Crackers reselling your logins on the deep web: the gray market for credentials
How email-and-password combolists become products traded in closed forums.
Audience: SaaS Platforms · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
Valid logins to your platform are listed on forums like BreachForums or specialized Telegram channels, priced per unit with a "fresh" guarantee.
How the scam works
Attackers run credential stuffing using leaks from other platforms. Working logins are sorted, validated and resold as premium access at a fraction of the official price.
Common mistake
Treating password lockouts as operational noise without investigating the source of the compromised logins.
Impact
Eroded revenue, support overloaded with locked-out legitimate customers and reputational exposure for being "easy to hack".
What works
Breach database monitoring, OSINT in closed forums and proactive blocking of leaked credentials.
Protection checklist
- Monitor HaveIBeenPwned and similar databases
- Force resets on passwords found in leaks
- Implement aggressive rate limiting on login
- Detect credential stuffing patterns by ASN
- Initiate takedown of forum listings
- Communicate clearly with affected users
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Your credentials are already for sale somewhere. The question is whether you are looking.