Data on the Dark Web: What Is Your Company Worth?

Data on the Dark Web: What Is Your Company Worth?

data dark web

The stolen data market has its price list, like any trading floor. An analysis conducted by Flare on 348 real data breach listings, published between 2008 and 2026 across dark web and clear web marketplaces, establishes the going rate for 25 categories of personal data. Its findings upend the defensive priorities of most organisations: what you protect the most is not always what attackers value the most.

What Is the Price of Stolen Data on the Dark Web?

Health records are the most expensive data on the criminal market, at roughly 300 dollars per record, far ahead of credit card numbers at 17 dollars. In between sit PINs (196 dollars), bank account numbers (69 dollars), driver’s licenses (68 dollars), passport numbers (33 dollars) and social media profiles (27 dollars).

At the bottom of the scale, email addresses trade at 0.83 dollars and IP addresses at around 1 dollar. This hierarchy is anything but anecdotal: it reflects the profitability of each data type for whoever exploits it, and it should serve as a compass for any protection strategy.

Price per record on dark and clear web marketplaces (USD)

Source: Flare, analysis of 348 real data breach listings, 2008-2026

Health records
$300
PINs
$196
Bank account numbers
$69
Driver's licenses
$68
Passport numbers
$33
Social media profiles
$27
Credit card numbers
$17
SSNs
$5
IP addresses
$1
Phone numbers
$0.97
Email addresses
$0.83

Why Is a Health Record Worth 18 Times More Than a Credit Card?

The answer comes down to one word: revocability. A compromised credit card can be cancelled within minutes; the block closes the market. A health record, by contrast, cannot be cancelled. Medical history, conditions, treatments: this information remains exploitable for years, fuelling insurance fraud, medical identity theft and targeted extortion.

The credit card, which many defenders still treat as the crown jewel of data to protect, is in reality a mid-tier commodity for attackers: it ranks only eighth in the price hierarchy. Consequently, organisations that calibrate their defence around the PCI DSS standard, believing they have covered the essentials, mostly protect what can be replaced, while underinvesting in what cannot.

Key takeaway: the value of data to an attacker is inversely proportional to its revocability. Anything that cannot be cancelled (health, biometrics, history) is structurally worth more than anything that can.

The Paradox of One-Dollar Data

An email address at 0.83 dollars and a phone number at 0.97 dollars may seem trivial. That reading would be a mistake: these prices are low because supply is massive, not because the data is harmless. Billions of addresses are in circulation, and the law of supply and demand has done the rest.

Yet this abundant data remains the raw material of most intrusions. A corporate email address is the entry point for phishing, credential stuffing and social engineering. In other words, the bottom of the table funds the top: with sub-dollar email addresses, attackers obtain the access that lets them steal 300-dollar records.

One category deserves adding, as the price list does not show it directly: credentials harvested by infostealers. A stealer log is a file produced by malware that siphons the passwords, session cookies and form data stored in the browser of an infected machine. It allows a buyer to replay authenticated sessions without triggering any login alert. These files circulate by the millions on Telegram and specialised forums, often for a few dollars, and now rank among the leading vectors of corporate compromise.

What This Price List Changes for a Regulated Company

Your real exposure is measured through the buyer’s eyes, not the auditor’s. Three practical consequences follow.

First, your data inventory should be weighted by its criminal market value. A healthcare provider or an insurer holds a stock of 300-dollar assets; its level of protection must match that valuation, which is precisely what NIS2 demands from health sector entities. Next, monitoring can no longer stop at the internal perimeter: knowing whether your data is already circulating on marketplaces, Telegram channels, clear web forums or inside stealer logs is a defensive capability in its own right. Finally, notification is only half the story: in the event of a breach, the GDPR requires informing the supervisory authority within 72 hours, but anticipating the sale of stolen data makes it possible to reduce the damage before it materialises.

Key takeaway: your data has a market price that you do not set. The only variable under your control is the detection time between its leak and its exploitation.

Monitor Your Exposure Before the Market Does It for You

The dark web price list tells the story of a rational, organised economy where every data type finds a buyer at its fair price. Against such a structured market, defence cannot remain artisanal: it requires continuous exposure monitoring, covering marketplaces, forums, Telegram channels, stealer logs and lookalike domains.

That is exactly the purpose of Stroople’s Threat Exposure Management: detecting your data, credentials and access points in circulation before they are exploited, and turning the attackers’ price list into a defensive action plan.

What Stroople Monitors on Your Behalf

Stroople’s Threat Exposure Management service combines EASM and data leak detection in a continuous monitoring program. In practice, Stroople tracks your external exposure across open and closed sources: compromised credentials, data surfacing on the dark web, misconfigured assets, orphaned access points at your suppliers. Each alert is qualified by analysts, then delivered with a clear remediation plan.

External Attack Surface Management & Data Leak Detection

External Attack Surface Management

See your exposure before attackers do. Know what's already compromised.

Learn more
0 %

of successful breaches start from publicly exposed assets.

Share:

X
LinkedIn
AI

Related Posts

Data on the Dark Web: What Is Your Company Worth?

The stolen data market has its price list, like any trading floor. An analysis conducted…

AI Cyber Safeguards: What Anthropic’s CVP Actually Changes

On April 23, 2026, Anthropic deployed real-time AI cyber safeguards on its most capable models.…

Enterprise Data Leaks: Detect What Attackers Already See

Most organizations invest in tools to prevent data leaks. However, a portion of their sensitive…