Stolen account credentials: an empirical comparison of online dissemination on different platforms

Publication date

2019-10-20

Authors

Madarie, Renushka
Ruiter, StijnISNI 0000000369949794
Steenbeek, W.ISNI 000000039485296X
Kleemans, Edward

Editors

Advisors

Supervisors

Document Type

Article
Open Access logo

License

Abstract

Account hijacking, i.e. illegitimately accessing someone else’s personal online account, is on the rise and affects not only financial accounts, but the full spectrum of online accounts. To gain more insight in the illicit act of online dissemination of stolen account credentials, we systematically examined how such credentials were offered on three different types of online platforms where stolen credentials were disseminated and how offers varied by platform. We used web scrapes of these platforms for our comparative analyses. Our results demonstrate variation by platform in the type of information on accounts and account holders offered, the average asking price for credentials, and rules and services following a transaction. We conclude with policy implications and suggestions for future research based on the criminal event perspective.

Keywords

criminal event perspective, illicit online markets, Stolen account credentials, web scrapes, Law

Citation

Madarie, R, Ruiter, S, Steenbeek, W & Kleemans, E 2019, 'Stolen account credentials : an empirical comparison of online dissemination on different platforms', Journal of Crime and Justice, vol. 42, no. 5, pp. 551-568. https://doi.org/10.1080/0735648X.2019.1692418