Approximately 617 million electronic accounts that have been stolen from 16 websites are being sold as of today on the Dark Web. For less than $20,000 in Bitcoin, the following compromised databases can be purchased from the online Dream Market, via the Tor network:
Dubsmash (162 million accounts), MyFitnessPal (151 million), MyHeritage (92 million), ShareThis (41 million), HauteLook (28 million), Animoto (25 million), EyeEm (22 million), 8fit (20 million), Whitepages (18 million), Fotolog (16 million), 500px (15 million), Armor Games (11 million), BookMate (8 million), CoffeeMeetsBagel (6 million), Artsy (1 million), and DataCamp (700.000).
The accounts, according to the Register, appear to be legitimate and consist primarily of names, email addresses, and passwords. The passwords are hashed, or one-way encrypted, so they would have to be cracked before they could be used.
There are also some other data, depending on the breached website the data comes from, such as location, personal details and social media authentication token. No payment data or bank cards appear anywhere.
Dark Web Who are the buyers?
This information is primarily addressed to spam senders. Others can also obtain usernames and passwords to log into accounts on other websites where users have used the same credentials.
Thus, for example, someone who purchases a database from the above sites could decode the weakest passwords that are on the list (the older passwords may have been hashed with the MD5 algorithm) and then attempt to log into Gmail or Facebook accounts with the same passwords.
All the databases are currently being sold separately by a hacker who claims to have breached the websites using web application vulnerabilities.
The seller, who is believed to be located outside the USA, claims that some of the affected websites should be aware of data theft in one way or another and repair their systems.
