logo

Following the digital trail: what happens to data stolen in a phishing attack

ID: e140a9a6-29a5-57d7-9930-e428b1e87dd4

STIX ID: report--e140a9a6-29a5-57d7-9930-e428b1e87dd4

Feed Name: Securelist by Kaspersky

Date Published: 2025-12-12

Date Updated: 2026-04-29

Author: Olga Altukhova

...
...

This report outlines how data stolen in phishing campaigns is collected (email scripts, Telegram bots, and PaaS admin panels), aggregated and verified, then sold on dark‑web/Telegram markets and repurposed for further attacks, including targeted whaling, with prices varying by account value and protections. It highlights that January–September 2025 attacks primarily aimed at account credentials (88.5%), with smaller shares targeting personal data (9.5%) and bank card details (2%), and closes with practical guidance for containment and recovery (unique passwords, MFA, session reviews, breach checks, and alerting contacts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.