BidenCash releases over 1.2 million credit card details on the dark web

Share post:

BidenCash, a popular dark web carding site, released more than 1.2 million credit cards to promote its service and underground payment card business, allowing anyone to download them for free to commit financial fraud, thereby alerting several security firms.

BidenCash, a marketplace for stolen cards launched in June 2022, has a habit of leaking a few thousand cards as a promotional measure to gift fraudsters who can download the dump for free and use it for fraudulent activities.

It has taken another step to promote its market by placing a record of more than 1.2 million credit and debit cards in a notorious cybercrime forum populated mainly by Russian and English-speaking threat actors who spread the collection through a clearnet domain and other hacking and carding forums.

The circulating file contains a mix of new cards expiring between 2023 and 2026 from around the world, but the majority appear to come from the United States, with others from Canada, India, Bangladesh, Saudi Arabia, the United Arab Emirates, Indonesia, Malaysia, and Singapore.

The stolen information includes 1,221,551 credit and debit card records, including credit card number, expiration date, three-digit card verification value (CVV), card holder’s name, associated bank name, full address, date of birth, email address and telephone number. The database also includes the social security numbers of American cardholders.

Although not all details of all 1.2 million records are available, most entries contain more than 70% of the data types.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways