Every year, cybersecurity analysts observe hundreds of databases being leaked on dark web platforms. However, researchers rarely explore who continues to exploit this data, and how they do it, months or even years after the initial release.
In this research, we focused less on the secondary market for leaked data itself and more on the specific tactics of dark web community members. We tracked how older, previously published databases resurface for sale, how threat actors fabricate the illusion of a fresh breach, and the specific schemes used to remonetize data. Analyzing this secondary market and the behavior of its participants is crucial for predicting cyberthreats and mitigating organizational risks.
The report primarily focuses on cases involving the exploitation of high-profile brand names and the creation of affiliated account networks. We structured our research as a digital investigation, analyzing forum posts, contact information, overlapping threat actor accounts, and disputes between data brokers. Our team examined over 30 sources, including dark web forums, cybercrime-focused Telegram channels, and open-source intelligence.
This report is designed for cybersecurity professionals, threat intelligence analysts, and any organizations or individuals seeking to understand modern cyberthreats, the inner workings of the dark web market, and the risks associated with compromised databases.














































