Kaspersky Uncovers Netflix, Roblox, and Discord Accounts Registered with Corporate Emails in Dark Web Leaks

A new investigation by Kaspersky Digital Footprint Intelligence has revealed that thousands of compromised accounts from popular platforms such as Netflix, Roblox, and Discord were registered using corporate email addresses—a practice that could put organizations at serious risk of security breaches.
Analyzing data from leaked credentials on the dark web between 2019 and 2024, Kaspersky found that, on average, 7% of exposed users had signed up for these entertainment services using their work emails. The findings raise concerns over growing threats linked to infostealer malware and highlight the need for stricter corporate cybersecurity policies.
> “Using your work email for personal services is risky,” warned Sergey Shcherbel, expert at Kaspersky Digital Footprint Intelligence. “You could lose access to these accounts when changing jobs, and more importantly, if your email credentials are leaked and your passwords follow predictable patterns, cybercriminals could compromise both your personal and corporate accounts.”
The study further found that employees in the banking sector were among the most likely to register corporate emails on platforms including streaming services, online marketplaces, and social networks. In some cases, corporate emails were even used to sign up for gaming platforms and adult content websites, significantly expanding the attack surface for potential breaches.
To conduct the analysis, Kaspersky examined leaked credentials tied to 50 companies in the financial sector, categorizing them across five types of online platforms. The results reflect a worrying trend in cyber hygiene, where personal and professional digital boundaries are increasingly blurred.
In response to the growing prevalence of credential leaks, Kaspersky launched a dedicated awareness campaign, offering actionable recommendations to reduce exposure risks. Key steps include:
Immediately changing passwords for compromised accounts and monitoring for unusual activity.
Performing full malware scans on all potentially affected devices.
Proactively monitoring dark web markets to detect corporate account leaks early.
Enforcing security awareness training and a strict password policy within organizations.
Kaspersky’s Digital Footprint Intelligence service enables businesses to assess their exposure on the dark web and identify potential attack vectors before they’re exploited