logo
Dark Web Alert — 2.9 Billion Passwords, 14 Million Credit Cards Stolen

Dark Web Alert — 2.9 Billion Passwords, 14 Million Credit Cards Stolen

Forbes11-05-2025

Stolen credit cards and passwords published on dark web.
I recently reported how a total of 19 billion compromised passwords had been published online to criminal forums on the dark web and shady corners of the surface web. Perhaps unsurprisingly, those shocking numbers resonated with the public, and the story went viral. Here's the bad news: the numbers are actually worse than initially thought. While 1.4 billion of the original stolen password count were found to be unique, the remainder being repeated common passwords, new research has now revealed that an incredible 2.9 unique compromised passwords are available for purchase or sharing on the dark web, along with an astonishing 14 million stolen credit cards. Here's what you need to know.
OK, so I'm taking liberties with the lyrics of Roger Miller's sixties classic, King of the Road, in this sub-heading, but the sentiment is spot on. Threat actors want your passwords to facilitate everything from ransomware to spyware attacks. Recent reports have placed the number of passwords available to cybercriminals on the dark as being in the range of 1.7 billion to the aforementioned 19 billion, although when talking about unique passwords, that drops to 1.4 billion, which is in the same kind of ballpark. The latest threat intelligence analysis, however, suggests those numbers are low. Very low indeed.
The Bitsight TRACE Security Research team has suggested that the amount of breach data, including compromised passwords and credit cards, skyrocketed by 43% in 2024 compared to the previous year. The State of the Underground report, found that 20% of all data breach victims were accounted for by U.S. organizations. Which makes the fact that is also identified that there were 2.9 billion totally unique sets of compromised credentials, up from 2.2 billion stolen passwords in the 2023 report, available to threat actors on the dark web. When it comes to stolen credit cards, the numbers are smaller but just as concerning: 14.5 million listed on underground criminal forums, that's up 20% on the previous year.
A surge in infostealer activity is partly responsible for the increased number of compromised passwords, Bitsight said. However, when it comes to the stolen credit cards, Bitsight confirmed that the rise was 'exclusively due to a surge in US cards; the number of cards from the rest of the world declined by 1.6 million, but listings of US cards increased by 4.5 million, counting for 80.7% of all compromised card listings in 2024.'

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Olympic Gymnastics Coach Receives Lifetime Ban For Abuse
Olympic Gymnastics Coach Receives Lifetime Ban For Abuse

Forbes

time32 minutes ago

  • Forbes

Olympic Gymnastics Coach Receives Lifetime Ban For Abuse

Gymnastics: US Olympic Trials: View of Ashton Locklear and Qi Han after uneven bars event during ... More Women's Competition at the SAP Center. San Jose, CA 7/8/2016 CREDIT: Donald Miralle (Photo by Donald Miralle /Sports Illustrated via Getty Images) (Set Number: SI439 TK1 ) The U.S. Center for SafeSport has permanently banned another prominent U.S. gymnastics coach. Qi Han, founder of Everest Gymnastics in Cornelius, N.C., is a former Chinese national team gymnast turned U.S. coach. The U.S. Center for SafeSport is an independent, non-profit organization responsible for investigating and responding to allegations of abuse in Olympic and Paralympic sports. On Thursday, June 5, SafeSport ruled Han 'permanently ineligible" on the centralized disciplinary database. The organization cites Han's emotional misconduct, physical misconduct, and the violation of USA Gymnastics policies and bylaws. Han coached former elite gymnast Ashton Locklear to an Olympic alternate spot in 2016 and a World title in 2014. He also coached Haleigh Bryant, a three-time NCAA National Champion with the LSU Tigers. The permanent suspension comes after Han was temporarily sanctioned for the reported misconduct in 2023. During the sanction period, Han was barred from training or contacting athletes without supplementary adult supervision. The process has been tedious for Han's victims. Allegations first surfaced in 2016, with Locklear, his most prominent athlete, reporting emotional and physical abuse to the U.S.A. Gymnastics and the U.S. Center for SafeSport in 2017. Locklear reported 'yelling" and abrupt expulsion from the gym, and accused Han of 'throwing a cellphone at her.' Han denied Locklear's claims, and in 2018, she told The New York Times that those allegations initially fell on deaf ears. 'They know about his abuse and they did nothing," she reported. The case was passed over to SafeSport in 2017, and Locklear was far from alone. According to the center, allegations against Han came from over 80 witnesses, with details measuring 'thousands of pages of evidence' and 'that span decades.' Han opened his Charlotte-area gym in 2004, nearly two decades before his initial sanction in 2023. Monica Avery, the owner of OSEGA Dream Academy in Asheville, N.C., reported Han's abuse to U.S.A Gymnastics in 2016. Avery alleged that she had seen Han 'kick an athlete' at a gymnastics competition in Texas. Avery also expressed frustration with the speed of Han's case. 'The emotional damage all these girls go through is so heartbreaking, and it could have been prevented if Han would have been stopped years ago,' she said. While the ruling is subject to appeal, the interim CEO of the U.S. Center for SafeSport, April Holmes, delivered the following statement regarding the verdict. 'This outcome sends a clear message that sport culture is changing and accountability is moving the needle.' SAN JOSE, CA - JULY 10: Ashton Locklear competes on the balance beam during Day 2 of the 2016 U.S. ... More Women's Gymnastics Olympic Trials at SAP Center on July 10, 2016 in San Jose, California. (Photo by)

FBI Director Kash Patel says his home targeted in swatting attack day before appearing on Joe Rogan's podcast
FBI Director Kash Patel says his home targeted in swatting attack day before appearing on Joe Rogan's podcast

Fox News

time40 minutes ago

  • Fox News

FBI Director Kash Patel says his home targeted in swatting attack day before appearing on Joe Rogan's podcast

FBI Director Kash Patel told podcast host Joe Rogan during an interview Friday that his house was swatted this week. Patel was a guest on "The Joe Rogan Experience," and during the interview, the FBI director broke news about his home getting swatted. "As Director of the FBI of responsibility, I'm not just gonna bring a case because somebody hurt me. They did. And they continue to do it," Patel said. "S- -t. My house just got swatted yesterday." Swatting is when a person attempts to send armed law enforcement to another person's house over a fake incident, which has led to deadly consequences in the past. The FBI did not immediately respond to Fox News Digital's request for comment on the matter. This is a developing story. Please check back for updates.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store