2022 CRIF Cyber Observatory - First semester

2022-09-25
2022 CRIF Cyber Observatory  - First semester

In the first half of 2022, we saw an increase in compromised account credentials, in combination with other extremely valuable data for hackers.

The number of alerts sent on the dark web was over 780.000 in the first half of 2022 and grew by +44.1% compared to the second half of 2021.

The number of alerts sent on the open web was over 70,000 in the first half of 2022 and fell by -4.9% compared to the second half of 2021.

In total, more than 850,000 alerts were sent in the first half of 2022, mainly related to data found on the dark web.

In particular, the address has become a valuable personal data because it allows you to complete the victim's profile and geolocate it.

The address is often found along with other information (such as the victim's first and last name) and contact details (email or phone number).

For example, in the first half of 2022, the full postal address was found in combination with a phone number in 70% of cases, this exposes the victim to receive more credible fraudulent messages, such as those of fake couriers to notify the delivery of a package.

Often these smishing messages (SMS phishing) contain malicious links that cause the victim to click and provide additional data to fraudsters.

 

Which are the most vulnerable data on the web?

There are several categories of data that are subject to attack; however, we have observed that email addresses, passwords, telephone numbers, usernames and postal addresses mainly circulate on the dark web and are therefore most vulnerable.

Compared to the last semester, the postal address enters the top 5, the telephone number exceeds the username and the email address rises to the top of the ranking.

TOP 5 MOST VULNERABLE DATA

I semester 2022

Email

Password

Phone number

Username

Postal address

 Data Source Provider: Cyber CRIF Observatory

Even more interesting is to observe the main combinations of data found: very often emails are associated with a password (88.1% of cases); as well as together with usernames, passwords appear very often (79.9%).

As far as personal data are concerned, the name and surname are often associated with the telephone number (52.2%) up by +251% compared to the second half of 2021, a valuable data for fraudsters, especially in the case of Smishing or SIM Swapping.

The phone number plays a fundamental role in these cases and, when also associated with the password (33.7%), the vulnerability of the victim increases.

With regard to credit card data, very frequently in addition to the card number there are also cvv and expiration date (95.9% of cases), with an increase of +8%.

Key data combination

II semester 2021

I semester 2022

change %

Email + Password

90,8%

88,1%

-3%

Phone number + password

81,6%

33,7%

-59%

Username + Password

86,6%

79,9%

-8%

Phone number + Name and Surname

14,8%

52,2%

+251%

Credit card + CVV e Expiry date

88,6%

95,9%

+8%

Data Source Provider: Cyber CRIF Observatory

 

Email accounts

I semester 2022

II semester 2021

change %

Personal

91,6%

77,9%

+17,6%

Business

8,4 %

22,1%

-62,0%

 Data Source Provider: Cyber CRIF Observatory

  

Most frequently circulating accounts on the Dark Web

 Amongst the most frequently circulating accounts on the dark web, the names of email services, dating sites, social networks and online games have emerged.  

TOP 10 account

Type

1

Yahoo

E-mail

2

Gmail

E-mail

3

MyHeritage

Family tree

4

Badoo

Dating site

5

Mail.ru

E-mail

6

Facebook

Social

7

Zynga

Online games

8

Dofus

Online games

9

LinkedIn

Social

10

Twitter

Social

Data Source Provider: Cyber CRIF Observatory

 

Most common stolen passwords on dark web

 The analysis of the passwords detected makes us reflect on the vulnerability of the accounts with which they are associated. In the top 10 passwords in circulation in the first half of 2022 we found the following:

TOP 10 I semester 2022

1

123456

2

123456789

3

password

4

qwerty

5

12345

6

12345678

7

qwerty123

8

1q2w3e

9

111111

10

1234567890

Data Source Provider: Cyber CRIF Observatory

These passwords are in order to be the most popular and therefore most compromised on the dark web and can be hacked in an average time of less than a second. In first place in the top 10 is "123456", a password very common in dark web environments during the first half of 2022, on the podium with "123456789" and "password", followed by "qwerty".

In the first half of 2022 in the list of the most common passwords appear "iloveyou" and "secret". Other common passwords include simple words like "dragon," "princess," "football," and "sunshine," proper names like "daniel," "michael," and "charlie," names referencing games like "pokemon," characters like "superman," and easy-to-guess number combinations, or repetitions like "111111."

While using simple passwords might seem like a practical way to help users remember them, it also leads to a high security risk for users and their systems.

As you can see by scrolling through the ranking, the most frequently detected passwords on the dark web are very simple combinations of numbers and letters, so it is very easy for hackers to discover them. On the other hand, the use of these passwords reveals the lack of awareness of web users, who often ignore the most basic rules to protect themselves from intrusions.

 

Ranking of the most detected email by domains and countries mostly hit by the phenomenon

 The ranking of the most detected emails on the dark web, with regards to the composition of the domains, allows us to locate the email provider, with the exception of the ".com" and ".net", commonly used worldwide.  The domain .com, in addition to being global, is also the most used in the USA. It can therefore be deduced that the countries most affected by the phenomenon of online email and password theft are US, Russia, Germany and France, followed by United Kingdom, which is just ahead of Italy. The other countries that complete the top 10 of the domains most affected in online password theft are Poland, Japan, Brazil, the Czech Republic which enters the ranking of the most affected countries surpassing Canada.

The .edu domain, widespread among schools, colleges and universities, also circulates widely on the dark web; this means that numerous email addresses of students and professors are exposed to cyber risk.  Even the .org domain, noteworthy as it refers to non-profit organizations and institutions, gains positions from 19 to 13th position.

