Whether these credentials are old or new, the risks for users are real. This case also highlights regulators’ increasing focus on fintech security. Online payment providers — PayPal, Stripe, Revolut, Wise, and others — operate under strict security and regulatory requirements.
Who Pays The Bill For Online Fraud?
He explains that beyond common attacks like injecting e-skimmers into websites, many attackers still target point of sale (POS) systems directly. Foss explains that there’s no shortage of cyber threats facing retailers and shoppers this holiday season, as the volume and sophistication of cyberattacks surges with more consumers opting to shop online Experts advise enabling multi-factor authentication, changing passwords regularly, and checking for data leaks. In 2025, PayPal agreed to pay $2 million to US regulators for failing to comply with cybersecurity requirements.
(The more expensive option would be transferred from a hacked account.) We process this information to create an index of average prices for a wide variety of specific products. As in our earlier reports, our data collection methods include scanning dark web marketplaces, forums, and websites. Predictably, as supply grew, most prices plummeted. In the past year, the Dark Web data market grew larger in total volume and product variety. Keep reading to discover the latest product prices, trends, and methods used to make the Dark Web operations more efficient and customers more secure.

Email Database Dumps
Get the latest updates on privacy, plus expert tips, and security guides to up your digital protection game. It’s convenient, but safer if combined with 2FA, account alerts, and regular password updates. Yes, but only if you secure your account with a strong password, 2FA, and avoid phishing attempts. Yes, PayPal has experienced breaches where user data was exposed, often due to credential stuffing or phishing.
That’s more than double the average price we recorded about eight months prior in a similar study, though that’s not the whole story. Comparitech researchers sifted through several illicit marketplaces on the dark web to find out how much our private information is worth. Cybersecurity researchers have uncovered a dangerous tool causing a stir on the dark web and within
The Darknet Market Price Index is a series of research reports that track the average sale prices of stolen online account credentials and personal data. Comparitech researchers gathered listings for stolen credit cards, PayPal accounts, and other illicit goods and services on 13 dark web marketplaces. Launched in 2023, STYX focuses on financial crime, providing stolen credit card data, hacked bank accounts and access to various cryptocurrency laundering tools. The following table shows the 20 online shopping brands whose hacked account credentials were most frequently listed for sale on the darknet markets. The following table shows the online payment platforms whose hacked account credentials were most frequently listed for sale on the darknet markets.
Thieves buy cards in order to cash them out or make purchases that can be resold. The average credit limit on the listings we examined was $2,980. Credit cards can be sold as physical or digital items on the dark web. Where possible, we’ll also examine how prices have changed over time. These black markets allow buyers and sellers to make anonymous transactions using a combination of encrypted messages, aliases, and cryptocurrency.

By far the most popular data for sale is credit card information, bank account logins, and payment platform credentials (such as PayPal). These accounts were only listed a handful of times each across the 15 darknet markets that we trawled for this study and this scarcity was at least one factor in driving up their prices. The following table shows the 20 most expensive account credentials we identified for sale on the darknet markets, ordered by average price. Indeed, Russian sites played host to an outsize proportion of hacked VPN account details, with 43% of VPN credentials globally from three of 15 darknet markets.
Banking Login Data

