Online identity auction selling credit cards for half a dollar

happygeek 1 Tallied Votes 696 Views Share

Internet security giant Symantec has just published the latest , based on an in-depth analysis of global Internet traffic and email during the last six months. Beyond all the usual who is hosting what and where, how much malware is contained in spam and which threats are continuing to cause problems data, there is one truly shocking statistic buried within the 134 page document: stolen information is dirt cheap on the black web economy.

The report suggests that cyber crime has become a professional, even a corporate, business. Organized crime units across the world are rolling out targeted, sophisticated and above all else hugely profitable online attacks. But they are also showing real business-savvy by creating the tools and the opportunity for wanabees to get involved who possess little in the way of criminal hacking, coding or scamming skill. They are establishing what can only be described as a criminal and fraudsters pyramid scheme.

If you want to enter the world of the cyber crime lord then you can start at the bottom by investing in an out-of-the-box toolkit, just $50 for a ready made phishing kit that is easy to install and professionally coded to enable the newbie to get out there and get defrauding the online public. These packages even come with built-in support for everything from fake website creation to email targeting. A Symantec investigation into the three most widely used phishing toolkits reveals that they alone were responsible for 42 per cent of all phishing attacks detected in the first half of 2007.

Or how about an online identity auction, black web economy servers where consumers' identities can be bought and sold? These auctions sell all kinds of personal data from social security numbers to credit cards. During the first six months of 2007, the United States accounted for hosting 64 percent of the total of such auctions known to Symantec, followed by Germany and Sweden. Credit cards are the most frequently traded item, not surprising when sold in batches of 10 for as little as fifty cents a card!

When it comes to stolen data, identities and assorted criminal goods it might surprise you juts how cheaply they can be purchased at these auction servers. Here are the top ten most traded items according to the report, which I have sorted by price rather than volume to help make the point:

  1. Credit Cards $0.50
  2. Proxies $0.50
  3. Email Passwords $1
  4. Compromised Unix Shells $2
  5. Email Addresses $2 per Mb
  6. Social Security Numbers $5
  7. Mailers $8
  8. Full Identity $10
  9. Scams $10 per week
  10. Bank Accounts $30

Commenting on the Internet Security Threat Report, Lee Sharrocks, Consumer Sales Director, Symantec UK told DaniWeb "the Internet underworld is growing at an alarming rate, with the latest trends showing that the growth of black market auction sites is continuing to increase. It's a multi-billion dollar criminal industry and identities are becoming cheaper and easier to buy online. With the introduction of software toolkits to provide access to the technology needed to become involved in these identity scams, we can only expect this trend to continue to grow, so the need for consumer vigilance is higher than ever."

Dani AI

Generated

As observed, a mature underground economy for stolen identities has lowered the bar for fraud: ready-made tools and resale markets turn breaches into cash flows and make credential/card reuse a systemic risk. Modern breach studies show credential theft and resale remain primary enablers of larger intrusions. (verizon.com)

Practical, immediate actions for exposed accounts include: check breach indexes such as Have I Been Pwned and register for breach notifications; rotate any passwords that appear in breach lists and adopt a password manager to avoid reuse; enable multi‑factor authentication (prefer phishing‑resistant methods where possible); monitor recent card and bank transactions and notify issuers of suspicious activity; and, if identity misuse is suspected, place fraud alerts or a credit freeze and file a recovery report at the federal identity‑theft resource. (troyhunt.com)

For home users and small organizations: keep operating systems and apps patched, run reputable endpoint protection, limit storage of full payment data, and use tokenization or virtual card numbers where supported. Implement least‑privilege access, basic network segmentation and centralized logging so compromises can be detected and contained quickly. Payment security and cardholder‑data controls remain governed by industry standards and best practice frameworks that should guide technical controls. (pcisecuritystandards.org)

For learners and people new to security (for example, ), useful starting points are the OWASP Top Ten for web risks and an entry certification like CompTIA Security+ for a structured foundation in defensive concepts, plus hands‑on labs and phishing‑awareness practice. Those resources map well to the defensive steps listed above. (owasptopten.org)

Short, practical vigilance combined with basic technical hygiene — patching, MFA, unique passwords, and prompt reporting — materially reduces the chance of being exploited by these low‑cost, high‑volume criminal marketplaces. (verizon.com)

paulanderson154 0 Newbie Poster

This a Paul; I want collect knowledge about computer like programming, software, hardware and other like computer related course. There are programs and software that are available for download and purchase that combine years of computer repair courses.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.