Prices to steal data or hack into a system appears to be hitting rock bottom, a new report found.
In this day of commercial off the shelf criminalware, it is possible to cull a service to steal credit card data, online banking accounts, or send out malware, hacking services, tutorials, online payment accounts to name a few.
The underground hacker market, those interested in hiring a hacker to compromise a Gmail, Hotmail, or Yahoo account only have to pay $129 for the service, according to a report from Dell SecureWorks.
“In our December 2014 report, we revealed that our security experts saw a big focus by the underground hackers on providing excellent customer service,” Dell SecureWorks researchers said in their new report report. “Interestingly, that trend has not died out, but rather increased, especially on the Russian Underground forums, where we
saw many of the hackers expand their working hours to include weekends and even promising to be available 24×7.”
Popular U.S. social media and Ukrainian email accounts are priced the same, popular Russian email accounts range between $65 and $103, while Russian social media accounts come in higher at $194.
Hackers also offer to compromise corporate email accounts, and ask $500 per business mailbox, the report found. What’s also interesting, is hackers are providing customer support, they do not ask for prepayments, promise fast results (depending on the complexity of the hack) and promise complete confidentiality, saying victims won’t notice they’ve been hacked.
Prices for Remote Access Trojans (RATs) dropped significantly over the past three years, down from $50-$250 in 2013, to only $5-$10 in 2015. Dell’s researchers also found the Angler Exploit Kit is available for $100-$135, and the price for “Crypters” went up significantly, reaching $80-$440, compared to 2014, when this type of malware went for only $50-$150.
Hacking tutorials are up for sale for between $20 and $40, for multiple tutorials, while doxing services cost only $19.99 (down from up to $100 a year ago). While hacking a website (stealing data) costs $350, distributed denial of service (DDoS) attacks can be hired for as low as $5 per hour, $200 per week, or $1,000 per month, with the price being higher if the website has anti-DDoS protection installed.
The price for credit card data mostly went up over the past three years, with U.S. Visa and MasterCard being at the bottom, priced at $7, and Premium Visa and MasterCard with Track 1 and 2 Data going for as much as $80 for Japan and Asia, or $60 for the EU and UK. Visa Classic and MasterCard Standard in Japan and Asia are also the most expensive across regions, at $50.
Bank account credentials are being sold for a very small percentage of their balance, though prices differ based on region. US bank accounts, for example, cost between $40 (for a $1,000 balance) and $500 (a $15,000 balance), EU bank accounts cost $400, with no balance listed, while Australian ones cost between $2,250 (a $22,000 balance) and $3,800 (a $62,567 balance).
For high quality bank accounts with verified, large balances of $70,000 – $150,000, hackers charge 6 percent of the balance. Hackers charge a fee for transferring funds from popular online payment accounts, as much as $950 for transferring $3,799, or up to $600 for popular U.S. online payment account credentials with a $950 balance.
Airline and hotel points can also be purchased in these underground black markets. Based on the number of points in account, large U.S. airline points accounts priced as high as $450 for 1,500,000 points, and large Middle East airline points accounts priced at $150 for 500,000 points. A large international hotel chain points account with 1,000,000 points cost just $200, the report reveals.