AdverseMonitor house promotionSearch the live index before an exposure becomes an incidentCheck a domain →
← All threat advisories

Threat Intel

How Cybercriminals Sell Stolen Credentials

AdverseMonitor Team10 min read
Original visual analysis for this threat advisory
AdverseMonitor original analysis visual, created for this advisory.

Executive summary

Risk context: verify
  • Attackers buy and sell stolen credentials through forums, automated shops, messaging channels, and private deals. A credential may pass through several sellers before another criminal uses it for fraud or network access.
  • Some marketplaces use fixed prices, seller reviews, escrow, and support channels. This article follows a credential from theft through resale and use.
  • Use the section links to jump directly to technical context and response guidance.

Attackers buy and sell stolen credentials through forums, automated shops, messaging channels, and private deals. A credential may pass through several sellers before another criminal uses it for fraud or network access.

Some marketplaces use fixed prices, seller reviews, escrow, and support channels. This article follows a credential from theft through resale and use.

The Credential Marketplace Ecosystem

Credentials stolen through phishing, malware, or a database breach may move through several types of seller:

Tier 1: Initial Collectors - Attackers who steal credentials through breaches, malware, or phishing operations

Tier 2: Wholesale Brokers - Bulk purchasers who buy large credential dumps and resell them in smaller quantities

Tier 3: Retail Sellers - Individuals selling specific high-value credentials or curated lists

Tier 4: End Users - Criminals who purchase credentials to conduct fraud, account takeovers, or further attacks

Where Credentials Are Sold

Dark Web Forums

Underground forums like BreachForums, XSS, and Exploit.in host dedicated marketplace sections where credentials are traded. These forums operate with:

  • Reputation systems (vendor ratings and reviews)
  • Escrow services to prevent scams
  • Dispute resolution processes
  • Dedicated administrators who enforce marketplace rules

Entry to many of these forums requires invitations, proof of skills, or payment, creating trusted communities of criminals.

Automated Shops

Some operators run automated credential shops, often on the dark web. A buyer can search inventory, pay with cryptocurrency, and receive the purchased data through the site.

Telegram Channels

Increasingly, credential sales happen through Telegram channels and bots. Sellers advertise fresh credential dumps, and buyers purchase through automated systems. Telegram's encryption and ease of use make it attractive for this market.

Paste Sites

Some attackers dump credentials on paste sites (like Pastebin) for free, either as proof of breach, reputation building, or because the data is old. These "combolists" are then aggregated by others for resale or credential stuffing attacks.

Types of Credential Products

Combolists

Combolists aggregate email-and-password pairs from several breaches. Sellers offer bulk lists for credential-stuffing attacks, but many entries may be old or invalid.

Fresh Dumps

Sellers may describe recently stolen credentials as more valuable. The asking price depends on the claimed target, freshness, access, and seller reputation, and the claim may be false.

Categorized Credentials

Credentials organized by company, industry, or domain. For example, "Fortune 500 corporate email credentials" or "healthcare provider logins." These curated lists command higher prices than random combolists.

Premium Access

Administrative credentials, VPN access, or credentials for high-value accounts may be advertised individually. Asking prices vary with the claimed access, target, freshness, and seller reputation.

Fullz

Complete identity packages may combine credentials with names, addresses, identification numbers, card details, and security answers. The contents and authenticity vary by seller.

Pricing Models

Credential pricing follows supply and demand economics:

Common Listing Categories:

  • Combolists: older username and password pairs packaged in bulk
  • Fresh credential dumps: recently collected account data
  • Corporate email credentials: accounts tied to an organization
  • Financial accounts: access claims involving banking or payment services
  • VPN or remote desktop access: claimed entry into a business network
  • Administrative credentials: accounts with elevated permissions
  • Cryptocurrency accounts: access claims involving exchanges or wallets

Prices fluctuate based on:

  • Freshness: Newer credentials worth more (likely unchanged)
  • Validity: Verified working credentials command premiums
  • Target Value: High-revenue companies or wealthy individuals
  • Access Level: Admin rights worth 10-100x standard user credentials
  • Supply: Rare credentials (government, military, major banks) are premium

The Business Model

Subscription Services

Some sellers charge a monthly subscription for access to databases that they update with new credential dumps.

Verification Services

Third parties may test whether credentials still work before purchase and charge for each check.

Credential Stuffing Tools

Automated tools can test credentials across many services. Tool access may itself be sold, while buyers use the results to find reused passwords.

Support and Training

Sophisticated sellers provide customer support, tutorials on using credentials, and even training on monetization techniques. This "professionalization" makes the market accessible to less technical criminals.

