity.
A compromised account on these platforms could enable unauthorized international transfers, manipulation of payment collection mandates, fraudulent purchases on credit, or access to the financial plumbing that connects bank accounts to third-party services.
With over 181,000 logs, specialist fintech platform credentials are in seven out of 10 infected devices in our dataset.
Traditional & Established Banks: 46,840 (18.3%)
Over 18% of EMEA fintech logs had a traditional bank access. HSBC, Standard Chartered, BNP Paribas, Deutsche Bank, ING, Société Générale, and Emirates NBD represent the institutional backbone of EMEA banking. Most people use it everyday for tasks such as banking, payroll, mortgages and savings.
A compromised credential here is a direct line to current accounts, savings, transaction histories, and personal financial data. Unlike specialist platforms where exposure is typically limited to a single function, a traditional bank account is the financial hub: payroll deposits, mortgage payments, direct debits, and card transactions all flow through it, making each compromised credential a gateway to a complete financial profile.
Digital Challenger Banks: 26,942 (10.5%)
Revolut, Monzo, N26, and their peers are the app-first banks built to compete with the traditional institutions. At nearly 27,000 logs, challenger banks trail the traditional institutions in absolute volume but represent a meaningful 10.5% share of EMEA fintech logs. The risk from a compromised challenger bank account is identical to a traditional bank: full access to the account, balances, transaction history, and the ability to initiate payments or transfers.
Banking Infrastructure (B2B): 728 (0.3%)
While 728 logs is a fraction of the dataset, this is arguably the most consequential category in the entire report.
Banking infrastructures such as Thought Machine, Tenemos, Finastra, or FIS Global build the core banking engines, payment rails, and ledger systems that banks and fintechs run on. Their clients include some of the largest financial institutions in the world.
Compromised credentials to banking infrastructure could expose the infrastructure that processes transactions, manages accounts, calculates interest, and enforces compliance rules for millions of customers across multiple institutions simultaneously. A threat actor with access to a core banking platform could, depending on the level of privilege, view or manipulate how accounts are structured across client banks, interfere with transaction processing logic, or disrupt ledger operations at scale.
The blast radius of even a single compromised banking infrastructure credential is every institution running on that infrastructure. This dataset contains 728 of them.
It’s worth noting that banking infrastructure platforms have no consumer-facing accounts. No “customers” log into Temenos or Thought Machine. Every one of those 728 credentials potentially belongs to an engineer, consultant, or integration specialist working on systems that power banks. These logs suggest the compromised machines were used for corporate activities, making them corporate device infections rather than consumer ones.
Client vs. Employee Exposure
Of the 231,672 EMEA fintech logs collected over the past 18 months, 954 contained both a fintech platform credential and a corporate email belonging to the same company. The presence of a corporate email alongside platform access on the same infected device strongly suggests the machine was used for work purposes, meaning the compromised individual is not a customer but an employee. Corporate exposure carries a fundamentally different risk profile: a single compromised employee credential can provide a threat actor with a foothold into internal systems, far beyond what any customer account could offer. These 954 logs, combined with the 728 banking infrastructure credentials, point to a corporate attack surface that raw volume figures alone do not capture.
We will dive deeper into these analyses by examining two countries: France and the UK.
Deeper Dive One: France’s Exposure
France accounts for 15,043 stealer logs over the last 18 months. The monthly log volume chart below tracks that activity across the period. France’s monthly fintech log volume mirrors the wider EMEA trend, though at a much lower scale. France averaged 1,258 fintech stealer logs per month in 2025 and 1,844 per month so far in 2026, a 47% increase in monthly volume, well above EMEA’s 6% rise. It’s worth noting, however, that the 2026 figure covers only five months, so this isn’t a full-year comparison.
The blue line, representing France’s monthly volume, shows an upward trend beginning in September 2025, a sharp peak in January 2026, and a steadying at around 1,800 logs per month through 2026, mirroring the global EMEA trend.

Banking and Fintech Services Compromised
France stands out in the mix of fintech and banking credential categories found in its logs. Where the broader EMEA dataset was dominated by fintech specialist platform credentials alone, France’s logs are defined by two categories rather than one: digital challenger banks and fintech specialist platforms.

