{"id":253364,"date":"2021-05-19T13:10:53","date_gmt":"2021-05-19T10:10:53","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web\/"},"modified":"2021-05-19T13:10:53","modified_gmt":"2021-05-19T10:10:53","slug":"heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web\/","title":{"rendered":"#Here\u2019s how much your stolen personal data is worth on the dark web"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a3873368ffe8\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a3873368ffe8\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web\/#Its_mostly_about_the_money\" >It\u2019s (mostly) about the money<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/buradabiliyorum.com\/en\/heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web\/#Where_stolen_data_goes\" >Where stolen data goes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/buradabiliyorum.com\/en\/heres-how-much-your-stolen-personal-data-is-worth-on-the-dark-web\/#How_to_know_and_what_to_do\" >How to know and what to do<\/a><\/li><\/ul><\/nav><\/div>\n<p>&#8220;<strong>#Here\u2019s how much your stolen personal data is worth on the dark web<\/strong>&#8221;<\/p>\n<div>Data breaches have become common, and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/pages.riskbasedsecurity.com\/hubfs\/Reports\/2020\/2020%20Q1%20Data%20Breach%20QuickView%20Report.pdf\">billions of records are stolen worldwide every year<\/a>. Most of the <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a> coverage of data breaches tends to focus on how the breach h<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ened, how many records were stolen and the financial and legal impact of the incident for organizations and individuals affected by the breach. But what happens to the data that is stolen during these incidents?<\/p>\n<p>As a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/scholar.google.com\/citations?user=pvxc54kAAAAJ&amp;hl=en\">cybersecurity researcher<\/a>, I track data breaches and the black market in stolen data. The destination of stolen data depends on who is behind a data breach and why they\u2019ve stolen a certain type of data. For example, when data thieves are motivated to embarrass a person or organization, expose perceived wrongdoing or improve cybersecurity, they tend to release relevant data into the public domain.<\/p>\n<p>In 2014, hackers backed by North Korea <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.pbs.org\/newshour\/nation\/north-korean-programmer-charged-in-sony-hack-wannacry-attack\">stole Sony Pictures Entertainment employee data<\/a> such as Social Security numbers, financial records and salary information, as well as emails among top executives. The hackers then published the emails to embarrass the company, possibly in retribution for releasing a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.sonypictures.com\/movies\/theinterview\">comedy<\/a> about a plot to assassinate North Korea\u2019s leader, Kim Jong Un.<\/p>\n<p>Sometimes when data is stolen by national governments it is not disclosed or sold. Instead, it is used for espionage. For example, the hotel company Marriott was the victim of a data breach in 2018 in which personal information on 500 million guests was stolen. The key suspects in this incident were hackers backed by the Chinese government. One theory is that <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/thehill.com\/policy\/technology\/420929-china-behind-marriott-data-breach-investigators-conclude\">the Chinese government stole this data<\/a> as part of an intelligence-gathering effort to collect information about U.S. government officials and corporate executives.<\/p>\n<p><iframe loading=\"lazy\" id=\"T0U9h\" class=\"tc-infographic-datawrapper\" style=\"border: none;\" src=\"https:\/\/datawrapper.dwcdn.net\/T0U9h\/1\/\" width=\"100%\" height=\"400px\" frameborder=\"0\"><\/iframe><\/p>\n<p>But the majority of hacks seem to be about selling the data to make a buck.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Its_mostly_about_the_money\"><\/span>It\u2019s (mostly) about the money<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Though data breaches can be a national security threat, 86% are about money, and 55% are committed by organized criminal groups, according to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/dbir\/2020\/results-and-analysis\/\">Verizon\u2019s annual data breach report<\/a>. Stolen data often ends up being sold online on the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.csoonline.com\/article\/3249765\/what-is-the-dark-web-how-to-access-it-and-what-youll-find.html\">dark web<\/a>. For example, in 2018 hackers <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/hackers-selling-stolen-data\/\">offered for sale more than 200 million records<\/a> containing the personal information of Chinese individuals. This included information on 130 million customers of the Chinese hotel chain Huazhu Hotels Group.<\/p>\n<p>Similarly, data stolen from <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.nbcnews.com\/business\/business-news\/target-says-stolen-info-data-breach-hit-70-million-people-flna2D11894083\">Target<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2014-03-05\/sally-beauty-data-hack-another-day-another-retailer-in-a-massive-credit-card-breach\">Sally Beauty<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.latimes.com\/business\/la-fi-pf-changs-breach-33-restaurants-20140804-story.html\">P.F. Chang<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/new-retail-breach-reported-a-5927\">Harbor Freight<\/a> and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/money.cnn.com\/2014\/09\/18\/technology\/security\/home-depot-hack\/index.html\">Home Depot<\/a> turned up on a known online black-market site called <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/qz.com\/260716\/these-are-the-websites-where-hackers-flip-stolen-credit-card-data-after-an-attack\/\">Rescator<\/a>. While it is easy to find marketplaces such as Rescator through a simple Google search, other marketplaces on the dark web can be found only by using <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/drfone.wondershare.com\/dark-web\/dark-web-browser.html\">special web browsers<\/a>.<\/p>\n<p>Buyers can purchase the data they are interested in. The most common way to pay for the transaction is with bitcoins or via Western Union. The prices depend on the type of data, its demand and its supply. For example, a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/follow-the-data\">big surplus<\/a> of stolen <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.csoonline.com\/article\/3215864\/how-to-protect-personally-identifiable-information-pii-under-gdpr.html\">personally identifiable information<\/a> caused its price to drop from US$4 for information about a person in 2014 to $1 in 2015. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.privacyaffairs.com\/dark-web-price-index-2021\/\">Email dumps<\/a> containing anywhere from a hundred thousand to a couple of million email addresses go for $10, and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.privacyaffairs.com\/dark-web-price-index-2021\/\">voter databases<\/a> from various states sell for $100.