Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/11/2019
02:15 PM
50%
50%

Joker's Stash Puts $130M Price Tag on Credit Card Database

A new analysis advises security teams on what they should know about the underground payment card seller.

Payment card data is among the most widely distributed information on the Dark Web. The breadth of data for sale in underground marketplaces can prove helpful to security teams, who can analyze this information and combine it with other threat data to learn their potential exposure and mitigate the impact of an incident, Flashpoint researchers advise in a new report.

The ecosystem for stolen payment card data ranges from low-level markets selling cards recycled from past breaches, to top-tier sellers with unused card data directly pulled from a new breach. Joker's Stash is one of the most prominent payment card retailers on the Dark Web, where it has been selling credit cards from online and physical transactions since 2014. In 2015, it began to also sell personally identifiable information including Social Security numbers.

A recent update on Joker's Stash arrived on Oct. 29, when it added data pertaining to more than 1.3 million credit and debit cards reportedly taken from banking customers in India. The data dump released was one of the largest in Joker's Stash's history, researchers report, with pricing information valued at $100 per card, which put the total for the database at $131 million.

Joker's Stash and similar marketplaces provide value beyond cybercrime, researchers say. Fraud teams can leverage its data to learn what card data is for sale and the timing of its availability on Joker's Stash. This reveals the common point of purchase (CPP) of compromised cards and can help identify the geographical source of a breach and stem its potential impact, they explain.

Read more details here.

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "What a Security Products Blacklist Means for End Users and Integrators."

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29565
PUBLISHED: 2020-12-04
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the...
CVE-2020-5675
PUBLISHED: 2020-12-04
Out-of-bounds read issue in GT21 model of GOT2000 series (GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, and GT2103-PMBD all versions), GS21 model of GOT series (GS2110-WTBD all versions and GS2107-WTBD all versions), and Tension Controller LE...
CVE-2020-29562
PUBLISHED: 2020-12-04
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
CVE-2020-28916
PUBLISHED: 2020-12-04
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-29561
PUBLISHED: 2020-12-04
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.