June 22, 2022

Free stolen credit cards details on new BidenCash market

Another Credit Card market decided to publish a dataset of data for free to advertise.

On June 16, BidenCash published an archive containing various information of credit card holders, containing a CSV file with 7.948.862 lines contains the following information:

  • Full name,
  • Home address,
  • Phone number,
  • Email address,
  • Credit Card number,
  • Type and Circuit of the Credit Card.

Overall there are 6.682 credit cards, but from our analysis only 1.281 would be new, valid and never before shared in the deep web. However, there are 3.076.098 unique email addresses.

The data was probably collected by web skimmers, sometimes there are HTML error messages in the compilation of common online shop forms (ex “Please select region or province”, “Si prega di selezionare la regione, lo stato o la provincia”, etc)

In the same time, almost a million customer records were exposed on an Elasticsearch server run by Malaysian point-of-sale software vendor StoreHub.