<\/p>\n<p><iframe loading=\"lazy\" id=\"YtPSu\" class=\"tc-infographic-datawrapper\" style=\"border: none;\" src=\"https:\/\/datawrapper.dwcdn.net\/YtPSu\/1\/\" width=\"100%\" height=\"400px\" frameborder=\"0\"><\/iframe><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Where_stolen_data_goes\"><\/span>Where stolen data goes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Buyers use stolen data in several ways. Credit card numbers and security codes can be used to create clone cards for making fraudulent transactions. Social Security numbers, home addresses, full names, dates of birth and other personally identifiable information can be used in identity theft. For example, the buyer can apply for loans or credit cards under the victim\u2019s name and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.irs.gov\/newsroom\/taxpayer-guide-to-identity-theft\">file fraudulent tax returns<\/a>.<\/p>\n<p>Sometimes <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cybercrime-and-digital-threats\/what-do-hackers-do-with-your-stolen-identity\">stolen personal information is purchased<\/a> by <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/technology-25808189\">marketing firms<\/a> or companies that specialize in spam campaigns. Buyers can also use stolen emails in phishing and other social engineering attacks and to distribute malware.<\/p>\n<p>Hackers have targeted personal information and financial data for a long time because they are easy to sell. Health care data has <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.hipaajournal.com\/healthcare-data-breach-statistics\/\">become a big attraction for data thieves<\/a> in recent years. In some cases the motivation is extortion.<\/p>\n<p>A good example is the theft of patient data from the Finnish psychotherapy practice firm Vastaamo. The hackers used the information they stole to demand a ransom from not only Vastaamo, but also from its patients. They <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/vastaamo-psychotherapy-patients-hack-data-breach\/\">emailed patients<\/a> with the threat to expose their mental health records unless the victims paid a ransom of 200 euros in bitcoins. At least 300 of these <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/apnews.com\/article\/psychotherapy-cabinets-finland-6b27c895df0abd532a4fb000c9d5d517\">stolen records have been posted online<\/a>, according to an Associated Press report.<\/p>\n<p>Stolen data including medical diplomas, medical licenses and insurance documents can also be used to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.zdnet.com\/article\/this-is-how-hackers-make-money-from-your-stolen-medical-data\/\">forge a medical background<\/a>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_know_and_what_to_do\"><\/span>How to know and what to do<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>What can you do to minimize your risk from stolen data? The first step is to find out if your information is being sold on the dark web. You can use websites such as <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/haveibeenpwned.com\/\">haveibeenpwned<\/a> and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/intelx.io\/\">IntelligenceX<\/a> to see whether your email was part of stolen data. It is also a good idea to subscribe to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.usnews.com\/360-reviews\/identity-theft-protection\">identity theft protection services<\/a>.<\/p>\n<p>If you have been the victim of a data breach, you can take <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.tomsguide.com\/us\/data-breach-to-dos,news-18007.html\">these steps<\/a> to minimize the impact: Inform credit reporting agencies and other organizations that collect data about you, such as your health care provider, insurance company, banks and credit card companies, and change the passwords for your accounts. You can also report the incident to the Federal Trade Commission to get a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/identitytheft.gov\/\">tailored plan<\/a> to recover from the incident.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading=\"lazy\" decoding=\"async\" style=\"border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important; text-shadow: none !important;\" alt=\"The Conversation\" width=\"1\" height=\"1\" class=\"js-lazy\" src=\"https:\/\/counter.theconversation.com\/content\/158934\/count.gif?distributor=republish-lightbox-basic\"\/><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https:\/\/theconversation.com\/republishing-guidelines --><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" style=\"border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important; text-shadow: none !important;\" src=\"https:\/\/counter.theconversation.com\/content\/158934\/count.gif?distributor=republish-lightbox-basic\" alt=\"The Conversation\" width=\"1\" height=\"1\" class=\"\" srcset=\"\"\/><\/noscript><\/p>\n<p><em>This article by\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/theconversation.com\/profiles\/ravi-sen-1224935\">Ravi Sen<\/a>, Associate Professor of Information and Operations Management, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/theconversation.com\/institutions\/texas-aandm-university-1672\">Texas A&amp;M University<\/a>,\u00a0is republished from <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/theconversation.com\">The Conversation<\/a> under a Creative Commons license. Read the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/theconversation.com\/heres-how-much-your-personal-information-is-worth-to-cybercriminals-and-what-they-do-with-it-158934\">original article<\/a>.<\/em><\/p>\n<\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/news\/how-much-your-stolen-personal-data-is-worth-on-the-dark-web-syndication\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Here\u2019s how much your stolen personal data is worth on the dark web&#8221; Data breaches have become common, and billions of records are stolen worldwide every year. Most of the media coverage of data breaches tends to focus on how the breach happened, how many records were stolen and the financial and legal impact of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":253365,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/05\/Cybercriminal-icons-hed.jpg&signature=d8075e8cd1124ce9d2d612930d894c6d","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-253364","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/253364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=253364"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/253364\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/253365"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=253364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=253364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=253364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}