Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Access To Thousands Of Breached Sites Found On Underground Market.

by The Gurus
November 8, 2018
in News
Flashpoint Logo
Share on FacebookShare on Twitter

Access to approximately 3,000 breached websites has been discovered for sale on a Russian-speaking underground marketplace called MagBo. Access to some of the sites is selling for as low as 50 cents (USD).

Analysts at Flashpoint who discovered the availability of access to the breached sites said that most of the victims come from ecommerce, while other victims in industries such as healthcare, legal, education, insurance, and government agencies were also found.

A number of the available servers investigated by Flashpoint led analysts to conclude that most of the breaches are from either U.S., Russian, or German hosting services. This particular market is populated by a more than a dozen vendors and hundreds of buyers who sell and take part in auctions in order to gain access to breached sites, databases, and administrator panels.

Flashpoint has shared its findings with law enforcement, which is working to notify victims.

Access to Breached Sites an Uneasy Trend
Illicit access to compromised or backdoored sites and databases is used by criminals for a number of activities, ranging from spam campaigns, to fraud, or cryptocurrency mining. These compromises have also been used to gain access to corporate networks. This could potentially allow actors to access proprietary internal documents or resources, as well as entry points through which they can drop various malicious payloads. The types of vulnerabilities present and the ways in which they can be exploited depend on the threat actor’s specific capability, motivation, targeting, and goals.

This is an uneasy trend that may have manifested itself already in a few high-profile publicly disclosed incidents. A recent well-publicised breach, for example, involved custom-built infrastructure, according to researchers at RiskIQ, allowing the attackers to avoid detection and compromise the data of 380,000 customers. Such an attack likely required compromised access and the ability to manipulate site content and inject code in order to steal customer data.

Today, a month-long breach at a computer retailer was disclosed. Attackers were able to inject code into the retailer’s site that sniffed for payment card numbers. In both breaches, researchers at RiskIQ and Volexity said the Magecart hacking group was behind the attacks.

MagBo a Recent Development on the Underground
Flashpoint analysts said the earliest advertisements for the MagBo market were posted in March to a top-tier Russian-language hacking and malware forum. The threat actor offered the market as a destination for sales of access to breached sites. Posts advertise access to websites that were breached via:

PHP shell access
Hosting control access
Domain control access
File Transfer Protocol (FTP) access
Secure Socket Shell (SSH) access
Admin panel access
Database or Structured Query Language (SQL) access

Potential customers will also find descriptions of the privilege levels available from the market, with labels such as “full access permissions,” “abilities to edit content,” and “add your content.”

In addition to access to breached websites, this particular market also sells stolen photocopies of national documents for identity fraud, breached payment wallet access, compromised social media accounts, and Bitcoin mixer or tumbler services.

Prices for compromised websites range from $0.50 USD to $1,000 USD per access, depending on a website ranking listing various host parameters. These parameters allow the buyer to purchase the exact breach they need depending on the website value as determined and checked by the store.

High-value targets would obviously fetch a higher price and capabilities to inject payment card sniffers or other tools for deeper network penetration. Sites with a lower ranking and a lesser perceived value are more likely to be abused for cryptocurrency mining or spam delivery.

Pre-emptive measures to protect against website exploitation include conducting audits and reviews of any externally accessible websites and their connections to any organisation networks.

[tpr-boilerplate company=’null’]

ShareTweet
Previous Post

Green Element Removes Barriers To Greener Business Operations With Innovative New Carbon Footprint Calculator.

Next Post

Businesses Are Future-Proofing Security Controls As Regulation Deadline Approaches.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol