Joker's Stash Puts $130M Price Tag on Credit Card DatabaseJoker's Stash Puts $130M Price Tag on Credit Card Database
A new analysis advises security teams on what they should know about the underground payment card seller.
November 12, 2019
Payment card data is among the most widely distributed information on the Dark Web. The breadth of data for sale in underground marketplaces can prove helpful to security teams, who can analyze this information and combine it with other threat data to learn their potential exposure and mitigate the impact of an incident, Flashpoint researchers advise in a new report.
The ecosystem for stolen payment card data ranges from low-level markets selling cards recycled from past breaches, to top-tier sellers with unused card data directly pulled from a new breach. Joker's Stash is one of the most prominent payment card retailers on the Dark Web, where it has been selling credit cards from online and physical transactions since 2014. In 2015, it began to also sell personally identifiable information including Social Security numbers.
A recent update on Joker's Stash arrived on Oct. 29, when it added data pertaining to more than 1.3 million credit and debit cards reportedly taken from banking customers in India. The data dump released was one of the largest in Joker's Stash's history, researchers report, with pricing information valued at $100 per card, which put the total for the database at $131 million.
Joker's Stash and similar marketplaces provide value beyond cybercrime, researchers say. Fraud teams can leverage its data to learn what card data is for sale and the timing of its availability on Joker's Stash. This reveals the common point of purchase (CPP) of compromised cards and can help identify the geographical source of a breach and stem its potential impact, they explain.
Read more details here.
Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "What a Security Products Blacklist Means for End Users and Integrators."
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
Get the Gartner Report: SOC Model Guide
Gone Phishing: How to Defend Against Persistent Phishing Attempts Targeting Your Organization
The Evolving Ransomware Threat: What Business Leaders Should Know About Data Leakage