Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Research Findings on the Fate of Data Stolen in Phishing Attacks

## Cybersecurity: Lifecycle of Data Stolen in Phishing Attacks

Cybersecurity: Lifecycle of Data Stolen in Phishing Attacks

Research conducted by Kaspersky has detailed the lifecycle of data obtained through phishing attacks, illustrating how such data is quickly commoditized. This study traces the process from the initial phishing attempt to the sale of credentials on dark web platforms, highlighting the role of automated tools in facilitating identity theft.

Technological Advancements in Data Theft

The report notes a shift from traditional methods, where PHP scripts were used to forward credentials to attackers via email. These methods are declining due to delays and blocks. Cybercriminals are increasingly using Telegram bots and "Platform as a Service" (PaaS) administration panels. Telegram bots enable real-time data exfiltration, while PaaS panels offer attackers a centralized dashboard to manage stolen data, verify credentials, and filter information by geographical location.

Between January and September 2025, 88.5% of phishing attacks targeted online account credentials. Personal data, including names and addresses, accounted for 9.5%, and direct bank card theft comprised 2% of incidents. Stolen data often goes through a four-stage process: consolidation, verification, sale, and targeted attacks. Cybercriminals may combine new leaks with historical data to build comprehensive profiles on victims.

The value of compromised accounts varies based on account type, balance, and whether two-factor authentication (2FA) is enabled. Banking and cryptocurrency accounts command higher prices compared to social media logins, which are used in social engineering campaigns.

Research conducted by Kaspersky has detailed the lifecycle of data obtained through phishing attacks, illustrating how such data is quickly commoditized.
Angela Waters · Thehackingpost

Banking Accounts: $70 – $2,000 (Average: $350.00) Crypto Platforms: $60 – $400 (Average: $105.00) E-government Portals: $15 – $2,000 (Average: $82.50) Online Stores: $10 – $50 (Average: $20.00) Personal Documents: $0.50 – $125 (Average: $15.00) Social Media: $0.40 – $279 (Average: $3.00) Messaging Apps: $0.06 – $150 (Average: $2.50)

Stolen biometric data and document scans are increasingly used for identity theft and deepfake creation. High-value individuals, such as executives, are often targeted for "whaling" attacks. Attackers use historical data, such as old passwords, to craft phishing emails aimed at infiltrating an organization.

Advertisement

To mitigate these risks, it is advised to change passwords immediately if a breach is suspected, implement multi-factor authentication, and use services that monitor personal data exposure in known breaches.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories