Kaspersky research finds out how much your personal data costs online

Woburn, MA – December 1, 2020 – Kaspersky researchers dug into the dark web to find out the sale price for users’ private information online, finding that a driver’s license can cost as little as $5 and credit card details start around $6. Such information can be used for financial gain or for doxing, which is the public de-anonymization of a person online.

Even though people’s awareness of privacy issues is rising, most of us still only have a general understanding of why it matters, with 37% of millennials thinking that they are too boring to be the victim of cybercrime. Doxing shows why this is not the case, with the potential to affect any user who is vocal online or does not conform to subjective standards of other users.

Doxing occurs when a person shares private information about another person, without their consent, in order to embarrass, hurt or otherwise put the target in danger. Users typically do not expect personal information to leak out into the public domain, and even if it does, do not anticipate the kind of harm it might do. But doxing can even involve the hacking of the target’s accounts.

To get a better understading of how users’ personal information can be used in the wrong hands, Kaspersky researchers analyzed active offers on 10 international darknet forums and marketplaces. The research found that access to personal data can start as low as 50 cents for an ID, depending on the depth and breadth of the data offered. Some personal information remains as in-demand as it was almost a decade ago. Credit card data, banking and e-payment service access have seen their respective prices unchanged in recent years.

id-50-cents-credit-card-6-usd-reputation-free-how-much-personal-data-costs-online-and-how-it-enables-doxing.jpg

The price range in USD for different types of data identified as a result of analysis of offers on the dark market forums

However, new types of data have also emerged. This now includes personal medical records and selfies with personal identification documents, which cost up to $40. The growth in the number of photos with documents in hand and schemes using them also reflects a trend in the cybergoods game. Abuse of this data potentially results in significant consequences, such as identity theft.

Consequences of abuse of other types of personal data are also significant. Data sold on the dark market can be used for extortion, execution of scams and phishing schemes, and direct theft of money. Certain types of data, such as access to personal accounts or password databases, can be also be abused for reputational harm and other types of social damage, including doxing.

“In the past few years many areas of our lives have become digitized – and some of them, such us our health, for instance, are especially private,” Dmitry Galov, security researcher at Kaspersky’s GReAT. “As we see by the increasing number of leaks, this leads to more risks for users. However, there are positive developments too – many organizations are taking extra steps to secure their users’ data. Social media platforms have made especially significant progress in this regard as it is much harder now to steal an account of a specific user. That said, I believe our research highlights how important it is to be aware that your data is in fact in demand and can be used for malicious purposes even if you do not especially have lots of money, do not voice controversial opinions and are generally not very active online.”

“The internet has given us an opportunity to express our individualities and share our stories and that is fantastic,” said Vladislav Tushkanov, privacy expert at Kaspersky. “Yet, one has to understand that being and expressing yourself online is not exactly a private endeavor – it is more like shouting on a crowded street and you never know who might come your way, disagree with you and how they might react. With this, comes risks. This does not mean that we should all delete and close our social media accounts, of course. It is all about understanding potential consequences and risks and being prepared for them. The best course of action when it comes to your data is this: know what they know, remove what you can and take control of what information about you goes online. It is that simple, but does require effort.”

Read the full Dox, steal, reveal. Where does your personal data end up? report to learn more about doxing practices and data abuse on Securelist.

To minimize the risks of having your personal information stolen, Kaspersky recommends:

  • Be aware of phishing email and websites;
  • Always check permission settings on the apps you use, to minimize the likelihood of your data being shared or stored by third parties – and beyond – without your knowledge;
  • Use two-factor authentication. Remember that using an application that generates one-time codes is more secure than receiving the second factor via SMS. If you need additional security, invest in a hardware 2FA key;
  • Use a reliable security solution like Kaspersky Password Manager to generate and secure unique passwords for every account, and resist the temptation to reuse the same one over and over again;
  • To find out if any of the passwords you use to access your online accounts have been compromised, use a tool such as Kaspersky Security Cloud. Its Account Check feature allows users to inspect their accounts for potential data leaks. If a leak is detected, Kaspersky Security Cloud provides information about the categories of data that may be publicly accessible so that the individual affected can take appropriate action;
  • Always consider how the content you share online might be interpreted and used by others.