InfoPathways is thrilled to announce our new Small Business Partnership with the Baltimore Ravens....
How is Data Bought and Sold by Cybercriminals?
Take a minute to imagine a cyberattack happening at your business. What comes to mind? A dramatic scene of a hacker alone in a dark room somewhere breaking through a firewall in real time? A shadowy network of criminals straight out of from some 90s movie like Hackers or the Matrix?
The reality is far more methodical... and probably not exciting enough to make it to the big screen. The groundwork for most attacks is laid weeks or months in advance, quietly, using credentials and personal data that were stolen, packaged, and sold long before anyone fires a single line of malicious code. Every day, the amount of personal data available for sale) grows not just in volume and structure. As collection expands, so does the infrastructure to sort, link, sell, and analyze it, making personal information more accessible, more interconnected, and more actionable than ever before.

Telegram
The clear web, meaning the ordinary indexed internet, plays a role in cybercrime that's easy to underestimate. Most people associate stolen data with dark web markets, and while those markets are real and active, they represent only one corner of a much larger ecosystem where threat actors buy, sell, share, and exploit compromised information. Telegram, a cloud-based messaging app, has become one of the most active channels for credential trading and malware distribution. A major 2026 Cambridge/Carnegie Mellon study monitored 1,500 Telegram channels over a year, collecting 14 million messages and 3.6 million shared files where stolen. Credentials, card details, and personal info were sold.
So why as an instant messaging app comparable to WhatsApp or Discord attracting he attention of tens of thousands of cybercriminals? Because Telegram requires minimal verification to join and offers end-to-end encryption, making it the perfect place for activity that once required navigating hidden services on the Tor network. The barrier to entry for a would-be attacker is lower than it has ever been. Dedicated channels and private groups operate openly on the platform, sharing stealer logs, leaked databases, combo lists, and access to compromised systems in real time.
Forums and Blogs
Other stand-alone hacker forums and communities, ranging from invitation-only cybercrime boards to semi-public forums accessible through standard browsers, serve as the research and development layer of the criminal ecosystem. Some forums have been operating for over a decade and maintain reputations for the reliability of what is sold there. Many of these sites, like the Russian Anonymous Marketplace (RAMP), have been found and seized by the FBI. But many of them still exist, dodging federal regulations by headquartering offshores and operating on both the dark and clear web.

Ransomware groups also operate their own public-facing leak sites, sometimes called "shame blogs," hosted on both the dark web and, in some cases, the clear web. These sites are used as extortion leverage, with operators threatening to publish stolen data if a victim refuses to pay. In practice, they also function as an inadvertent intelligence resource, cataloguing breached organizations, the types of data taken, and the sectors being targeted most aggressively. Security researchers monitor these sites closely, and so do other criminal groups looking for targets of opportunity.
The Dark Web Marketplace
Dark web markets do still play a central role in the data brokerage side of the ecosystem. Initial access brokers, a specific class of threat actor, specialize in compromising organizations and then selling that verified network access to ransomware groups and other operators. Stolen credentials are listed like products, complete with pricing tiers based on the type of account, the organization it belongs to, and how recently it was verified as active. A set of corporate VPN credentials fetches more than a generic email login. Domain administrator credentials can fetch hundreds of dollars per record. Bulk datasets containing thousands of employee usernames and passwords are sold at a discount to buyers who run automated attacks at scale.
Breach databases are also compiled and re-listed over time. An email and password combination exposed in a breach from three years ago may still be valid today if the employee never changed their password, which is far more common than most IT teams want to admit.
.
How are Credentials Typically Exposed In the First Place?
Employees use the same email addresses and password patterns across personal and professional accounts constantly. A breach at a retail site, fitness app, or streaming service can expose credentials that an employee also uses for their work email or company VPN. Your organization's security posture can be undermined by a breach you had no part in and no way to directly prevent. Small and mid-sized businesses are disproportionately affected because they typically lack the security staffing to monitor threat intelligence feeds or dark web activity on their own. Larger enterprises have dedicated threat intelligence teams. Most growing businesses do not.
Our Dark Web Monitoring Breaks the Chain
Dark web monitoring tools continuously scan underground forums, marketplaces, paste sites, and breach databases for data tied to your organization, looking for your company domain, employee email addresses, and other identifiers that would signal an exposure. The value of this capability is not that it prevents the original breach (which may have occurred at a third party). The value is that it dramatically shortens the window between exposure and response. InfoPathways uses NordStellar as part of its security toolkit to provide exactly this kind of visibility for clients.