The Digital Shadows Photon Research team spent 18 months scavenging the dark web and underground forums to analyze how cybercriminals steal your credentials and take over your account. They found that password theft has increased by 300% since 2018, caused by 100,000 data breaches. The reason behind this significant leap is the fact that many consumers use weak passwords, which can be obtained with a brute force attack.
Most of the stolen login credentials are shared several times, which means that victims aren’t even aware of any hack that may have taken place. However, around five billion unique logins are up for sale on the dark web, the report found. As for most of the duplicates, cybercriminals were giving them away for free.
Prices for commercially traded logins varied depending on the account’s importance. Streaming services, VPNs, and social media platforms all cost under $10. Antivirus program logins had a higher average fee of $21.67 but were still below the legitimate subscription price. Online banking and financial accounts, meanwhile, cost $70.91 on average. These credentials were more expensive because the buyer has access to the victim’s bank account, which could contain thousands of dollars. In fact, the research team reported that some banking logins were sold for $500.
But the most valuable usernames and passwords pertained to network administrators, which give hackers access to company grids. Researchers found that the stolen data was auctioned off to cybercriminals, reaching $120,000 in some cases. The average cost, though, was $3,139. But even if attackers pay a sum of six figures for these credentials, they could still make a lot of money. For example, they can install ransomware on the network, encrypt files, and demand millions of dollars in exchange for the data.
Stolen Credentials Affordable
When you take into consideration the possible rewards for hackers, these prices don’t seem too steep. You see, it’s not that difficult for attackers to break and steal user passwords. People often use the same password for multiple accounts, and the passcode is weak and predictable most of the time. Even beginner hackers can obtain them with brute force attacks, which they could launch using tools that coast as little as $4 on the dark web.
Therefore, Digital Shadows threat research team lead Alex Guirakhoo recommends individuals and businesses to create unique and strong passwords for each account. A password generator and manager could help produce and safely store passcodes so that users don’t forget them. And for another layer of protection, people could also enable two-factor authentication. That way, hackers would still need a pin code to access your account. “If you suspect your account has been compromised, you should immediately change your passwords,” says Guirakhoo.
There are several online resources that offer such services, like TheVPN.Guru, which also contains VPN reviews and how-to guides.