Hacked PayPal accounts tripled in value during pandemic
But value of hacked credit cards decline, according to survey


Security researchers have discovered that the value of hacked PayPal accounts have spiked by 293% during the pandemic, almost tripling in a matter of months.
In an analysis of listings on 13 dark web marketplaces, researchers at pro-consumer website Comparitech found criminals were paying around 9.2 cents for every dollar in a hacked PayPal account. This is compared to a similar study conducted eight months prior, when buyers spent an average of 3.13 cents per dollar in the account.
The researchers found the average price of a PayPal account across all the marketplaces we examined was $196.50, with an average account balance of $2,133.61.
PayPal accounts have different tiers. Researchers found that individual accounts cost $161.59 on average and had an average account balance of $1,732.85, or 9.32 cents per dollar. Premier accounts, on the other hand, cost $186.31 on average and had an average balance of $2, 029.95,or 9.18 cents per dollar.
Business accounts were even more valuable, costing an average of $246 and carrying an average balance of $2,684.29, equating to 9.18 cents per dollar.
This contrasted with credit cards, including the credit card number, CVV, expiration date, cardholder name and postal code, which sell for $17.36 on average. While researchers said this is double the average price recorded from earlier this year, its value is decreasing.
RELATED RESOURCE
The state of ransomware in retail 2021
Insights into the current state of ransomware in the retail sector
Previously, cyber criminals would pay out 0.42 cents for every dollar on the stolen card. Today, they pay 0.33 cents per dollar, or 306 times the price of the stolen card.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The report said the average price of a cloned, physical card is $171, or 5.75 cents per dollar of credit limit. Researchers noted there was a positive correlation between a cloned card’s credit limit and its price. The correlation was less strong but still apparent in sales of credit card details. The average credit limit on the listings researchers examined was $2,980.
The researcher also looked at the average price for cloned copies of each major brand of credit card to find out which types of credit cards are worth the most to criminals. MasterCard was worth the most at 6.47 cents per dollar, then Discover at 6.27 cents per dollar, Visa at 5.75 cents per dollar, and American Express at 5.13 cents per dollar.
Researchers said that while brand was one consideration, other factors can contribute to a higher price on the dark web, such as whether the product is a physical card (usually cloned) or digital (just the number and other information on the card), the expiration date (newer cards are more likely to be valid), and credit limit.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
PayPal to put hate group funding under the microscope
News It will research how extremists are using payment platforms for funding
By Mike Brassfield Published
-
PayPal's authentication is no challenge for one hacker
News The white hat hacker said he could bypass the two-step security measures used to protect customer accounts
By Clare Hopping Published
-
Pressure mounts on US justice department to drop Wikileaks investigation
News Human rights organisations claim investigation could put all journalists at risk of prosecution
By Caroline Donnelly Published
-
Anonymous hackers admit involvement in 2010 PayPal cyber attack
News Anonymous group members plead guilty to taking part in DDoS attack against PayPal.
By Rene Millman Published
-
Anonymous DDoS attacks cost PayPal £3.5m, court hears
News Northampton student pleads not guilty to charges relating to attacks on online payment portal.
By Caroline Donnelly Published
-
Anonymous, LulzSec go legal in PayPal war?
News Anonymous and LulzSec claim success already in attempts to get people to ditch their PayPal accounts.
By Tom Brewster Published
-
UK teen detained as FBI makes PayPal attack arrests
News Anonymous is being hunted by police across the world, with 20 arrests made in relation to high profile cyber attacks.
By Tom Brewster Published
-
Website danger as hacker breaks SSL encryption
News The Black Hat conference in the US shows that software can be used to steal information from sites you may think are secure.
By Asavin Wattanajantra Published