Trending

ee-track">
Link copied!

Over 2 Million Cards Leaked By BidenCash

Underground carding marketplace BidenCash leaks over 2 million payment card records, enabling financial fraud at scale.

March 1, 2023 · 2 min read
Over 2 Million Cards Leaked By BidenCash

Underground carding marketplace leaks over 2 million payment card records, enabling large-scale financial fraud.

Over 2 Million Cards Leaked By BidenCash
Figure 1 – Bidencash announces another leak

On February 28, 2023, the operators of the notorious carding marketplace BidenCash released a dataset of 2,165,700 credit and debit cards to commemorate one year of operation.

This leak was advertised on an underground cybercrime forum, similar to cc leaks previously covered by CRIL (Cyble Research and Intelligence Labs) in October 2022 and June 2022.

Several other shops use famous personas for marketing their wares, such as Brian’s Club impersonating cybersecurity journalist Brian Krebs since 2015. Similarly, the strategy of leaking cards at scale to advertise the shops was previously utilized by All World Cards.

Analysis

The data within the leak included Personally Identifiable Information such as names, emails, phone numbers, home addresses, and the main offering: payment card numbers, expiration dates, and CVV codes, with the expiration dates ranging from early 2023 up to 2052.

However, threat actors have been known to purchase expired payment cards to gain more information on potential victims.

report-ad-banner

This credit card leak contained at least 740,858 credit cards, 811,676 debit cards, and 293 charge cards. The inherent risk is higher for debit card holders than credit card holders, due to different fraud protection.

Heatmap of Countries Impacted by the Leak
Figure 2 – Heatmap of Countries Impacted by the Leak

According to our analysis, the most records leaked by country are as follows:

RecordsCountry
965,846UNITED STATES
97,665MEXICO
97,003CHINA
86,313UNITED KINGDOM
36,906CANADA
36,672INDIA
23,009ITALY
22,798SOUTH AFRICA
21,361AUSTRALIA
19,700BRAZIL

The top ten most impacted banks were as follows:

RecordsBank
118,826CHASE BANK USA, N.A.
98,631BANK OF AMERICA, N.A.
62,650WELLS FARGO BANK, N.A.
50,832CAPITAL ONE BANK (USA), NATIONAL ASSOCIATION
47,851CITIBANK N.A.
35,249BANK OF AMERICA, NATIONAL ASSOCIATION
28,296BBVA BANCOMER, S.A.
27,192CAPITAL ONE BANK (USA), N.A.
1,696,173Others

The presence of email addresses and full information (commonly referred to as “Fullz” by cybercriminals) will make the victims of this cc leak vulnerable to other attacks, such as phishing, identity theft, and scams, long past the expiration of their credit card details.

Conclusion

Threat Actors routinely utilize stolen credit cards for fraud by purchasing them from carding marketplaces, as we have seen in the examples of BidenCash. However, the availability of these cards for free will enable bad actors to commit more fraudulent activities. Banking institutions should monitor the dark web for these cc leaks and fraudulent activities to prevent fraud proactively.

See Cyble Vision in Action

AI Threat Intelligence

Stop Executive Threats
Before They Strike

Monitor dark web chatter, detect lookalike domains, and protect your C-suite from targeted impersonation — in real time, across 50+ countries.

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams