{"id":19287,"date":"2022-06-08T05:10:13","date_gmt":"2022-06-08T13:10:13","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/08\/news-13020\/"},"modified":"2022-06-08T05:10:13","modified_gmt":"2022-06-08T13:10:13","slug":"news-13020","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/08\/news-13020\/","title":{"rendered":"SSNDOB marketplace shut down by global law enforcement operation"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 08 Jun 2022 13:05:35 +0000<\/strong><\/p>\n<p>The United States Department of Justice has announced a <a href=\"https:\/\/www.justice.gov\/usao-mdfl\/pr\/ssndob-marketplace-series-websites-listed-more-20-million-social-security-numbers-sale\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">major takedow<\/a><a href=\"https:\/\/www.justice.gov\/usao-mdfl\/prssndob-marketplace-series-websites-listed-more-20-million-social-security-numbers-sale\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">n<\/a> of a criminal marketplace that traded Personally Identifiable Information (PII). Not just any old marketplace; this was a major, years-long operation with several failsafes to prevent permanent takedown. It took quite the assortment of law enforcement worldwide to shut this one down for good.<\/p>\n<p>SSNDOB (Social Security Number, Date of Birth) marketplace was seized as the result of an international operation involving the FBI, Department of Justice, the IRS, and authorities in both Latvia and Cyprus.<\/p>\n<h2>A big underground business<\/h2>\n<p>According to the press release, the ring of sites associated with SSNDOB:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><em>&#8230;were used to sell personal information, including the names, dates of birth, and Social Security numbers belonging to individuals in the United States. The SSNDOB Marketplace has listed the personal information for approximately 24 million individuals in the United States, generating more than $19 million USD in sales revenue.<\/em><\/p>\n<\/blockquote>\n<p>Social Security numbers are hugely popular on underground portals. They&#8217;re frequently <a href=\"https:\/\/www.forbes.com\/sites\/jessedamiani\/2020\/03\/25\/your-social-security-number-costs-4-on-the-dark-web-new-report-finds\/?sh=6dcb602a13f1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cheap to buy<\/a>, stolen in <a href=\"https:\/\/finance.yahoo.com\/news\/hackers-steal-even-more-social-205753006.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">large numbers<\/a>, and can be bundled with other documents such as passport, driver&#8217;s licence, email, and more.<\/p>\n<p>SSNDOB attempted to ward off a permanent shut down by spreading the data across four different URLs. As <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-seizes-ssndob-market-for-selling-personal-info-of-24-million-people\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bleeping Computer<\/a> notes, this is one tactic to get around attempts to shut down the service. DDoS attacks from rivals are common, so several domains working together keeps things ticking over. Shutdowns generally via abuse reports or law enforcement raids are also less of a threat as a result.<\/p>\n<p>SSNDOB advertised its services on dark web forums and offered customer support for buyers. Digital payment methods such as Bitcoin were used to preserve the operator&#8217;s anonymity.<\/p>\n<h2>The Bitcoin boon<\/h2>\n<p>According to <a href=\"https:\/\/blog.chainalysis.com\/reports\/ssndob-darknet-market-shutdown\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">research from Chainalysis<\/a>, SSNDOB received &#8220;$22 million worth of Bitcoin across over 100,000 transactions&#8221; since 2015. We&#8217;ve noted the <a href=\"https:\/\/blog.malwarebytes.com\/scams\/2021\/08\/if-a-qr-code-leads-you-to-a-bitcoin-atm-at-a-gas-station-its-a-scam\/\">gradual emergence<\/a> of Bitcoin ATMs in scams previously; here, cryptocurrency ATMs are more popular as a payment method to SSNDOB than other dubious online services.<\/p>\n<p>Chainalysis also notes a potential connection between SSNDOB and another dark web market trading in credit cards which <a href=\"https:\/\/krebsonsecurity.com\/2021\/01\/jokers-stash-carding-market-to-call-it-quits\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">called it quits in 2021<\/a>. Joker&#8217;s Stash, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/stolen-credit-card-shop-jokers-stash-closes-after-making-a-fortune\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">trading since 2014<\/a>, received more than $100,000 in Bitcoin from SSNDOB. <\/p>\n<h2>The threat of stolen PII<\/h2>\n<p>Once your data is out there, you can&#8217;t get it back. Criminals will make use of it however they can to make money. You run the risk of being targeted for spear phishing, or having your personal information used for fraudulent applications.<\/p>\n<p>Data breaches are so common that multiple services exist to <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">check if you&#8217;ve been impacted<\/a>. Password reuse is one big reason for <a href=\"https:\/\/www.ncsc.gov.uk\/news\/use-credential-stuffing-tools\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">credential stuffing<\/a> (using stolen data across additional sites) being so popular. One breach taking your login from a gaming forum can quickly become something that exposes Government service logins or bank accounts. The data exposure risk creeps ever upwards and one small mistake can have severe consequences.<\/p>\n<h2>Tips for locking down after an SSN breach<\/h2>\n<p>This is a great result for law enforcement, but still a drop in the ocean of underground sales portals. If you&#8217;re a victim of Social Security number fraud, there are <a href=\"https:\/\/www.experian.com\/blogs\/ask-experian\/3-steps-to-take-if-your-social-security-number-has-been-stolen\/#:~:text=If%20your%20Social%20Security%20number%20has%20been%20stolen%2C%20report%20the,your%20SSN%20due%20to%20fraud.\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">some steps you can take<\/a> according to Experian:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.identitytheft.gov\/#\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report the theft<\/a> to the FTC<\/li>\n<li>Request a <a href=\"https:\/\/www.experian.com\/blogs\/ask-experian\/credit-education\/preventing-fraud\/security-freeze\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">credit freeze<\/a>, and also a <a href=\"https:\/\/www.experian.com\/blogs\/ask-experian\/what-is-the-difference-between-a-credit-freeze-and-fraud-alert\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fraud Alert<\/a>.<\/li>\n<li>Notify companies where your data has been used fraudulently.<\/li>\n<\/ul>\n<p>Stay safe out there!<\/p>\n<\/p>\n<\/p>\n<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/06\/ssndob-marketplace-shut-down-by-global-law-enforcement-operation\/\">SSNDOB marketplace shut down by global law enforcement operation<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/06\/ssndob-marketplace-shut-down-by-global-law-enforcement-operation\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Wed, 08 Jun 2022 13:05:35 +0000<\/strong><\/p>\n<p>Law enforcement has seized an underground marketplace trading in SSNs and other personal data. We take a look at how they did it.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/privacy-2\/2022\/06\/ssndob-marketplace-shut-down-by-global-law-enforcement-operation\/\">SSNDOB marketplace shut down by global law enforcement operation<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10615,9751,26470,19131,5897,26471,26472,26473],"class_list":["post-19287","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-dark-web","tag-fraud","tag-marketplace","tag-pii","tag-privacy","tag-social-security-number","tag-ssndob","tag-underground-forum"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19287"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19287\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19287"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}