Comparitech researchers gathered listings for stolen credit cards, PayPal accounts, and other illicit goods and services on 13 dark web marketplaces. For legal reasons, we will not publicly disclose which marketplaces were used. Information in the listings was entered into a spreadsheet for data analysis and statistical calculations. We reviewed all darknet markets that were active in February-March 2023 that featured fraud-related listings. This meant we excluded bank accounts, credit cards and software cracks for example.
In the past few months, VMware Carbon Black researchers have seen POS malware variants in use across a wide variety of retailers. These attacks rely on the actual physical swipes of cards, which then allow the malware to exfiltrate credit card data along with verification data such as a PIN numbers or zip codes. Most of use just have the standard personal account, but Premier and Business accounts also exist, and are up for sale on the dark web. But those tiers don’t have much influence on dark web prices, which are largely governed by account balance.
History Of Dark Web Marketplaces
- Comparitech researchers gathered listings for stolen credit cards, PayPal accounts, and other illicit goods and services on 13 dark web marketplaces.
- A fair number of vendors include access to a SOCKS5 internet proxy that can be used by the buyer to match their computer’s IP address location with that of the cardholder in order to avoid being blacklisted.
- Almost 30% of all stolen log-ins for sale on Russian markets were for NordVPN and Windscribe.
- When a hacker writes up new malware, steals a database, or phishes someone for their credit card number, the next step is often toward dark net marketplaces.
- Four platforms were focused on access to books and book summaries, while three were language learning platforms.
Hulu was more popular than average on this darknet market, with more of its accounts for sale than any other streaming service. Streaming and VPN services dominated the listings of hacked accounts for sale on the darknet markets, together accounting for 57% of all log-ins available for purchase. The recent real-world proliferation of streaming services was clearly reflected on the darknet markets, with stolen credentials for 150 different services identified. In conducting this research, we have assembled the world’s largest dataset of darknet market listings for hacked account details.

Personal Documents At The Top

Sellers often need to pay a deposit to prove they’re serious, and they build their reputation through positive reviews. Today’s cybercriminals spread their activities across multiple platforms, making them harder to track and shut down. Despite growing crackdowns from law enforcement agencies, the dark web remains a hotbed of criminal activity, offering everything from drugs to stolen data. Where listings offered a selection of accounts at specific prices, each account was treated as an individual listing.
Dark Web Price Index 2023

Skeptics argue the resemblance between the alleged PayPal dataset and the structure of infostealer malware logs from an older event suggests foul play. Your account must be older than 4 days, and have more than 20 post and 10 comment karma to contribute. A fair number of vendors include access to a SOCKS5 internet proxy that can be used by the buyer to match their computer’s IP address location with that of the cardholder in order to avoid being blacklisted. Therefore, the probability of being hacked is unpredictable but on the rise unless you take measures to protect yourself. Install anti-virus or other anti-malware software on your personal computer to scan for malware.
Forged Documents (Scans)
- This information is then processed to generate an index of average prices for a broad range of specific products.
- The preference in Russian markets for multi-buy offers of streaming accounts meant that Start TV, a niche U.S. service focusing on classic women-led legal dramas, was the second-most listed streaming platform on Kraken.
- They may mean the world to us and cause devestation when fraud takes place, but for traders in the Dark Web, your ID and financial accounts are just assets to sell.
- Security researchers have been monitoring forums within the cybercriminal underworld to investigate the leading markets operating in 2024.
- Furthermore, we have not purchased any of the credentials being sold on the Darknet.
Only brands with more than one listing have been included to reduce the impact of anomalous pricing. Another key difference was the popularity of ISP account details on Russian darknet markets compared to elsewhere. Not only were these credentials found for sale more commonly but they were worth significantly more with an average price of $408 compared with $15 on non-Russian darknet markets. On the Russian darknet markets, VPN account log-ins were the most popular stolen credentials for sale, accounting for almost 40% of all listings.
What Is The Darknet Market Price Index?
When a hacker writes up new malware, steals a database, or phishes someone for their credit card number, the next step is often toward dark net marketplaces. These black markets allow buyers and sellers to make anonymous transactions using a combination of encrypted messages, aliases, and cryptocurrency. A thriving category of illicit goods and services sold on dark web markets is that of scans of personal documents. Hacked social media accounts are evidence that cybercriminals have a diverse appetite for Dark Web data products.
Abacus Market
These accounts were only listed a handful of times each across the 15 darknet markets that we trawled for this study and this scarcity was at least one factor in driving up their prices. In terms of individual brands, NordVPN was by far the most popular with 19% of all listings on Russian darknet markets. By comparison, the most popular brand outside of Russia was PayPal, which accounted for less than 5% of all listings on non-Russian darknet markets.
Streaming was much less concentrated than other categories we analyzed, with the 20 most frequently-listed services accounting for almost 60% of all listings. To educate the public about the value of their personal data to identity thieves. Our hope is that this will lead to improvements in day-to-day information security. The goal of our research was to determine which accounts were most popular with cybercriminals and therefore most at risk of hacking. Freshtools was established in 2019 and offers various stolen credentials, accounts, and host protocols like RDP. It is considered a go-to site for malware purchasing, providing keyloggers, trojans, and other Malware as a Service products.
Infostealers are often installed after users click on a malicious link or attachment that has malware embedded in it, then it works quietly in the background to funnel stolen information back to the attackers. Some infostealers can hide themselves or delete themselves after they’ve taken passwords, browser data or payment information and they’re available to buy or rent on the dark web for any platform. This is reason enough to have the best antivirus software installed on your devices and kept up to date. It’s also important to follow good security practices, have browser features enabled to protect you online and make full use of the extra included in many antivirus suites like a VPN or firewall.
And then there’s malware—click the wrong link or download the wrong file, and your device could get infected. Some dark web marketplaces even host content that’s not just illegal but extremely harmful, so it’s really important to understand the risks before diving in. The first category includes classic marketplaces, which serve as one-stop shops for a wide range of illegal goods.

We ranked the most popular types of account (ie for streaming, VPN, payments etc) listed on the darknet markets. It reveals the extent to which streaming and VPN account details dominate the illicit trade in personal data on the darknet markets. Like every cyberattack, launching credential stuffing attacks has its own challenges.