← All news

breach

The Underground Now Has a Search Bar for Stolen Logins

2026-06-22

Sifting through billions of stolen credentials used to be the buyer's problem. Not anymore. Researchers at Flare have mapped a growing corner of the underground where sellers offer what they call a "search your target" service: hand over a domain, a login URL, an email list or a country code, and they return matching credentials from their private stockpiles.

Flare reviewed 470 forum posts between January 2025 and June 2026 to work out how the trade operates. The sellers sit neatly in the middle of the account takeover chain, between the infostealer crews who harvest the data off infected devices and the fraudsters who eventually weaponise it. They pitch themselves like any other data broker. Database size (one claimed five billion lines, another ten), daily updates, fast turnaround, and tidy output formats such as URL:LOGIN:PASS or MAIL:PHONE. One seller was charging $20 per query, with surcharges depending on what came back.

A data analytics business that happens to be illegal

What stands out is how professional the operation has become. Sellers talk about indexing, slicing, deduplication and enrichment. A buyer holding only an email list can request matching passwords. A buyer chasing a particular country can ask for results filtered by city, domain, or even password pattern. The vocabulary is the vocabulary of any analytics shop. The product just happens to be other people's logins.

Not that buyers are uniformly delighted. Forum threads are dotted with complaints: invalid credentials, heavy duplication (one buyer reported only 200 unique records out of 3,000), and entries that turned out to be recycled from free combo lists doing the rounds. Sellers tend to reply with a shrug, pointing out that they never claimed to validate anything. Caveat emptor, apparently, survives the trip into the criminal economy.

Why this matters for defenders

The interesting overlap is with initial access brokers, the higher tier of the underground who sell ready-made footholds into corporate networks. A targeted query against a company's VPN portal, Microsoft 365 tenant or SaaS login can produce roughly the same outcome as a curated access sale. Cheaper, noisier, less polished, but functionally similar. For an attacker who knows where they want in, a $20 search is a reasonable opening move.

The raw material feeding these searches is overwhelmingly infostealer output, and infostealers tend to land on personal devices that happen to be logged into work accounts. The home laptop where someone checked their email. The family PC where a teenager installed a dodgy game mod. Once a session token or saved password lands in a stealer log, it eventually finds its way into one of these searchable databases, often within days.

  • Credentials are now queryable by domain, geography or pattern, not just dumped in bulk.
  • The price point is low enough that targeted abuse no longer needs a sophisticated buyer.
  • The exposure largely originates on employee devices outside the corporate perimeter.

Which puts a slightly awkward question in front of every security team: the technical controls inside the network are doing their job, but the credentials walking through the front door were stolen somewhere nobody was watching. Password reuse, MFA coverage on every external login, and what staff actually click on at home all weigh more heavily on this risk than the org chart suggests.

The Underground Now Has a Search Bar for Stolen Logins | RiskSense