In the first half of 2022, we saw an increase in compromised account credentials, in combination with other extremely valuable data for hackers.
The number of alerts sent on the dark web was over 780.000 in the first half of 2022 and grew by +44.1% compared to the second half of 2021.
The number of alerts sent on the open web was over 70,000 in the first half of 2022 and fell by -4.9% compared to the second half of 2021.
In total, more than 850,000 alerts were sent in the first half of 2022, mainly related to data found on the dark web.
In particular, the address has become a valuable personal data because it allows you to complete the victim's profile and geolocate it.
The address is often found along with other information (such as the victim's first and last name) and contact details (email or phone number).
For example, in the first half of 2022, the full postal address was found in combination with a phone number in 70% of cases, this exposes the victim to receive more credible fraudulent messages, such as those of fake couriers to notify the delivery of a package.
Often these smishing messages (SMS phishing) contain malicious links that cause the victim to click and provide additional data to fraudsters.
Which are the most vulnerable data on the web?
There are several categories of data that are subject to attack; however, we have observed that email addresses, passwords, telephone numbers, usernames and postal addresses mainly circulate on the dark web and are therefore most vulnerable.
Compared to the last semester, the postal address enters the top 5, the telephone number exceeds the username and the email address rises to the top of the ranking.
TOP 5 MOST VULNERABLE DATA I semester 2022 |
|
Password |
Phone number |
Username |
Postal address |
Data Source Provider: Cyber CRIF Observatory
Even more interesting is to observe the main combinations of data found: very often emails are associated with a password (88.1% of cases); as well as together with usernames, passwords appear very often (79.9%).
As far as personal data are concerned, the name and surname are often associated with the telephone number (52.2%) up by +251% compared to the second half of 2021, a valuable data for fraudsters, especially in the case of Smishing or SIM Swapping.
The phone number plays a fundamental role in these cases and, when also associated with the password (33.7%), the vulnerability of the victim increases.
With regard to credit card data, very frequently in addition to the card number there are also cvv and expiration date (95.9% of cases), with an increase of +8%.
Key data combination |
II semester 2021 |
I semester 2022 |
change % |
Email + Password |
90,8% |
88,1% |
-3% |
Phone number + password |
81,6% |
33,7% |
-59% |
Username + Password |
86,6% |
79,9% |
-8% |
Phone number + Name and Surname |
14,8% |
52,2% |
+251% |
Credit card + CVV e Expiry date |
88,6% |
95,9% |
+8% |
Data Source Provider: Cyber CRIF Observatory
Email accounts |
I semester 2022 |
II semester 2021 |
change % |
Personal |
91,6% |
77,9% |
+17,6% |
Business |
8,4 % |
22,1% |
-62,0% |
Data Source Provider: Cyber CRIF Observatory
Most frequently circulating accounts on the Dark Web
Amongst the most frequently circulating accounts on the dark web, the names of email services, dating sites, social networks and online games have emerged.
TOP 10 account |
Type |
|
1 |
Yahoo |
|
2 |
Gmail |
|
3 |
MyHeritage |
Family tree |
4 |
Badoo |
Dating site |
5 |
Mail.ru |
|
6 |
|
Social |
7 |
Zynga |
Online games |
8 |
Dofus |
Online games |
9 |
|
Social |
10 |
|
Social |
Data Source Provider: Cyber CRIF Observatory
Most common stolen passwords on dark web
The analysis of the passwords detected makes us reflect on the vulnerability of the accounts with which they are associated. In the top 10 passwords in circulation in the first half of 2022 we found the following:
TOP 10 I semester 2022 |
|
1 |
123456 |
2 |
123456789 |
3 |
password |
4 |
qwerty |
5 |
12345 |
6 |
12345678 |
7 |
qwerty123 |
8 |
1q2w3e |
9 |
111111 |
10 |
1234567890 |
Data Source Provider: Cyber CRIF Observatory
These passwords are in order to be the most popular and therefore most compromised on the dark web and can be hacked in an average time of less than a second. In first place in the top 10 is "123456", a password very common in dark web environments during the first half of 2022, on the podium with "123456789" and "password", followed by "qwerty".
In the first half of 2022 in the list of the most common passwords appear "iloveyou" and "secret". Other common passwords include simple words like "dragon," "princess," "football," and "sunshine," proper names like "daniel," "michael," and "charlie," names referencing games like "pokemon," characters like "superman," and easy-to-guess number combinations, or repetitions like "111111."
While using simple passwords might seem like a practical way to help users remember them, it also leads to a high security risk for users and their systems.
As you can see by scrolling through the ranking, the most frequently detected passwords on the dark web are very simple combinations of numbers and letters, so it is very easy for hackers to discover them. On the other hand, the use of these passwords reveals the lack of awareness of web users, who often ignore the most basic rules to protect themselves from intrusions.
Ranking of the most detected email by domains and countries mostly hit by the phenomenon
The ranking of the most detected emails on the dark web, with regards to the composition of the domains, allows us to locate the email provider, with the exception of the ".com" and ".net", commonly used worldwide. The domain .com, in addition to being global, is also the most used in the USA. It can therefore be deduced that the countries most affected by the phenomenon of online email and password theft are US, Russia, Germany and France, followed by United Kingdom, which is just ahead of Italy. The other countries that complete the top 10 of the domains most affected in online password theft are Poland, Japan, Brazil, the Czech Republic which enters the ranking of the most affected countries surpassing Canada.
The .edu domain, widespread among schools, colleges and universities, also circulates widely on the dark web; this means that numerous email addresses of students and professors are exposed to cyber risk. Even the .org domain, noteworthy as it refers to non-profit organizations and institutions, gains positions from 19 to 13th position.
