B1ack’s Stash released 1 Million credit cards

This post was originally published on Security Affairs. It can be found here.

Experts warn that the carding website B1ack’s Stash released a collection of over 1 million unique credit and debit cards.

D3 Lab researchers reported that on February 19, 2025, the carding website B1ack’s Stash released a collection of over 1 million unique credit and debit cards. Experts speculate that B1ack’s Stash used the free card release as a marketing strategy. The decision to release free samples aims at attracting new customers and gain notoriety in the cybercrime ecosystem.

The marketplace administrator announced the data leak on a popular cybercrime forum, claiming the release of a lot composed of 4 million free credit cards.

D3 Lab pointed out that hundreds of thousands of cards were issued by European financial institutions. Cards are sorted by type, country, and bank, the threat actors are also offering card dumps.

“The post promised the release of 4 million free credit cards, with the actual upload of 6 archives containing 1,018,014 unique cards. Among these, 192,174 were issued by European financial institutions.” reads the analysis published by D3 Lab.

The leaked data includes PAN (Primary Account Number), expiration date, CVV2, cardholder’s personal details, email address, IP address, and User-Agent.

The researchers speculate the data was obtained through e-skimming.

“Web Skimming remains one of the most prevalent threats to e-commerce platforms and credit card holders.” concludes the report.

In February 2023, the dark web carding site BidenCash leaked for free a collection of approximately 2 million stolen payment card numbers.

Underground carding marketplaces are crucial components of the cybercrime ecosystem, they facilitate the sale and purchase of payment card data. One of the most popular carding site was Joker Stash, its operators retired in February 2021 and shut down their servers and destroyed the backups.

According to Forbes, the administrator has amassed a billion dollars worth of Bitcoin with its activity.

After the retirement, other carding websites such as ‘Ferum Shop’, ‘UAS’, and ‘Trump Dump’ gained popularity in the underground marketplace.

‘BidenCash’ was launched in April 2022 and was considered a low-profile credit card shop. The ability of its operators to periodically release fresh dumps and promotional lots for free increased rapidly increased its popularity.

In June 2022, BidenCash released over 7.9 million payment card data dating from 2019 to 2022 on a cybercrime forum. However, the dump only contained 6,581 records exposing credit card numbers.

Banking institutions should monitor the dark web for the offering of credit/debit cards to prevent fraudulent activities.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, carding)

This post was originally published on this site

Forum Search

Partners & Sponsors
  • University of Baltimore
  • Towson University
  • Bureau of Justice Assistance
  • National Science Foundation
LATEST FORUM POSTS
Test post2

Test Post2

By Demo User12, 1 year ago

Finding internships

Hello, Has anyone here secured any forensic related internships for 2024? I'm collecting some data and wanted to know what...

By AP Malla, 1 year ago

Beginner network forensic investigation

How should I approach network forensic? Would you recommend learning tools like WireShark?

By AP Malla, 1 year ago

Cyber Forensic Employment: High level guidelines

Understand the Basics: Know the Field: Cyber forensics involves investigating digital crimes, analyzing electronic data, and recovering hidden, deleted, or...

By AP Malla, 1 year ago

LATEST POSTS