What’s Your Personal Data Worth On The Dark Web?

It's an inevitability of the modern world that your personal information is going to be compromised at some point and you'll have to go through the hassle of changing your password or account number or signing up for credit monitoring.

For victims it's a headache, but it generally doesn't extend beyond that. For the cybercriminals, though, it can be a wildly lucrative venture.

But how do hackers sell your stolen data, and who is willing to buy it? Thomas Holt, an associate professor of criminal justice at Michigan State University, recently conducted a study with some colleagues examining the strategies used by individuals operating in the real world for stolen goods in virtual illicit markets that are hidden from the public, specifically, the dark web. This clandestine marketplace is a heavily encrypted underground world within the internet, and it is difficult for authorities to detect the location or owners of the data markets within the dark web.

Funded by the National Institute of Justice, Office of Justice Programs and US Department of Justice, Holt and his colleagues analyzed posts from 10 Russian- and three English-language web forums selling stolen data to engage in identity theft and fraud.

The study found that most of the sellers on the dark web advertise their data and services in forums much like an Amazon or eBay, where buyers and sellers rate each other and the quality of their products being sold, in this case, personal information. While it sounds lawless, there's an honor amongst data thieves. Buyers of stolen data pay first and trust it will be delivered.

Holt claims it is hard to put an exact figure on what hackers are getting for stolen data, for several reasons: Cash transactions tend to be on the rare side in these sorts of transactions, bulk discounts take place for big data scores, and precise negotiations take place via email or private online chat. Yet it appears bitcoin and other web-based currencies are the norm, because the sources are much harder to trace.

What Holt and his colleagues found was that of the 320 transactions they studied, data sellers earned between $1 million and $2 million. Similarly, buyers in 141 of these transactions earned between $1.7 million and $3.4 million through the use of the information they purchased.

How much is your data worth?

So how much is your data worth? It varies, sometimes tremendously, on where it's being sold. To get the broadest possible look at what hackers are buying and selling these days, CNBC.com reached out to several security experts. The prices stolen data is commanding ran the gamut.

According to Michal Salat, threat intelligence manager at Avast Software, an IT security company that develops antivirus software, data is not worth that much individually. Avast focuses on commonly stolen personal data, such as Social Security and credit card numbers.

"The price increase [per account/credit card number] usually isn't linear," says Salat. "A lot of sellers have discounts for higher credentials counts and for regular customers."

Here is what Avast claims data sellers are fetching for the following:

  • Credit cards without a balance guarantee: $8 per card (number and CVV)
  • $2,000 balance guarantee: $20 per card (number and CVV)
  • Driver's license scans: $20
  • Email addresses and passwords: $0.70–$2.30
  • Social Security numbers: $1 ($1.25 for state selection)
  • PayPal credentials/access: $1.50

Beyond the financial data

Yet some thieves are interested in more than just financial data. Some are looking for access to something as mundane as entertainment services or as significant as logins to national services (via FTP or SFTP — file-transfer protocols that allow users to transfer files between computers).

The high prices for .GOV accounts might seem surprising, but Ed Cabrera, chief cybersecurity officer at Trend Micro, says the access they provide commands top dollar.

"These stolen credentials enable criminals to compromise servers to steal data or otherwise launch secondary attacks," he says. "The criminal underground operates on supply and demand so the same market forces we see on surface web you can see in the deep web."

Here are what security software company Trend Micro claims this type of data is commanding today:

  • Credit card credentials: $15-$22
  • Spotify account: $2.75
  • Hulu account: $2.75
  • Netflix account: $1–$3
  • NOAA.gov account (FTP or SFTP access): $476
  • USPS.gov account (FTP or SFTP access): $680
  • CDC.gov account (FTP or SFTP access): $340
  • Western Union account: $6.80

CNBChttp://cnb.cx/2aRwXZS

« Risky Business: Desktop Banking Declines As Users Switch To Apps
Too Much Information: Making Sense Of Big Data »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

SmartSearch

SmartSearch

SmartSearch is a leading online provider of Anti-Money Laundering and Fraud Prevention Services.

IT Security Guru

IT Security Guru

IT Security Gurus publish daily breaking news. interviews with the key thinkers in IT security, videos and the top 10 stories as picked by our Editor.

Zimperium

Zimperium

Zimperium offers enterprise class protection for mobile devices against the next generation of advanced mobile attacks.

Massive Alliance

Massive Alliance

Massive is a global service agency providing internet monitoring, data & security threat surveillance and reputation management.

VADO Security Technologies

VADO Security Technologies

VADO Security enables the safe transfer of data between low & high security networks.

British Blockchain Association (BBA)

British Blockchain Association (BBA)

British Blockchain Association (BBA) is a not-for-profit organisation that promotes evidence-based adoption of Blockchain and Distributed Ledger Technologies (DLT) across the public and private sector

astarios

astarios

astarios provide near-shore software development services including secure software development (DevSecOps), quality assurance and testing.

Syber Technology

Syber Technology

Syber Technology is an IT project implementer empowering IT systems of Small to Medium Enterprises in the Middle East.

Center for Infrastructure Assurance and Security (CIAS)

Center for Infrastructure Assurance and Security (CIAS)

CIAS is developing the world's foremost center for multidisciplinary education and development of operational capabilities in the areas of infrastructure assurance and security.

Digital Beachhead

Digital Beachhead

Digital Beachhead has the expertise to provide a range of Cyber Risk Management and other Professional Services with specifically tailored solutions at competitive prices.

TWC IT Solutions

TWC IT Solutions

Since 2011, TWC IT Solutions has offered managed IT Support, Cybersecurity, Disaster Recovery, Contact Centre and Business Connectivity services to clients across 24 countries globally.

Extreme Networks

Extreme Networks

Since 1996, Extreme has been pushing the boundaries of networking technology, driven by a vision of making it simpler and faster as well as more agile and secure.

Snare

Snare

Snare is a comprehensive set of event monitoring and analysis tools designed to address critical auditing and security requirements.

Actelis Networks

Actelis Networks

Actelis Networks is a market leader in cyber-hardened, rapid deployment networking solutions for wide-area IoT applications.

StepSecurity

StepSecurity

StepSecurity provides a comprehensive security platform for GitHub Actions.

Redinent Innovations

Redinent Innovations

Redinent is a cutting-edge IoT Security platform that offers precise security posture analysis and delivers actionable intelligence, empowering businesses to operate with unrivaled resilience.