Every verified open-source observation, newest first. Each entry feeds the platform pages, the price index and the research registry automatically — verifying an observation recalculates that platform's score and price percentiles.
7 verified observations0 with a disclosed priceLatest: Aug 21, 2026
Submissions are reviewed before publication. Excerpts are sanitized: no seller identities, contact details, invite links, credentials or marketplace locations are stored or shown. Asking prices are not realized prices.
Hundreds of leaked AWS keys give full control over corporate accounts
Researchers examining more than 64,000 unique cloud access keys exposed publicly between 2022 and 2026 found that around 88% of a retested sample still authenticated, and 768 granted full administrative control of a corporate cloud account.
Infostealer malware database exposes millions of iCloud and email passwords
A researcher found a publicly accessible database of roughly 149 million credential records, of which about 900,000 were Apple iCloud username and password pairs. The records were attributed to infostealer malware rather than a compromise of Apple infrastructure.
VVS Stealer Attacking Discord Users to Exfiltrate Credentials and Tokens
Researchers documented credential-stealing malware sold on a subscription basis since 2025 that harvests Discord account tokens, saved credentials, payment methods and session data to enable account takeover.
Kaspersky: Over 7 million streaming accounts credentials were leaked in 2024
Kaspersky Digital Footprint Intelligence identified more than 7 million compromised credentials tied to major streaming platforms during 2024, with Netflix accounting for the largest single share. The credentials were harvested by infostealer malware campaigns rather than a breach of the platform itself.
Ticketmaster breach: leaked credentials are the golden ticket once again
Threat-intelligence analysis attributes access to credentials harvested by infostealer malware and later circulated through underground credential trading.
Microsoft disrupts cybercrime operation selling fraudulent accounts to notorious hacking gang
Reporting on the same disruption noted that the fraudulent Outlook accounts were sold through a dedicated service and that a well-known intrusion group was among the buyers, using the accounts to support further attacks.
Over 100,000 Stolen ChatGPT Account Credentials Sold on Dark Web Marketplaces
A second outlet, citing the same threat-intelligence dataset, described stolen ChatGPT credentials being traded inside underground log markets under subscription-style access models, most commonly harvested by three named infostealer malware families.
Market activity is an external indicator of abuse incentives, not a measurement of fraudulent accounts on the underlying platform. Prices are never inferred — an observation without a published figure is recorded without one. See the methodology for scoring and confidence rules.