Every December, the same pattern shows up in the data we monitor: the volume of freshly harvested credentials climbs through the holiday period, and the criminals using them get faster. It isn't a coincidence, and it isn't luck. The holidays stack the deck against defenders in four specific ways - and each one has a concrete counter you can put in place before you set your out-of-office.
Why the Holidays Favour the Attacker
1. Infections Spike Because Downloads Spike
Infostealer malware spreads through cracked software, game cheats, fake installers and poisoned search ads. School holidays plus new devices plus gift-shopping searches equals a seasonal surge in exactly the downloads that carry stealers. Much of this happens on personal machines - the family laptop, the teenager's gaming PC - but those are the same browsers where staff keep work passwords saved. The infection happens at home; the corporate credential still ends up in the log.
2. Phishing Lures Write Themselves
"Your parcel could not be delivered." "Issue with your order." "E-card from a colleague." December is the one month when everyone genuinely is expecting parcels and greetings, so the click-through rate on delivery-themed phishing jumps. The UK's Cyber Security Breaches Survey consistently finds phishing involved in the vast majority of identified attacks - the holidays simply sharpen the hook.
3. Credential Stuffing Meets Peak Retail
If you run customer accounts, the festive trading period is when stolen password lists get replayed against your login page hardest - gift-card balances, stored payment methods and loyalty points are at their most valuable, and fraud teams are at their most stretched. (We wrote more about the retail side in our January sales fraud post.)
4. Your Response Window Collapses
Independent lifecycle research puts the gap between an infection and the stolen credentials being on sale at 48 hours or less. That window is survivable in a normal working week. Over a bank-holiday stretch with a skeleton crew, a credential can be harvested, sold, and used before anyone reads the alert. The attacker's tempo doesn't slow down for Christmas; your team's does.
The Pre-Break Checklist
A practical list, in the order we'd do it:
- Check your existing exposure before you leave. Rotating a stolen credential on 20 December is easy; discovering it was used on 27 December is not. A free trial will show you within minutes whether your domain already appears in stealer logs or breach dumps.
- Close out leavers and dormant accounts. Year-end is peak staff turnover. An enabled account nobody is watching is the perfect holiday guest.
- Revoke stale sessions and tighten session lifetimes. Stolen session cookies bypass MFA entirely; the shorter a token lives, the less resale value it has.
- Brief staff on the two seasonal lures - delivery notifications and e-cards - and remind them that "free" software downloads on the family PC are how work passwords get stolen. One paragraph in the last all-hands email is enough.
- Decide the escalation path now. Who gets the alert on 28 December, and what are they authorised to do - force a reset? Kill sessions? Write it down before people disperse.
- Reconsider what your out-of-office reveals. "I'm away until 5 January, contact our finance team at…" is a social-engineering gift. Keep it vague, keep it internal where possible.
Making the Quiet Weeks Work for You
The counter to a shrinking response window is automation that doesn't take leave. This is the season our own stack earns its keep, and we run everything we sell:
- Stolen Data Monitoring watches stealer logs, marketplaces and breach corpora for your domains continuously - the alert fires at 3am on Boxing Day if that's when your credentials surface, with the context (infected machine, exposed applications, whether cookies were taken) to act on it quickly.
- Our Credential Check APIs block known-compromised passwords at login time using k-anonymity, which blunts seasonal credential stuffing without adding friction for legitimate customers mid-sale.
- Lens handles the human follow-up privately: the affected employee sees their own exposure and fixes it themselves, without anyone having to convene a meeting between Christmas and New Year - and without their employer reading their personal accounts.
Every DarkStrata employee is enrolled in Lens, and our own domains are monitored by our own platform. Security companies get their credentials stolen too; the difference we're selling is finding out in hours rather than months.
Before You Log Off
None of the list above takes more than an afternoon, and most of it takes minutes. The holiday threat isn't a special class of attack - it's the ordinary credential-theft machine running at full speed while your defence runs at half. Close the gap with automation and a little preparation, then take the break properly.
From everyone at DarkStrata: enjoy it. We'll keep watching the logs.