Below are the average prices for data from popular payment processing platforms in 2025. There are also many international credit card details with CVV for sale on the dark web. Here are some of the most shocking statistics about credit card details for sale on the dark web.
The story of dark web marketplaces kicks off with Silk Road, launched in 2011. To protect both parties, many marketplaces use an escrow system, so the money is only released to the seller once the buyer confirms that everything went smoothly. Ransomware and cryptocurrency-based crimes saw a significant increase in 2025, with $2.17 billion stolen from crypto platforms, surpassing the total for all of 2024. In 2019, there were approximately 8,400 active sites on the dark web, selling thousands of products and services daily. Users can browse and purchase various illicit items, making these marketplaces a hub for unlawful activity. These platforms sell everything from drugs and fake IDs to weapons and hacking tools, resembling a digital black-market bazaar.
Topics And Products Sold
Widespread password re-use across multiple accounts means hackers only need one set of login details to run a credential stuffing attack and instantly gain access to many more. A single hacked account can open the door to identity theft, due to password re-use and the wealth of personal details stored within that can be exploited. The markets are often used to buy and sell personal data, along with other contraband including weapons and illicit drugs. The average person has dozens of accounts which form their online identity, all of which can be hacked and sold. The Darknet Market Price Index has been tracking the trade in hacked online accounts since 2018. The process of taking over a PayPal account is somewhat different from stealing credit card data, with the vital information being in the form of usernames and passwords, rather than card and CVV numbers.
Massive Data Breach Sees 16 Million PayPal Accounts Leaked Online – Here's What We Know, And How To Stay Safe
For instance, cybercriminals can buy credit card details with a $5,000 balance for just $110. My question is do these accounts actually let you use the credit balance on them? I see a lot of people selling these accounts that come with $2,000 to $10,000 in available credit balance. But if an attacker has access to an unencrypted network that you’re using, it’s easy to view your account data and steal or alter your information. These are the highest-priced items on the Dark Web markets by far. They can be used for SIM swap attacks and personal data access requests in California and the European Union.
Why People Use Dark Web Marketplaces
Believe it or not, some dark web marketplaces have pretty advanced systems for building trust. Some fake sellers take your crypto and never ship what you ordered, or phishing sites that look like real marketplaces but steal your login info. One of the most common is the exit scam, where a marketplace suddenly disappears and takes everyone’s money with it. Some dark web marketplaces even host content that’s not just illegal but extremely harmful, so it’s really important to understand the risks before diving in.
Cyble Titan Endpoint Security

Here is a listing related to stolen PayPal accounts. In December 2022, an estimated 7.5 million credit cards were made available on the Dark Web. 2022 and early 2023 saw the seizure of many major darknet markets by law enforcement.
- One of the most common is the exit scam, where a marketplace suddenly disappears and takes everyone’s money with it.
- Haveibeenpwned.com should be your first port of call, as it’ll help you find out which of your email accounts and old passwords have been compromised in a data breach.
- As in the previous 3 years, we conducted research into the supply and prices of various goods and services sold by cybercriminals on the dark web.
- A PayPal subsidiary suffered a significant data breach affecting approximately 1.6 million customers.
- 2022 and early 2023 saw the seizure of many major darknet markets by law enforcement.
This includes sensitive data like email addresses, usernames, bank account details, social security numbers, and more. If sensitive information like your Social Security number or bank account details was exposed, it’s important to monitor your credit reports and bank accounts for any unusual activity. This can lead to fraudulent activities, including unauthorized transactions, new account creation in the victim’s name, and application for loans or credit cards. As a result of these data breaches, PayPal users faced a range of serious threats that compromised their personal, financial, and online security. PayPal experienced a data breach involving unauthorized access to user accounts through credential stuffing attacks.
There is also a growing market for fake documents, such as IDs, and passports. This causes websites to crash or gamers to be booted out of live-action online games. However, this is because it is the most profitable; ransomware attacks can earn cybercriminals millions of dollars, which is why this part of the dark web market is highly lucrative. As you can see, malware is some of the most expensive data on the dark web.
Malware for sale is divided into categories, depending on its likelihood of successfully infecting systems. Possibly one of the most dangerous products for sale on the dark web is malware. PayPal isn’t the only platform with user details being sold on the dark web. Unfortunately, this is happening more frequently as banking login data is being sold on the dark web. Malware and DDoS attack sales have also increased, with cybercriminals purchasing these to launch attacks on systems or carry out ransomware attacks. We’ve reported on many recent security attacks such as the FlexBooker, Volkswagen, and Gigabyte breaches, as well as supply chain attacks like the SolarWinds breach.
WeTheNorth is a Canadian market established in 2021 that also serves international users. It maintains a very strict level of user verification and integration with an official Telegram account to provide real-time updates to users. The Abacus Market links to the new dark web marketplace sections and took over much of the vacuum left by the AlphaBay takedown. Stick to cryptocurrency, avoid downloading anything, and don’t share any personal info.