shufti_logoshufti_logo
  • Products

  • Solutions

  • Explore

  • Company

  • Pricing
burger-menu burger-menu-close

us

216.73.216.187

15 Billion Stolen Logins From 100,000 Breaches – Reveals New Dark Web Audit

15 billion stolen

15 billion – a figure published demonstrates the stolen logins came about through the 18 months of Digital Shadow’s Security researchers. They audited the criminal’s marketplace over the dark web and found that the stolen credentials have increased 300% since the audit done previously in 2017. The audit reveals 15 billion stolen credentials from 100,000 breaches. 

Among those 15 billion records, about 5 billion are unique. These records estimate an average of $15.43 as an individual record selling. These data breaches highlight most of the compromised data belongs to banks and financial accounts which accumulate an average of $70.91 per piece. Also, about 25% of all dark web advertisements offer such records as they carry more valuable data.

In the audit, researchers have also found that the stolen credentials are provided as a service. Now instead of buying the credentials, criminals rent the identity for a particular time period for less than $10. 

The chief information security officer, Rick Holland, said in a statement,

“The sheer number of credentials available is staggering and in just over the past 1.5 years, we’ve identified and alerted our customers to some 27 million credentials – which could directly affect them,”  Also, he said, “Some of these exposed accounts can have (or have access to) incredibly sensitive information. Details exposed from one breach could be re-used to compromise accounts used elsewhere.”

He added by giving a simple message: “Consumers should use different passwords for every account and organizations should stay ahead of the criminals by tracking where the details of their employees and customers could be compromised.”

Certified information systems security professional and senior vice president of global business and corporate development at digital identity firm ForgeRock Inc., Ben Goodman, told in a statement that passwords are traditional user authentication method for decades and that a user has an average of 130 online accounts.

“It’s unlikely that users can remember 130 unique sets of login credentials and as a result, most opt to reuse the same passwords and usernames across most if not all of their accounts,” he said. “In fact, 57% of people who have already been scammed in phishing attacks still haven’t changed their password, enabling fraudsters to leverage compromised login credentials from one account to access additional profiles with more critical data, including banking and healthcare information.”

His advice: Organizations must recognize the security risks of passwords and usernames and adopt technology to enable passwordless and username-less logins.

Related Posts

News

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Explore More

News

California enacts law requiring age input on devices and app stores from 2027

California enacts law requiring age input on devices and app stores from 2027

Explore More

News

Google to Block Access to Adult Apps for Under-18s in Singapore

Google to Block Access to Adult Apps for Under-18s in Singapore

Explore More

News

Malaysia to push mandatory ID checks on social media to curb online scams

Malaysia to push mandatory ID checks on social media to curb online scams

Explore More

News

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Explore More

News

Brazil enacts new law to regulate children’s use of social media and digital platforms

Brazil enacts new law to regulate children’s use of social media and digital platforms

Explore More

News

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

Explore More

News

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Google deemed Australia’s social media age ban as “extremely difficult” to implement

Explore More

News

California enacts law requiring age input on devices and app stores from 2027

California enacts law requiring age input on devices and app stores from 2027

Explore More

News

Google to Block Access to Adult Apps for Under-18s in Singapore

Google to Block Access to Adult Apps for Under-18s in Singapore

Explore More

News

Malaysia to push mandatory ID checks on social media to curb online scams

Malaysia to push mandatory ID checks on social media to curb online scams

Explore More

News

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Michigan Lawmakers propose that Age Verification be mandatory to access pornography

Explore More

News

Brazil enacts new law to regulate children’s use of social media and digital platforms

Brazil enacts new law to regulate children’s use of social media and digital platforms

Explore More

News

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

ChatGPT to introduce age checks after the UK’s teen death sparks lawsuits

Explore More

Take the next steps to better security.

Contact us

Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

Contact us

Request demo

Get free access to our platform and try our products today.

Get started