The table below shows the ranking of the most detected domains and the most affected countries:

TOP 20 I semester 2022

1

.COM .NET global and USA

2

.RU Russia

3

DE Germany

4

.FR France

5

.UK United Kingdom

6

.IT Italy

7

.PL Poland

8

.JP Japan

9

.BR Brazil

10

.CZ Czech republic

11

.EDU

12

Canada

13

.ORG

14

India

15

Ukraine

16

Spain

17

Taiwan

18

China

19

Australia

20

Netherlands

 Data Source Provider: Cyber CRIF Observatory

Misuse of the most detected accounts

Stolen credentials can be used for a variety of purposes, such as to break into victims' accounts, misuse services, send emails with requests for money or phishing links, send malware or ransomware, for the purpose of extorting or stealing money. Through a qualitative analysis of the contexts in which the data circulates, the accounts have been categorized according to the purpose of use.

Most of the accounts detected are related to email mailboxes (27.0%) followed by entertainment sites (21.0%), mainly  related to online gaming and dating accounts (online dating sites). In third place, the theft of forum accounts and websites of paid services (18.6%) and social media (13.9%) is highlighted. A fair part of the stolen accounts  can be ascribed to e-commerce platforms (12.3%), up by +132% compared to the previous semester.

The risk of theft of such accounts can have direct economic consequences for victims.

Most detected account

I semester 2022

Email accounts

27,0%

Entertainment

21,0%

Forum and website

18,6%

Social Media

13,9%

Ecommerce

12,3%

Other services

7,2%

Data Source Provider: Cyber CRIF Observatory

 

 Where is more credit card data obtained?

The ranking of the continents most subject to illicit credit card data exchange is lead by North America, followed by Asia which surpasses Europe, while Africa surpasses South America. At the bottom of the ranking we find Oceania, with a significant % growth compared to the previous period.

Continent

I semester 2022

change %

North America

40,1%

-27%

Asia

26,3%

+97%

Europe

14,1%

-33%

Africa

8,8%

+183%

South America

5,5%

+76%

Oceania

5,2%

+304%

Data Source Provider: Cyber CRIF Observatory

 The ranking of the countries most subject to credit card data exchange sees the United States, Russia, the United Kingdom, Brazil and Canada in the lead. In particular, Russia raised 9 positions compared to the second half of 2021.

Even more evident is Ukraine position, previously ranked 92° while entering now amongst the the top 20.

The ranking includes:

TOP 20 - I semester 2022

1

USA

2

Russia

3

UK

4

Brazil

5

Canada

6

India

7

France

8

Spain

9

Japan

10

China

11

Germany

12

Australia

13

Ukraine

14

Italy

15

Argentina

16

South Korea

17

Poland

18

Mexico

19

Chile

20

Turkey

Data Source Provider: Cyber CRIF Observatory

 

Focus: Top 3 countries by continent

 Below are the rankings of the countries most subject to credit card data exchange for each continent:

 

TOP 3 Africa I semester 2022

1

South Africa

2

Egypt

3

Nigeria

   

TOP 3 America I semester 2022

1

USA

2

Canada

3

Mexico

   

TOP 3 Asia I semester 2022

1

India

2

Japan

3

China

   

TOP 3 Europe I semester 2022

1

Russia

2

UK

3

France

   

TOP 3 Oceania I semester 2022

1

Australia

2

New Zeland

3

Guam

 Data Source Provider: Cyber CRIF Observatory

 

About CRIF Cyber Observatory

The Cyber Observatory aims to analyze the vulnerability of people and companies to cyber-attacks and interpret the main trends concerning the data exchanged in Open Web and Dark Web environments, the type of information, the areas in which data traffic is concentrated and the most exposed countries.

In addition, the Cyber Observatory aims to highlight the risks to which individuals and businesses are exposed on a daily basis, evaluate the main trends and offer some ideas to face cyber risk.

The data are the result of an analysis and study activity carried out on the web environments where data are shared and exchanged. These are not only websites but groups, forums and specialized communities of the so-called "Dark Web". But what do we mean by the dark web and how does it work?  The Dark Web is a set of web environments that do not appear through normal Internet browsing activities and requires some specific browsers or targeted searches. Precisely because of its nature, it is exploited by hackers to exchange data, obtained through phishing activities or other types of attacks.

H1 2022 - Cyber Observatory

Related news

CRIF Cyber Observatory - 2022 Yearly Report
CRIF Cyber Observatory - 2022 Yearly Report
2023-05-03

Credit cards are in the sights of cyber criminals Over the past year, more than 1.6 million alerts were sent relating to data found on the dark web. Alerts relating to phone numbers combined with first and last names on the rise: +4.4%. The majority of hacked accounts relate to entertainment (mainly online gaming and dating) (37.2%), but breaches of social media accounts increased significantly (+125.8%).

Read more
CRIF Cyber Observatory - 2023 Yearly Report
2024-03-18

Cyber-attacks in 2023: 45% increase in data theft on the dark web. Over 7.5 billion pieces of information circulating on the dark web at a global level, with a 15.9% increase in reports. The techniques used by cybercriminals are becoming increasingly sophisticated: with the malicious use of artificial intelligence, it is getting harder and harder to distinguish between genuine and bogus communications.

Read more
Top 5 Ransomware Attacks of 2022 | White Blue Ocean
Top 5 Ransomware Attacks of 2022
2023-01-16

Ransomware attacks show no signs of slowing down. Discover 5 of the most severe attacks that occurred in 2022.

Read more

Contacts

Let's talk

Please fill in the form below (fields with * are mandatory) and we will respond to your request as soon as possible!