After a web breach, billions of credentials are discovered in the wild. What happens to them? How are they being misused for profit and how is the actual reuse accomplished? This talk will discuss how it is done, what tools are out there and the monetization currently being seen in the wild.