logo

U.S. Institutions and the Dark Web: What’s Being Sold and Who’s Buying?

ID: 1e775387-ec28-5fcf-b0db-82931c3a2241

STIX ID: report--1e775387-ec28-5fcf-b0db-82931c3a2241

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report surveys Dark Web marketplaces targeting U.S. institutions, detailing what is sold (PII, medical records, credit card dumps, VPN/RDP credentials, cloud/OAuth tokens, session cookies, intellectual property), who buys access (ransomware groups, fraud networks, nation-state linked actors, phishing operators), the most-targeted sectors (finance, technology/SaaS, government, healthcare), and recommended defensive measures (dark web monitoring, credential rotation, supply-chain risk monitoring). It emphasizes the industrialization of cybercrime—Initial Access Brokers, infostealers, and commoditized session cookies/tokens—creating high-value, rapidly monetizable access that amplifies risk to U.S. organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.