Full Report
AWC joins illicit carding business by offering 1 Mln compromised cards for free
Analysis Summary
# Incident Report: Massive Data Leak by "All World Cards" (AWC) Market
## Executive Summary
The newly established illicit carding marketplace "All World Cards" (AWC) released approximately 1,000,000 compromised credit card records for free on underground forums. This action served as a massive promotional campaign to establish credibility and attract users to their new platform. The leak represents a significant volume of stolen financial data, impacting consumers globally and highlighting the sophisticated marketing tactics of modern cybercriminal organizations.
## Incident Details
- **Discovery Date:** August 2021
- **Incident Date:** June 2021 (Market creation) – August 2021 (Data release)
- **Affected Organization:** Multiple financial institutions and card issuers globally
- **Sector:** Finance / E-commerce
- **Geography:** Global (Primary concentrations in the US, India, Brazil, and Mexico)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing (2018–2019 data included)
- **Vector:** Likely a combination of web skimming (Magecart), point-of-sale (POS) malware, and phishing.
- **Details:** The data was collected over several years prior to the leak; AWC claims the cards were stolen between 2018 and 2019.
### Lateral Movement
- **Details:** N/A (The incident refers to the bulk release of data aggregated from various independent breaches rather than a single network intrusion).
### Data Exfiltration/Impact
- **Details:** AWC published a database of 1,000,000 cards. The data included Credit Card Numbers, Expiration Dates, CVV/CVC codes, Names, Countries, States, Cities, Addresses, Zip codes, and Phone numbers.
### Detection & Response
- **How it was discovered:** Group-IB Threat Intelligence monitored underground forums (specifically the "XSS" forum) where AWC advertised the leak.
- **Response actions taken:** Intelligence gathered by security firms was shared with financial institutions to initiate card re-issuance and fraud monitoring.
## Attack Methodology
*Note: The following relates to how AWC likely acquired the data they distributed.*
- **Initial Access:** Web skimming (JS-sniffers) on e-commerce sites and POS malware at brick-and-mortar retailers.
- **Persistence:** Maintaining access to compromised merchant environments.
- **Credential Access:** Scraping payment data directly from browser memory or checkout forms.
- **Collection:** Automated aggregation of stolen card data into centralized Command & Control (C2) servers.
- **Exfiltration:** Transfer of data from merchant servers to carding shop databases.
- **Impact:** Financial fraud, identity theft, and significant promotional growth for the AWC marketplace.
## Impact Assessment
- **Financial:** High potential for fraudulent transactions; 0.27 BTC deposit made by AWC on XSS forum to show solvency.
- **Data Breach:** 1,000,000 cards leaked for free; over 3.8 million cards total uploaded to the AWC shop since June 2021.
- **Operational:** Increased load on bank fraud departments for card cancellation and re-issuance.
- **Reputational:** AWC successfully established itself as a "serious" player in the underground market.
## Indicators of Compromise
- **Network Indicators:**
- `allworldcards[.]com` (Defanged market URL)
- Links to data dumps hosted on encrypted file-sharing services (e.g., Mega[.]nz - *Note: specific links frequently rotate*).
- **Behavioral Indicators:**
- Promotional threads on "XSS" and "Mazafaka" forums by user "AW_cards".
- Distribution of large ZIP/CSV files containing cleartext credit card data.
## Response Actions
- **Containment:** Monitoring of the AWC platform to identify newly uploaded batches.
- **Eradication:** Blocking of associated domains by security vendors and ISPs where possible.
- **Recovery:** Financial institutions proactively flagging and replacing compromised cards listed in the 1M record dump.
## Lessons Learned
- **Market Dynamics:** Cybercriminal entities are using traditional "freemium" marketing models (giving away 1M records) to gain market share.
- **Data Longevity:** Even data stolen years ago (2018/2019) retains value for "carding" and identity theft, despite claims of "freshness."
- **Collaboration:** The actor "AW_cards" is likely an experienced administrator rebranding themselves, showing the fluidity of threat actor identities.
## Recommendations
- **Financial Institutions:** Implement and mandate Multi-Factor Authentication (MFA) or 3D Secure for all online transactions.
- **Merchants:** Regularly audit e-commerce platforms for unauthorized JavaScript (anti-skimming) and ensure POS systems are isolated and encrypted.
- **Consumers:** Enable transaction alerts on all credit/debit accounts and utilize virtual card numbers for online shopping.