Full Report
The rise and fall of illicit cardshop breached twice in two years
Analysis Summary
# Incident Report: The Breaches of Swarmshop Carding Market
## Executive Summary
Swarmshop, a prominent illicit underground marketplace for stolen payment cards, suffered two major data breaches between 2020 and 2021. In both instances, the site's database was leaked on competing underground forums, exposing the records of both administrators and users. These incidents highlights the lack of "honor among thieves" and the significant growth of the illicit carding economy despite internal security failures.
## Incident Details
- **Discovery Date:** January 2020 and March 2021
- **Incident Date:** Ongoing (2019–2021)
- **Affected Organization:** Swarmshop (Illicit Marketplace)
- **Sector:** Cybercrime / Underground Economy
- **Geography:** Global (Users and victims worldwide)
## Timeline of Events
### Initial Access
- **Date/Time:** Approximately January 2020 (1st breach); March 2021 (2nd breach).
- **Vector:** Targeted attacks on the shop's web infrastructure/database.
- **Details:** In the 2021 breach, a user on a competing forum posted a link to the Swarmshop database, containing the site's entire record set.
### Lateral Movement
- **Details:** The attackers gained administrative-level access to the web server's database, allowing for a full dump of SQL tables.
### Data Exfiltration/Impact
- **Data Stolen:** 12,344 records of card shop users (nicknames, hashed passwords, contact details, activity history, and unspent balances).
- **Card Data Exposed:** Over 623,000 payment card records (US, Canada, UK, China, Singapore, France, Germany, Brazil, Mexico, etc.).
- **Other Data:** 498 sets of online banking credentials and 69,592 sets of Social Security Numbers (SSNs) and Canadian Social Insurance Numbers (SINs).
### Detection & Response
- **Detection:** Discovered by Group-IB researchers monitoring underground forums where the leaked databases were advertised.
- **Response Actions:** Group-IB notified relevant national CERTs and financial institutions to mitigate the impact of the stolen payment data.
## Attack Methodology
- **Initial Access:** Likely web application vulnerabilities (e.g., SQL injection or unauthorized access to the database management interface).
- **Persistence:** Not explicitly stated, though the repeated nature suggests unpatched vulnerabilities.
- **Credential Access:** Hashed passwords for all users were obtained during the database dump.
- **Collection:** Automated scripts or SQL queries to aggregate user balances and card inventory.
- **Exfiltration:** Database dumps uploaded to public file-sharing services and linked on hacker forums.
- **Impact:** Complete exposure of the site’s internal operations, financial records, and "buyer/seller" identities.
## Impact Assessment
- **Financial:** Total unspent user balances reached $18,145 at the time of the 2021 leak. Administrator monthly profit estimated at $5,300.
- **Data Breach:** Compromise of 623,000+ payment cards and 69,000+ PII records.
- **Operational:** The shop's reputation was severely damaged, and its growth was hampered by the exposure of its user base.
- **Reputational:** Public "doxxing" of cybercriminals by their peers.
## Indicators of Compromise
*(Note: As this was a breach of an illicit site, indicators represent the site itself and the leak source)*
- **Network Indicators:** `swarmshop[.]ru` (defanged)
- **Behavioral Indicators:** Large SQL dumps posted on forums like XSS or Exploit[.]in; sudden spikes in "card testing" activity following a leak.
## Response Actions
- **Containment:** None by the shop itself; the leak was public.
- **Eradication:** Group-IB identified the leaked card numbers.
- **Recovery:** Financial institutions were advised to block and reissue cards identified in the breach.
## Lessons Learned
- **No Honor Among Thieves:** Cybercriminals frequently target each other to eliminate competition or steal funds.
- **Poor Operational Security (OpSec):** Even criminal platforms fail to secure their databases against common web attacks.
- **Visibility is Key:** Monitoring underground forums provides early warning for financial institutions to protect their customers before stolen cards are used.
## Recommendations
- **For Financial Organizations:**
- Implement advanced Threat Intelligence to monitor for leaked BINs (Bank Identification Numbers).
- Proactively block and reissue cards found in underground database dumps.
- Educate customers on monitoring their statements for small, unauthorized "testing" transactions.
- **For Security Teams:**
- Use compromised credential monitoring to ensure employees are not using the same passwords on personal accounts that may have been part of the Swarmshop buyer list.