back to article Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50

Stolen domain admin login credentials can be resold by dark web criminals for up to £95,000 and a total of 15 billion purloined credentials are traded on illicit marketplaces. Or so says threat intel biz Digital Shadows in a study published today, which it said equates to roughly two login details for every human on the planet …

  1. Doctor Syntax Silver badge

    "Such is the popularity of these services that users on forums are desperate to acquire invite codes to this market,"

    I suppose that's the next market. Stolen invite codes.

  2. Cederic Silver badge

    I'll do you a deal

    Look, times are hard this year, so I'll give you a big discount. You can have admin credentials for any of my four domains for just £50k.

    For £95k I'll give you credentials for all four!

    1. Insert sadsack pun here Silver badge

      Re: I'll do you a deal

      Similarly, I'm willing to give full login details to my bank account for a tenner. It's loaded up with twenty grand of debt, so you'd be increasing my net wealth...

  3. LucreLout


    I'd not even give you £95,000 for admin access to Jennifer Lawrence herself. I mean, I'm sure she's lovely and it'd be the best 2 minutes of physical activity one of us ever saw, but £95k is a lot of money.

    Given the time to detection for an account with access to something you could extract at least 95 grands worth of value from, I'm not seeing any obvious account details that would be worth so much money. Maybe an AWS admin to I can mine crypto, but even that is likely to get detected before I get the value out unless I can spin up a massive amount of resources to burn the compute before anyone can react to what I'm doing. What else is worth £95k in terms of creds? Corporate espionage maybe?

    1. RayG

      Re: £95K!!

      Maybe I'm being naive, but I find it hard to think of anything one could do (for criminal gain) with £95k admin credentials that wasn't really quite high risk, so one would need expected gain of much more than 95k to take it on. Unless I'm wrong about the risk, there must be some ways of wringing genuinely huge amounts of cash out of these.

      The bank accounts tell a different story, I think. Lots of them will have little in, and most anti-fraud measures are no doubt only effective if one were to try to drain a really large amount in a rash way. So a figure of £100 rather suggests low risk to the criminal and weak protections by the banks. I guessed that, but it's not very cheering to see it demonstrated this way.

      1. LucreLout

        Re: £95K!!

        The bank accounts tell a different story, I think. Lots of them will have little in, and most anti-fraud measures are no doubt only effective if one were to try to drain a really large amount in a rash way.

        Retail accounts are most likely sought for their laundering capacity rather than their current balance.

        I can launder anything up to about £1M per year with almost no risk of getting caught, though it would inevitably come with some losses built into that - maybe about 5 or 10%. Betting shops and casinos are the easiest ways to do this.

        If you want scale however, you need a web of accounts through which to funnel money. That's easily done with corporations, however its expensive to do if you want things to be untraceable, so you're suddenly talking about £100M plus.

        The gap in that market is the £1M to £100M range, and the easiest way to make that spin cycle untraceable is dipping in and out of retail accounts, crypto wallets etc in as many different jurisdictions as you can. Some people will notice and report it, others will not notice, and others will see a credit and a debit and assume a banking error now resolved. This you can do entirely from your laptop with a few hundred quids worth of moody bank details, with no previous experience required.

        1. RayG

          Re: £95K!!

          Very informative, thank you. I had underestimated the usefulness of retail banks for that. See what you mean that even 1% of £1m gives you a very long chain. No doubt highly automatable as well.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like