A Million Credit Cards Dumped on the Dark Web

In a recent routine security sweep of dark web forums, researchers spotted something quite extraordinary. Bad actors have dumped the credentials of around a million credit cards on the internet, and have released the info for free.

The unusual gesture of criminal generosity is not motivated by altruistic motives or done by criminals playing at Robin Hood, but is instead made as a marketing push to promote a new website and service that sells stolen credit card credentials. The criminal platform promoted in the weird marketing push is called All World Cards and is hosted at the domain AllWorld dot Cards.

The free cards dump was spotted by researchers working with security firm Cyble. They found the cards credentials were pilfered sometime between 2018 and 2019, if the forum post about them is to be believed.

The data sets that accompany each card are sufficient to perform fraud and steal money from them, it appears, as the leak contains card number, expiration dates, CVV numbers, holder names and country of residence, including state and city, as well as postal codes, phone and emails.

Stolen credit cards are used very often to purchase gift cards - an item that makes tracking the purchase and connecting it with the entity that made it very difficult.

There is no hard information what percentage of the huge card dump is comprised of cards that have not yet expired, but when we are dealing with such volumes and numbers, it is more or less a given that a good chunk of the cards will still be active, given that the credentials were stolen between two and three years ago.

The bad actors who put up the card dump claimed that just over a quarter of the cards should be active, quoting their own testing of a very limited 100 cards. Of course, believing a cyber criminal who is peddling their wares is never a great idea.

Researchers with Italian D3 Lab conducted their own testing, passing card numbers to respective banks, and discovered that the percentage of cards that are likely still active is much closer to half than a third.

August 11, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.