Fintech Specialist Platforms: 13,781 Logs (91.6% of Devices)
Fintech specialist platform credentials appeared in roughly nine of every 10 French compromised devices (13,781 logs, 91.6%), far outpacing the EMEA equivalent of 70.9%.
Top fintech specialist platforms in French logs:

Digital Challenger Banks: 10,784 Logs (71.7% of Devices)
This is where France diverges most sharply from the regional profile. Challenger bank credentials appeared on about seven in 10 French compromised devices or 70%, compared to just 10.5% across EMEA. N26’s dominance (9,474 logs) suggests particularly deep adoption of this platform among French users whose devices have been compromised by infostealers.
Top digital challenger banks in French logs:

Traditional and Established Banks: 5.2% of Devices
Traditional and established banks tell the opposite story, appearing in just over 5% of French compromised devices versus 18.3% across EMEA. These patterns may point to broader adoption of digital challenger banks in France than in the rest of the region, alongside a lighter traditional-banking footprint.
Top traditional established banks in French logs:

Banking Infrastructure (B2B): 21 Logs (0.1% of Devices)
Banking infrastructure (B2B) credentials were rare, found on just 21 French devices, 0.1% of France’s fintech logs. Small as that slice is, it’s notable that these are credentials to core banking platforms, with 19 of the 21 tied to FIS Global.
Note: a single device can contain credentials for multiple providers, so category figures overlap and do not sum to the country total.
Client vs. Employee Exposure
Of the 15,043 France fintech logs collected over the past 18 months, 73 contained both a fintech platform credential and a corporate email belonging to the same company. The presence of a corporate email alongside platform access on the same infected device strongly suggests the machine was used for work purposes, meaning the compromised individual is not a customer but an employee. Corporate exposure carries a fundamentally different risk profile: a single compromised employee credential can provide a threat actor with a foothold into internal systems, far beyond what any customer account could offer.
Top five domains from employee exposure logs:

BNP Paribas alone accounts for 40 of the 73 devices, roughly 55% of France’s fintech employee exposure. This concentration is unsurprising as one of France’s largest banks and a domestically headquartered institution, it has by far the biggest French workforce among the companies tracked, so France-located employee devices naturally skew toward it. Worldline, a French payments firm, follows the same logic.
Foreign institutions such as Nationwide and HSBC (UK), Deutsche Bank (Germany), ING (Netherlands), and Flutterwave (Africa) also appear on France-located employee exposure devices. Here the geolocation reflects where the infected machine was, not where the company sits, so these could represent French-based staff of multinationals’ local offices or remote workers.
Taken together, employee exposure is a small slice of France’s fintech logs but a qualitatively distinct one. Where the customer-credential findings in this report speak to consumer fraud risk, these 73 devices point to a supply-chain and insider-access risk: infected staff endpoints that could serve as initial-access vectors into the institutions themselves.
Deeper Dive Two: The Scale of the UK’s Exposure
The UK’s fintech stealer log problem is growing faster than the region around it, and what is being stolen looks different from the EMEA norm. Over the past 18 months, 14,567 stealer logs containing fintech credentials from UK devices appeared on underground forums. Monthly volumes have jumped 48% between 2025 and the first five months of 2026, eight times the 6% rise seen across EMEA as a whole (It’s worth noting that the 2026 figure covers only five months, so this isn’t a full-year comparison). More striking still: traditional established bank credentials appear on more than three-quarters of compromised UK devices, a rate four times higher than the EMEA average. Where most of the region’s exposure concentrates in specialist fintech platforms, the UK’s profile reveals a population whose compromised machines routinely contain the keys to high-street banking.The UK’s monthly fintech log volume broadly mirrors the wider EMEA trend, but at a much lower scale and with a flatter profile, showing less month-to-month variation than the overall figures shown by the green dotted line.
The blue line, representing the UK’s monthly volume, shows an upward trend beginning in April 2025, a sharp peak in January 2026, and a steadying at around 1,800 logs per month through 2026. The timing sets the UK apart from the broader region: while the EMEA line (green, dotted) declines from January 2025 through August 2025 before turning upward, the UK’s climb starts four months earlier, in April 2025.

