Every verified open-source observation, newest first. Each entry feeds the platform pages, the price index and the research registry automatically — verifying an observation recalculates that platform's score and price percentiles.
49 verified observations9 with a disclosed priceLatest: Aug 21, 2026
Submissions are reviewed before publication. Excerpts are sanitized: no seller identities, contact details, invite links, credentials or marketplace locations are stored or shown. Asking prices are not realized prices.
Hundreds of leaked AWS keys give full control over corporate accounts
Researchers examining more than 64,000 unique cloud access keys exposed publicly between 2022 and 2026 found that around 88% of a retested sample still authenticated, and 768 granted full administrative control of a corporate cloud account.
How Uber, DoorDash and Lyft accounts are being rented and stolen online
A broadcast investigation found rideshare and delivery driver accounts openly advertised for rent or sale on mainstream social platforms, allowing people without a valid licence or completed background check to work under someone else's account.
Members Of Conspiracy To Steal More Than $2.5 Million From DoorDash Sentenced
Federal prosecutors announced sentences for five people who created numerous fraudulent customer and driver accounts on a delivery platform to submit phantom orders, obtaining more than $2.5 million in fraudulent payouts.
Infostealer malware database exposes millions of iCloud and email passwords
A researcher found a publicly accessible database of roughly 149 million credential records, of which about 900,000 were Apple iCloud username and password pairs. The records were attributed to infostealer malware rather than a compromise of Apple infrastructure.
Nearly Half of Gig Workers Have Sold, Rented Accounts on Apps Like Uber
Coverage of an identity-vendor survey reported that 45% of gig workers surveyed said they had rented or sold access to a gig-work account, a practice the platforms prohibit.
VVS Stealer Attacking Discord Users to Exfiltrate Credentials and Tokens
Researchers documented credential-stealing malware sold on a subscription basis since 2025 that harvests Discord account tokens, saved credentials, payment methods and session data to enable account takeover.
Researchers found stolen consumer accounts from more than 60 businesses being sold through criminal storefronts operating across chat platforms including Discord, with the credentials obtained largely through credential-stuffing attacks.
A consumer-credit bureau summary of a published dark-web price index lists an average advertised price of 60 US dollars for a hacked Gmail account, against 20 to 25 dollars for a hacked social media account and 1 to 20 dollars for streaming service logins.
Kaspersky: Over 7 million streaming accounts credentials were leaked in 2024
Kaspersky Digital Footprint Intelligence identified more than 7 million compromised credentials tied to major streaming platforms during 2024, with Netflix accounting for the largest single share. The credentials were harvested by infostealer malware campaigns rather than a breach of the platform itself.
UBERMarketplace Listing · Research ReportMedium confidence
For Sale on Facebook: Fraudulent Uber Driver Accounts
A watchdog investigation identified 80 social-media groups with a combined membership of over 800,000 in which rideshare driver accounts were advertised for sale or rent, enabling people to drive under another person's verified identity without passing a background check.
DASHMarketplace Listing · Research ReportMedium confidence
For Sale on Facebook: Fraudulent Uber Driver Accounts
The same watchdog investigation found delivery driver accounts traded alongside rideshare accounts in the groups it identified, with group names openly referencing delivery account rentals.
Instagram Lawsuit Takes Aim at Account Selling, Reinstatement Services
Meta filed a US civil action alleging that an individual had sold Instagram usernames and offered unauthorised account reinstatement services since 2022, in breach of platform terms. Meta described it as its first US legal action of this kind against account-selling services.
A vendor blog reported an underground forum post claiming to offer more than 20 million OpenAI account credentials, with sample data presented as proof. Other forum participants disputed whether the credentials granted account access, and the claimed compromise was never substantiated.
Airbnb 2024 Law Enforcement Response Transparency Report
Airbnb's annual transparency report describes the categories and volumes of law-enforcement requests it received in 2024 relating to user accounts and account data, including legal process, emergency disclosure and preservation requests.
Consumers report tickets transferred out of Ticketmaster accounts without authorisation
Investigative reporting documents multiple consumers whose purchased tickets were transferred out of their accounts without authorisation, indicating demand for accounts holding transferable inventory.
U.S. says Russian bot farm used AI to impersonate Americans
Public radio reporting on the same enforcement action described the AI-assisted operation of fake profiles on the platform and placed it in a wider pattern of state-backed fake-account activity around elections.
