Skip to main content
Back to overview
High

SurveyMonkey Experiences Significant Credential Exposure Affecting Nearly One Million Clients and Over 8,000 Employees

SurveyMonkey, a U.S.-based software company providing online survey and feedback tools, has been identified in a significant credential exposure event with a high-risk score.

Key points

  • Nearly one million clients and over 8,000 employees affected by credential exposure.
  • 853,111 historical data breaches and 124,422 active infostealer logs identified.
  • Primary exposure vector: Combolist sources (99.6%) and Database dumps (0.4%).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Malware · Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Jul 26, 2026
Updated
Jul 28, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential extortion or operational risk
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

SurveymonkeyData DisclosureSurveyMonkey Experiences Significant Credential ExposureAffecting Nearly One Million ClientsOverEmployees SurveyMonkeyU.S.-basedCombolistMalwareRedline

Quick context

Questions about this signal

What happened in this signal?

SurveyMonkey, a U.S.-based software company providing online survey and feedback tools, has been identified in a significant credential exposure event with a high-risk score. The incident involves 853,111 historical data breaches and 124,422 active infostealer logs, impacting approximately 969,240 clients and 8,293 employees. The exposure is primarily linked to "Combolist sources" (99.6%) and "Database dumps" (0.4%) within leak repositories, indicating that compromised credentials are the main vector. Malware families such as Redline, LummaC2, and Rhadamanthys are prevalent, suggesting active credential harvesting and data exfiltration. The infostealer malware primarily targets Windows 10 and Windows 11 operating systems, with a notable presence in India, Brazil, and the United States. This event highlights the urgent need for credential resets and enhanced monitoring for unusual access patterns. SurveyMonkey's security statement, updated in November 2025, outlines its commitment to data protection, including AES 256 encryption for data at rest and RSA encryption for data in motion, as well as ISO 27001 certification and a vulnerability management program. However, the current exposure indicates a persistent threat despite these measures. The company's privacy notice, effective May 2026, details the types of personal data collected and how it is shared, emphasizing that data is not shared with third parties outside SurveyMonkey except in limited circumstances, such as with administrators in enterprise plans or in response to legal requests. The notice also mentions the use of event data to investigate security issues and prevent unlawful activities. The incident underscores the ongoing challenges organizations face in protecting against sophisticated credential-stealing malware and the importance of robust authentication mechanisms and user education.

When was this signal reported?

Shadow Tier lists Jul 26, 2026 as the signal date.

Which organization is connected to this signal?

Surveymonkey is the organization connected to this public signal.

Explore Surveymonkey
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence