With more and more credit card theft incidents happening every day, it's only natural to wonder where these cards. We know that most of them are sold on the Dark Web, but how does this happen?

Your credit card information can be stolen in two ways: after a data breach, such as the Capital One incident that affected 106 million customers , and through so-called e-skimming, where hackers insert JavaScript code into a website's payment processing pages in order to steal credit card and account information from customers.
During the holiday season, cybercriminals turn to electronic skimming, according to Greg Foss, Senior Cybersecurity Strategist at VMware Carbon Black.
“Magecart is one of the most prominent criminal groups behind this activity,” said Mr. Foss.
Recently, Magecart has been impersonating legitimate payment requests using homoglyph attacks. It created a website called “g00gle.com” instead of google.com, which tricks victims into visiting the malicious website, Foss explained.
Cybercriminals then sell the stolen credit cards, which cost an average of $10 to $20 on the Dark Web. PayPal accounts cost from $2 to $10 per account, with accounts holding more money costing even more.

Stolen credit card data is usually offered in the form of a shopping cart, where the “shopper” can check which credit cards they want to purchase based on a menu of available credentials.
These credentials often include social security numbers and dates of birth. “While there are other services that specialize in data collection and resale, many forums also provide this information in conjunction with credit cards,” said Mr. Foss.
In 2019, cybercriminals sold more than 30 million credit card records on the Dark Web, linked to a data breach at US gas stations.
This breach, caused by an attack that compromised POS devices, went undetected for nine months. It affected 860 stores, 600 of which were also gas stations.
Another ominous trend in credit card theft is ransomware. Criminals in these cases will try to secure a ransom payment after they have already stolen data and are putting it up for sale, according to Mr. Foss. “We have seen these methods used in the final stages of an attack as a means of masking the criminal’s identity and maximizing profitability.”