Justice Department leads efforts among federal, international and private-sector partners to disrupt covert Russian government-operated social media bot farm
US prosecutors announced the court-authorised seizure of infrastructure behind an AI-assisted bot farm that created and operated close to 1,000 fake accounts impersonating Americans between 2022 and 2024. The platform suspended the remaining accounts.
Observed
Jul 9, 2024
Account type
Synthetic
Geography
Russia (alleged operators); United States (targets)
Ticketmaster breach: leaked credentials are the golden ticket once again
Threat-intelligence analysis attributes access to credentials harvested by infostealer malware and later circulated through underground credential trading.
Miscreants claim they have snatched 560M people's info from Ticketmaster
Reporting describes an unverified underground listing offering a claimed 560-million-record Ticketmaster customer dataset for a reported USD 500,000 lump sum.
FBMarketplace Listing · Research ReportMedium confidence
Facebook Black Market for Ad Accounts Looms Over India Election
Researchers documented users publicly offering to transfer business advertising accounts already authorised to run political ads in India, contrary to platform policy prohibiting account sale or transfer. The researchers did not transact with sellers.
Microsoft said a Vietnamese cybercrime group cracked their CAPTCHA process
A US court authorised the seizure of domains that Microsoft described as a widely used service for buying fraudulent Hotmail accounts in bulk, which were then resold to other criminal operators at scale.
Observed
Dec 14, 2023
Account type
Synthetic
Geography
Vietnam (alleged operators); United States (jurisdiction)
Microsoft disrupts cybercrime operation selling fraudulent accounts to notorious hacking gang
Reporting on the same disruption noted that the fraudulent Outlook accounts were sold through a dedicated service and that a well-known intrusion group was among the buyers, using the accounts to support further attacks.
Microsoft and a fraud-prevention vendor disclosed the disruption of a group that Microsoft estimates created and sold roughly 750 million fraudulent Outlook and Hotmail accounts, together with automated CAPTCHA-solving services, to other criminal groups.
Airbnb says it is cracking down on fake listings and has removed 59,000 of them
Wire-service reporting cited Airbnb disclosing that it removed 59,000 fake listings and blocked a further 157,000 from joining the platform in a single year, as part of automated detection work against fraudulent host accounts.
Know Your Cybercriminal: measuring profile sales on a criminal impersonation market
Academic measurement of a criminal impersonation market recorded 10,193 sold user profiles over 161 days, with estimated trade of up to roughly 700 profiles per day and buyer preference driven by geography and attached resources.
Over 100,000 Stolen ChatGPT Account Credentials Sold on Dark Web Marketplaces
A second outlet, citing the same threat-intelligence dataset, described stolen ChatGPT credentials being traded inside underground log markets under subscription-style access models, most commonly harvested by three named infostealer malware families.
Over 100,000 ChatGPT accounts stolen via info-stealing malware
Reporting on threat-intelligence research found more than 101,000 ChatGPT account credentials appearing in infostealer logs traded on underground marketplaces between June 2022 and May 2023, peaking at roughly 26,800 credential sets in a single month, with Asia-Pacific the most affected region.
Krebs on Security reported on a service that pays people for access to their existing email accounts and then rents that access on to customers who need established mailboxes to complete sign-ups elsewhere in bulk. Renters receive only the verification messages, not full control of the mailbox, which is described as a way of monetising aged, reputable email addresses.
Secure Your Netflix Account: Limited Sharing Can Result in Dark Web Sales for EUR 2 per Month
Check Point Research observed channels advertising monthly access to Netflix Premium plans at very low prices, describing the accounts as sourced from compromised credentials rather than legitimate resale. Researchers noted buyers frequently lost access after a short period, indicating unreliable fulfilment.
A Growing Goldmine: Your LinkedIn Data Abused for Cybercrime
Vendor research reports that once LinkedIn accounts are compromised, the credentials are shared, sold and packaged within cybercriminal underground communities.
Keys to the Kingdom: compromised corporate webmail as an attack vector
Threat-intelligence research documents dedicated shops selling access to compromised webmail accounts, reporting an average advertised price of about USD 25 for a single webmail account.
Random people are being bombarded with unwanted Amazon packages after having their identities stolen by fraudulent Amazon merchants
A companion investigation documented cases in which sellers registered new marketplace seller accounts using stolen personal identities, bypassing identity-verification checks.
There is an underground market where secondhand Amazon merchant accounts are bought and sold for thousands of dollars
An investigation documented a grey market in secondhand marketplace seller accounts traded through chat channels and account-swapping forums, with established accounts reportedly changing hands for thousands of dollars and sometimes used to evade seller bans.
This salesperson does not exist: GAN-image fake LinkedIn profiles used for lead generation
Peer-reviewed study identified 1,003 fake LinkedIn profiles using AI-generated portrait images and outsourced account management for commercial lead generation.
SMS PVA: An Underground Service Enabling Threat Actors to Register Bulk Fake Accounts
Trend Micro documents services that resell one-time SMS verification codes so that buyers can register accounts in bulk on major platforms including Google. The researchers found one such service drawing its numbers from a botnet of thousands of compromised Android handsets whose owners were unaware their devices were intercepting verification messages.
Google's Threat Analysis Group disclosed action against a botnet of roughly one million Windows machines whose operators stole Google account credentials and ran ancillary criminal services, including one selling access to systems pre-loaded with stolen credentials. Google terminated the associated accounts and cloud projects and filed civil litigation against the operators.
Google LLC v. Starovikov and Filippov — civil complaint (S.D.N.Y.)
Google's civil complaint alleges the defendants operated a botnet that harvested Google account login credentials at scale and monetised that access through paid criminal services, including the sale of access to machines loaded with stolen credentials. The filing is a court record of alleged account-market activity rather than a marketplace listing.
Your Gmail is worth more than a bank account on the dark web
Reporting on a published dark-web price index covering listings captured up to May 2021, which recorded an advertised price of 80 US dollars for a compromised Gmail account — higher than the figures the same index recorded for cloned payment cards or for online banking logins holding at least 100 dollars.
Facebook, Instagram, TikTok and Twitter Target Resellers of Hacked Accounts
Facebook stated it removed hundreds of accounts linked to a forum whose members traded hijacked accounts and short, high-value usernames obtained through hacking, coercion and SIM-swapping, with intermediaries taking a percentage cut of resale transactions.
Facebook, Instagram, TikTok and Twitter Target Resellers of Hacked Accounts
The platform joined a coordinated enforcement action against members of a forum functioning as a marketplace for hijacked accounts and rare usernames, some obtained through SIM-swapping and extortion.
Facebook, Instagram, TikTok and Twitter Target Resellers of Hacked Accounts
The platform stated that hundreds of hijacked accounts, primarily on Instagram, were reclaimed from members of a username-trading forum, describing an escrow-based resale ecosystem focused on short, high-value Instagram usernames.
A mid-year update to a recurring darknet price index recorded a sharp rise in advertised prices for hijacked Airbnb account credentials in the UK sample, alongside increases across other travel and payment account categories.
A recurring darknet price index tracked listings for hijacked streaming accounts, including Netflix, across multiple marketplaces and reported year-over-year movement in advertised prices for this account category.
The same recurring darknet price index reported a year-over-year decline in advertised prices for Apple ID accounts, which the authors read as softening demand relative to other brands in the sample.
Shady Marketplaces Selling Fake Facebook Profiles Operate In Plain Sight
A journalist documented purchasing a single fabricated Facebook profile, supplied with a constructed posting history and personal details, from a foreign-language site for a small cryptocurrency payment.
Criminals pay just $15 for Apple iCloud account IDs, report claims
Reporting on a darknet price study found that compromised Apple ID and iCloud accounts were among the most highly valued non-financial account types listed on several marketplaces, with an average advertised price of about $15, behind only banking and payment credentials.
An investigation described a large-scale operation manufacturing engagement and follower accounts aimed primarily at Instagram, with production concentrated in South and Southeast Asia. Revenue and volume figures were the operator's own unverified claims.
Google researchers working with university partners studied the market for phone-verified Google accounts, obtaining 4,695 such accounts from underground sellers and analysing roughly 300,000 phone-verified accounts Google had disabled for abuse. Sellers depended heavily on free internet-telephony numbers and short-lived numbers concentrated in a small number of countries, and the paper reports advertised prices for Google phone-verified accounts falling by 30 to 40 percent as that number supply spread.
Market activity is an external indicator of abuse incentives, not a measurement of fraudulent accounts on the underlying platform. Prices are never inferred — an observation without a published figure is recorded without one. See the methodology for scoring and confidence rules.