logo

Looted RIPE Credentials for Sale on the Dark Web

ID: 93c5143c-7122-5025-b82f-b552f96f944d

STIX ID: report--93c5143c-7122-5025-b82f-b552f96f944d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-31

Date Updated: 2026-04-21

Author: Alicia Buller, Contributing Writer

...
...

Resecurity discovered hundreds of compromised RIPE and other regional registry accounts (716 RIPE customers; 1,572 accounts overall) with credentials sold on the dark web after infection by information-stealer malware (Redline, Vidar, Lumma, Azorult, Taurus). Attackers used stolen privileged access to probe services and at least once to misconfigure BGP/RPKI (Orange España outage); the report urges stronger authentication, privileged access management, and just-in-time credentials to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.