Banking and Fintech Services Compromised
The UK stands out in the mix of fintech and banking credential categories found in its logs. The UK’s monthly fintech log volume broadly mirrors the wider EMEA trend but at a lower scale and with a flatter profile, showing less month-to-month variation than the regional aggregate (green dotted line). Where the broader EMEA dataset was dominated by fintech specialist platform credentials alone, the UK’s logs are defined by two categories rather than one: fintech specialist platforms and traditional established banks.

Fintech Specialist Platforms: 11,666 Logs (80.1% of Devices)
Fintech specialist platform credentials appeared in roughly eight of every 10 UK compromised devices (11,666 logs, 80.1%), and traditional established bank credentials in about seven of 10 (11,154 logs, 76.6%). The specialist share sits slightly above its EMEA equivalent (70.9%), but the traditional-bank figure is the real outlier, far outpacing the 18.3% seen across EMEA.
Top fintech specialist platforms in UK logs:

Traditional and Established Banks: 11,154 Logs (76.6% of Devices)
This is where the UK diverges most sharply from the regional profile. Traditional bank credentials appeared on about seven in 10 UK compromised devices, compared to just 18.3% across EMEA. This four-fold difference is the UK’s most distinctive characteristic in the dataset.
Top traditional established banks in UK logs:

Digital Challenger Banks: 5,044 Logs (35.2% of Devices)
Digital challenger banks mark a further point of difference, present in 35.2% of UK logs versus 10.5% across EMEA. Taken together, these patterns may point to broader adoption of digital challenger banks in the UK than in the rest of the region, alongside a notably heavier presence of traditional established bank credentials than the EMEA average.
Top digital challenger banks in UK logs:

Banking Infrastructure (B2B): 53 Logs (0.4% of Devices)
Banking infrastructure (B2B) credentials were rare, found on just 53 UK devices, 0.4% of the UK’s fintech logs. Small as that slice is, it’s notable that these are credentials to core banking platforms, with 48 of them tied to FIS Global.
Note: a single device can contain credentials for multiple providers, so category figures overlap and do not sum to the country total.
Client vs. Employee Exposure
Of the 14,567 UK fintech logs collected over the past 18 months, 126 contained both a fintech platform credential and a corporate email belonging to that same company. The presence of a corporate email alongside platform access on a single infected device strongly suggests the machine was used for work, meaning the compromised individual is most likely an employee rather than a customer. This exposure carries a fundamentally different risk profile: a single compromised employee credential can hand a threat actor a foothold into internal systems, privileged tooling, or administrative dashboards, far beyond what any single customer account could offer.
Top five domains from employee exposure logs:

