Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Inforstealers. Show all posts

Tanaka Emerges as Leading Data Leak Broker as Stolen Information Fuels Cybercrime

 

Ransomware attacks are undoubtedly one of the most notorious security threats today. Yet it seems that information itself has become a very popular target among cybercriminals. Particularly, the threat actor called Tanaka has appeared to be the most successful data dealer during the first half of 2026, according to the research conducted by Cyble. Overall, 367 confirmed cases of corporate data leaks or breaches happened worldwide during the first half of 2026, the experts from Cyble have found. 

While the activity of Tanaka appeared to be less prominent than that of many well-known ransomware groups, he has been the most active data dealer according to Cyble research. His activity has resulted in 25 leak posts, which is more than double than the number of posts of other famous data-leak organizations. The threat actor has been targeting organizations in various fields, pursuing different goals. While the Banking, Financial Services and Insurance sector remained the most attractive for criminals with 38 data breach incidents recorded, governments and technology companies have also been frequently targeted by Tanaka. 

It implies that data theft is no more limited by regional or economic factors and can happen to organizations of any size or any industry. In particular, Tanaka has been very active in North America, where 7 leak posts related to the criminal have been discovered this year. Meanwhile, Europe and the UK have witnessed 6 leak posts related to Tanaka, as well. In these regions, financial services, telecom, and retail companies have experienced the most significant challenges, as customer and financial data of these organizations are highly attractive to data prospectors. 

In general, data prospecting has become a significant threat to organizations worldwide, as there are now more opportunities to benefit from the data belonging to other organizations. It is a part of the ransomware attack chain, as ransomware criminals can use the data belonging to the victim as leverage to demand more significant ransoms. However, data extortion is not the only way to monetize data theft, as leaked databases can be further sold on dark web forums and marketplaces. 

In addition, the stolen data can be used for extortion, reconnaissance, and other nefarious purposes. It is necessary for companies to realize that the detection of one’s data being sold or showcased on underground forums should be treated as a serious security incident. It can be a sign of the potential ransomware attack, which should be responded to accordingly. Monitoring the dark web for signs of reconnaissance activities is one of the essential aspects of cybersecurity, which is why professionals may want to consider detecting their organization’s potential exposure to ransomware attackers.

100K+ ChatGPT Login Credentials Leaked to the Dark Web


A Singaporean cybersecurity company discovered that over the last few year, login credentials of more than 100,000 online users using chatbot like ChatGPT has been leaked and traded in the Dark Web.

According to the security researchers, infostealers illicitly acquire collect just anything, be it information of a target machine, cookies and browser history, documents and so on. Hackers frequently make money off of this kind of bounty by reselling it on the Dark Web as well as using it themselves. For instance, logs containing the user names and passwords of victims for some popular applications are frequently transmitted to online markets.

According to a blog post by cybersecurity firm Group-IB published on June 20, over 101,000 devices with compromised logins for OpenAI's flagship bot and were later traded on the Dark Web.

The aforementioned figure is apparently is “the number of logs from stealer-infected devices that Group-IB analyzed,” according to Dmitry Shestakov, Group-IB threat intelligence head.

“Every log contained at least one combination of login credential and password for ChatGPT,” he added.

A peak was apparently seen in May last year, where nearly 27,000 ChatGPT-related information was made available on the illegal marketplaces.

Less than 5,000 infected devices out of the whole sample size could be tracked back to North America. The two countries with the highest percentage of Asian origins were India (12,632) and Pakistan (9,217). Brazil (6,531), Vietnam (4,771), and Egypt (4,558) were other nations where a large number of ChatGPT credentials were disclosed.

However, compromised ChatGPT logins may well be the tip of the iceberg, since the cases of Web stealers are on a constant surge.

The researchers monitored 2,766 Dark Web stealer logs including compromised accounts in December of last year, the first month ChatGPT was made available to the general public. The following month, it went over 11,000, and two months later, doubled. The figure increased to 26,802 by May.

To conclude, this trendline is obviously jutting in one direction.

However, according to senior technical engineer at Vulcan Cyber, Mike Parkin, "Infostealers can be an issue, at least in part, because they're not as outwardly destructive as, say, ransomware, which is hard to miss. A well obfuscated infostealer can be much harder to detect, precisely because it doesn't make itself known." Reason being, its more likely for firm to ignore than some other types of malware, where they are likely to discover their sensitive data has been stolen only after it is too late.