The table below shows the ranking of the most detected domains and the most affected countries:
TOP 20 I semester 2022 |
|
1 |
.COM .NET global and USA |
2 |
.RU Russia |
3 |
DE Germany |
4 |
.FR France |
5 |
.UK United Kingdom |
6 |
.IT Italy |
7 |
.PL Poland |
8 |
.JP Japan |
9 |
.BR Brazil |
10 |
.CZ Czech republic |
11 |
.EDU |
12 |
Canada |
13 |
.ORG |
14 |
India |
15 |
Ukraine |
16 |
Spain |
17 |
Taiwan |
18 |
China |
19 |
Australia |
20 |
Netherlands |
Data Source Provider: Cyber CRIF Observatory
Misuse of the most detected accounts
Stolen credentials can be used for a variety of purposes, such as to break into victims' accounts, misuse services, send emails with requests for money or phishing links, send malware or ransomware, for the purpose of extorting or stealing money. Through a qualitative analysis of the contexts in which the data circulates, the accounts have been categorized according to the purpose of use.
Most of the accounts detected are related to email mailboxes (27.0%) followed by entertainment sites (21.0%), mainly related to online gaming and dating accounts (online dating sites). In third place, the theft of forum accounts and websites of paid services (18.6%) and social media (13.9%) is highlighted. A fair part of the stolen accounts can be ascribed to e-commerce platforms (12.3%), up by +132% compared to the previous semester.
The risk of theft of such accounts can have direct economic consequences for victims.
Most detected account |
I semester 2022 |
Email accounts |
27,0% |
Entertainment |
21,0% |
Forum and website |
18,6% |
Social Media |
13,9% |
Ecommerce |
12,3% |
Other services |
7,2% |
Data Source Provider: Cyber CRIF Observatory
Where is more credit card data obtained?
The ranking of the continents most subject to illicit credit card data exchange is lead by North America, followed by Asia which surpasses Europe, while Africa surpasses South America. At the bottom of the ranking we find Oceania, with a significant % growth compared to the previous period.
Continent |
I semester 2022 |
change % |
North America |
40,1% |
-27% |
Asia |
26,3% |
+97% |
Europe |
14,1% |
-33% |
Africa |
8,8% |
+183% |
South America |
5,5% |
+76% |
Oceania |
5,2% |
+304% |
Data Source Provider: Cyber CRIF Observatory
The ranking of the countries most subject to credit card data exchange sees the United States, Russia, the United Kingdom, Brazil and Canada in the lead. In particular, Russia raised 9 positions compared to the second half of 2021.
Even more evident is Ukraine position, previously ranked 92° while entering now amongst the the top 20.
The ranking includes:
TOP 20 - I semester 2022 |
|
1 |
USA |
2 |
Russia |
3 |
UK |
4 |
Brazil |
5 |
Canada |
6 |
India |
7 |
France |
8 |
Spain |
9 |
Japan |
10 |
China |
11 |
Germany |
12 |
Australia |
13 |
Ukraine |
14 |
Italy |
15 |
Argentina |
16 |
South Korea |
17 |
Poland |
18 |
Mexico |
19 |
Chile |
20 |
Turkey |
Data Source Provider: Cyber CRIF Observatory
Focus: Top 3 countries by continent
Below are the rankings of the countries most subject to credit card data exchange for each continent:
TOP 3 Africa I semester 2022 |
|
1 |
South Africa |
2 |
Egypt |
3 |
Nigeria |
TOP 3 America I semester 2022 |
|
1 |
USA |
2 |
Canada |
3 |
Mexico |
TOP 3 Asia I semester 2022 |
|
1 |
India |
2 |
Japan |
3 |
China |
TOP 3 Europe I semester 2022 |
|
1 |
Russia |
2 |
UK |
3 |
France |
TOP 3 Oceania I semester 2022 |
|
1 |
Australia |
2 |
New Zeland |
3 |
Guam |
Data Source Provider: Cyber CRIF Observatory
About CRIF Cyber Observatory
The Cyber Observatory aims to analyze the vulnerability of people and companies to cyber-attacks and interpret the main trends concerning the data exchanged in Open Web and Dark Web environments, the type of information, the areas in which data traffic is concentrated and the most exposed countries.
In addition, the Cyber Observatory aims to highlight the risks to which individuals and businesses are exposed on a daily basis, evaluate the main trends and offer some ideas to face cyber risk.
The data are the result of an analysis and study activity carried out on the web environments where data are shared and exchanged. These are not only websites but groups, forums and specialized communities of the so-called "Dark Web". But what do we mean by the dark web and how does it work? The Dark Web is a set of web environments that do not appear through normal Internet browsing activities and requires some specific browsers or targeted searches. Precisely because of its nature, it is exploited by hackers to exchange data, obtained through phishing activities or other types of attacks.
Credit cards are in the sights of cyber criminals Over the past year, more than 1.6 million alerts were sent relating to data found on the dark web. Alerts relating to phone numbers combined with first and last names on the rise: +4.4%. The majority of hacked accounts relate to entertainment (mainly online gaming and dating) (37.2%), but breaches of social media accounts increased significantly (+125.8%).
Read moreCyber-attacks in 2023: 45% increase in data theft on the dark web. Over 7.5 billion pieces of information circulating on the dark web at a global level, with a 15.9% increase in reports. The techniques used by cybercriminals are becoming increasingly sophisticated: with the malicious use of artificial intelligence, it is getting harder and harder to distinguish between genuine and bogus communications.
Read moreRansomware attacks show no signs of slowing down. Discover 5 of the most severe attacks that occurred in 2022.
Read morePlease fill in the form below (fields with * are mandatory) and we will respond to your request as soon as possible!