Exposure is spread widely rather than concentrated in any single institution. Deutsche Bank leads with 27 of 126 devices (about 21%), followed by FIS Global (20) and HSBC (19), with a long tail of institutions accounting for the remainder. The traditional-bank tier as a whole is the largest source of exposure, spanning seven institutions, which mirrors the unusually heavy traditional-banking presence seen previously in this report.
Geolocation Context
Geolocation reflects where the infected device sat, not where the company is headquartered. Foreign-headquartered firms such as Deutsche Bank (Germany), Nubank (Brazil), N26 (Germany), BNP Paribas (France), Santander (Spain), Mollie (Netherlands), Worldline (France), and Flutterwave (Africa) all surface on UK-located devices, most plausibly representing UK-based staff of these companies’ London offices, remote workers, or employees passing through the region.
The Banking Infrastructure Concentration
The most consequential finding sits in the banking infrastructure tier. FIS Global (20 devices) and Temenos (two devices) compromised credentials. FIS Global alone is the second-largest exposure in the entire UK employee exposure dataset. Given the disproportionate blast radius of a supply-chain compromise at this layer, this concentration is the UK’s most significant employee-exposure finding.
What Employee Exposure Means
Taken together, employee exposure is a small slice of the UK’s fintech logs but a qualitatively distinct one, weighted toward large global institutions and, critically, toward the banking-infrastructure providers that underpin the wider sector. Where the customer-credential findings elsewhere in this report speak to consumer fraud risk, these 126 devices point to a supply-chain and insider-access risk: infected staff endpoints that could serve as initial-access vectors into the institutions, and the platforms, at the core of UK finance.
Regulatory Context: Why This Data Matters Under DORA and NIS2
For EMEA financial institutions, stealer log exposure is both a security and regulatory concern. The Digital Operational Resilience Act (DORA), now in force across the EU, places specific obligations on banks, insurers, and financial entities that map directly to the findings in this report:
- DORA Article 8 (Identification) requires financial entities to assess cyber threats and ICT vulnerabilities relevant to their business functions. Stealer logs containing your organization’s credentials are precisely those threats. Flare’s External Threat Monitoring, Identity Intelligence, and Dark Web Monitoring capabilities directly address this requirement.
- DORA Article 13 (Learning and Evolving) requires continuous gathering of information and intelligence regarding vulnerabilities and cyber threats. The monthly flow of fintech credential logs (averaging 14,150 per month in EMEA in 2026) is a threat stream that regulated entities are now obligated to track.
- DORA Article 17(3) (Early Warning Indicators) requires entities to put early warning indicators in place within their incident management processes. A stealer log containing employee credentials is an early warning indicator: it surfaces before account takeover occurs, giving defenders a window to act. Flare’s alerting and reporting capabilities enable this integration.
- DORA Article 3 (Third-Party Due Diligence) requires risk assessments of subcontractors supporting critical functions. The 728 banking infrastructure logs (Thought Machine, Temenos, Finastra, FIS Global) make this obligation tangible. If your institution runs on a core banking platform whose engineers’ credentials are circulating underground, that is a third-party ICT risk DORA requires you to understand.
Under NIS2, the picture is similar. Article 22 (Supply Chain Security) requires entities to address cybersecurity risks across their service providers, and Article 23 (Reporting Obligations) mandates 24-hour incident reporting for significant events. Identifying compromised credentials before they are exploited converts what would be a reportable incident into a proactive remediation.
Flare’s identity-first threat intelligence platform enables financial institutions to monitor for exactly the exposure documented in this report: compromised credentials on underground forums, identity intelligence for employee and third-party exposure, and automated alerting that supports the early-warning and continuous-intelligence obligations DORA now demands.
How Fintech Security Teams Can Respond
Fintech credential logs are not a niche concern. Over the past 18 months, nearly a quarter of a million EMEA devices carrying fintech credentials have surfaced on underground platforms, with monthly volumes climbing 6% into 2026 and no sign of slowing down.
At this scale, the exposure represents a systemic threat to consumer finances, payment infrastructure, and the operational integrity of the institutions that underpin the region’s financial system.
The scale alone warrants attention, but the real concern lies in what sits inside these logs. The dataset captures every layer of the financial stack in a single sweep: the banks where salaries land, the fintechs that move money across borders, the payment rails that process merchant transactions, and the core infrastructure that keeps it all running.
Not all credentials are equal. The 728 banking infrastructure logs may barely register as a percentage, yet each one potentially hands a threat actor the keys to the systems that run banks. The blast radius of a single compromised infrastructure credential dwarfs anything a consumer log could deliver. Financial institutions across EMEA should not mistake low volume for low risk.
Financial services organizations across EMEA would benefit from treating stealer log exposure not as a cybercrime statistic but as an operational risk indicator. The credentials are already out there. The question is whether they are found by defenders first.
Identity Intelligence for Financial Services
Find Your Organization’s Compromised Credentials Before Threat Actors Use Them
231,000 EMEA devices with fintech credentials surfaced on underground forums in the past 18 months — and monthly volumes are climbing. Flare continuously monitors stealer log marketplaces to detect when your employees’ or customers’ banking and fintech credentials appear, giving your team the window to remediate before account takeover occurs.
Methodology
Traditional / Established Banks (10) Standard Chartered, HSBC, Nationwide, Santander, NatWest, BNP Paribas, Deutsche Bank, ING, Société Générale, Emirates NBD
Digital / Challenger Banks (14) Monzo, Revolut, Atom Bank, Zopa, Zempler Bank, Kroo, Starling Bank, N26, bunq, Nubank, Chime, Wio Bank, Zand Bank, TymeBank
Fintech / Specialist Platforms (17) Wise, GoCardless, Zilch, Stripe, Adyen, Klarna, Checkout.com, Worldline, Mollie, SumUp, Flutterwave, Paystack, Plaid, TrueLayer, Tink, Yapily, Marqeta
Banking Infrastructure / B2B (12) Thought Machine, Temenos, Finastra, Mambu, 10x Banking, Backbase, FIS, Solaris, ClearBank, Form3, Modulr, Banking Circle