How Credentials Are Validated

Buyers want assurance they're purchasing working credentials. Sellers use several methods:

Sample Credentials: Providing a small number of free credentials from the batch as proof

Screenshots: Showing successful logins to prove validity

Automated Checking: Running credentials through verification tools and sharing results

Escrow Systems: Third-party holds payment until buyer confirms credentials work

Reputation: Established sellers with positive reviews command trust and higher prices

Payment Methods

Cryptocurrency dominates credential marketplace payments:

Cryptocurrency: Sellers may request assets such as Bitcoin, while transactions can still leave records investigators use.

Monero: Privacy-focused cryptocurrency preferred for anonymity

Ethereum & Altcoins: Alternative options with varying anonymity

Cryptocurrency Mixers: Services that obscure transaction origins, adding anonymity layer

Some sellers accept gift cards, prepaid debit cards, or other cryptocurrencies. Payment method choice balances anonymity, convenience, and transaction fees.

How Organizations End Up in These Markets

Your credentials reach these marketplaces through multiple vectors:

Direct Database Breaches: Attackers breach your systems and steal credential databases

Phishing Campaigns: Employees tricked into providing credentials through fake login pages

Malware/Infostealers: Malware captures credentials as users enter them or from browser storage

Third-Party Breaches: Vendors or partners get breached, exposing credentials your employees used on their platforms

Password Reuse: Employees reuse corporate passwords on personal sites that get breached

Insider Threats: Malicious or compromised employees sell credentials directly

The Credential Lifecycle

A credential may move through several stages, but there is no fixed timetable:

  1. Collection: Credentials are taken through a breach, phishing, malware, or another access path.
  2. Use or sale: The collector may test the account, retain it, or offer it to another buyer.
  3. Verification and sorting: A broker may test entries and group them by organization or service.
  4. Resale: The same entry may appear in several packages or services.
  5. Aggregation: Older entries may be added to larger combolists used for password-reuse attacks.

A listing price does not show whether the credential works, whether it has already been reset, or whether the seller possesses the claimed access.

Protecting Against Credential Theft

Understanding this economy informs defensive strategies:

Multi-Factor Authentication: Blocks a password-only login when the attacker lacks the required factor. Phishing-resistant methods offer stronger protection against interception and session theft.

Password Policies: Require unique passwords, screen new passwords against known compromised values, support password managers, and force a change when compromise is suspected rather than on an arbitrary routine.

Dark Web Monitoring: Surface available records that match the organization's terms, then verify the account and source before applying the response process.

Employee Training: Educate staff about phishing, password reuse dangers, and social engineering tactics.

Breach Detection: Fast detection limits how much data can be stolen before access is cut off.

Zero Trust Architecture: Assume credentials will be compromised; limit what they can access.

Anomaly Detection: Monitor for unusual login patterns (geographic anomalies, time-of-day oddities, impossible travel).

Regular Access Reviews: Disable unused accounts; former employees' credentials frequently appear in marketplaces.

What Happens When Credentials Are Used

Purchased credentials enable various attacks:

Account Takeovers: Access customer accounts to steal data, make fraudulent purchases, or conduct financial fraud

Business Email Compromise: Impersonate executives to authorize fraudulent wire transfers

Ransomware Deployment: Use VPN credentials to access networks and deploy ransomware

Data Theft: Steal intellectual property, customer databases, or other sensitive information

Lateral Movement: Use compromised employee accounts to access additional systems and escalate privileges

Credential Stuffing at Scale: Test credentials across thousands of sites to find additional valid accounts

The Evolving Market

The credential marketplace continues to evolve:

Increased Automation: Bots handle everything from theft through sale to validation

Specialization: Vendors focusing on specific industries (healthcare, financial services) or credential types

Quality Over Quantity: Shift toward fewer, higher-quality verified credentials rather than massive unverified dumps

Integrated Services: Bundling credentials with access methods, bypass techniques, or monetization guidance

AI-Enhanced: Using AI to curate credentials, predict which are most valuable, and optimize pricing

Conclusion

Credential markets divide the work of theft, sorting, validation, resale, and use among different participants. Defenders should account for the full path rather than treating the original breach as the end of the incident.

Organizations can prepare for credential exposure by requiring MFA, watching authentication logs, and defining when to reset an affected account.

A relevant monitoring match can point an analyst to credential-related source evidence. The analyst still needs to validate the match, identify the affected account, and check for unauthorized access.

MFA and limited account privileges can reduce what an attacker can do with a stolen password. Monitoring and authentication logs help the team decide which accounts need investigation.

SHARE / SEARCHXLinkedInFacebook