Blog

Card Shop Threat Landscape: BidenCash Dumps 2.1M Stolen Credit Cards

What we know about the most recent BidenCash dump, and what it means in the context of the greater card shop threat landscape

March 2, 2023

What BidenCash has shared

On February 28, 2023, card shop BidenCash announced its one-year anniversary. To commemorate the event, the administrators of BidenCash shared a text file of 2.1 million compromised credit cards for free on a top-tier Russian-speaking darknet forum XSS. Here’s what we know about the most recent BidenCash dump, and what this means in the context of the greater card shop threat landscape.

Initial findings

Our initial findings indicate that the text file with the credit card numbers contains a host of personally identifiable information (PII), including the cardholder’s name and address as well as private financial data such as the  full card number, expiration date, CVV number, and bank name.

Additionally, about 70% of the cards have expiration dates in 2023; 50% of the cards belong to US-based people or entities; while fewer than 5% of them are based in China and the UK.

While BidenCash currently ranks in the top-5 card shops by total volume (above), quality (the viability of the cards) always trumps the quantity (total number of cards). BidenCash’s release is one of the largest observed in the last year, where a typical release is somewhere in the ballpark of 40,000 stolen credit cards. Like any offering of free samples, the goal is to attract new customers to the storefront. The actual mileage on those credit cards may be limited, as they are approaching expiration, or have likely been already flagged for fraud by financial institutions. 

Not the first BidenCash release

BidenCash has previously released large compromised card dumps to gauge interest in its card shop. For example, on June 16, 2022, BidenCash card shop released a database with information of 7.9 million individuals on the top-tier Russian-language forum XSS.

The Great Cyber Exit: Why the Number of Illicit Marketplaces Is Dwindling

On August 2, 2021, another card shop AllWorldCards announced on XSS the release of 1,000,000 credit cards for free. The data contained in these records included full credit card numbers, expiration dates, CVVs, and in some cases other PII, including country, state, city, address, zip code, email, phone number).

BidenCash vs. The competition

Since the official closure of Joker’s Stash on February 15, 2021, several card shops have attempted to earn the title of “top card shop,” with Telegram-based shops increasingly conquering market share from more traditional web-based shops. BidenCash is currently a mid- to-top-tier card shop in terms of volume and popularity with threat actors. The shop has managed to steadily increase the volume of cards sold through its platform throughout 2022 and the shop’s giveaway of free credit cards likely constitutes a push to increase its popularity in a still-malleable market. 

BidenCash launched on April 27, 2022, shortly after Russian authorities seized a number of illicit card shops, including Forum, Trump Dumps, and UniCC, along with the carding forum Sky-Fraud and Remote Desktop Protocol access shop UAS. These cybercrime-related takedowns—which represent one of the last actions of Russian authorities in the cybercrime realm before its military 2022 invasion of Ukraine—launched significant movements in the market of credit card shops, as new or emergent card shops breathed fresh competition into the illicit landscape.

Fight card fraud with Flashpoint

With more than 2 billion stolen credit cards in our collections, Flashpoint’s Card Fraud Mitigation helps fraud teams detect compromised credit cards from illicit communities and data breaches, and identify high-risk merchants before fraudulent transactions occur or multiply. Card Fraud Mitigation unlocks visibility into attacker techniques, emerging trends, and new fraud schemes to help teams quickly take action.

Flashpoint cyber threat intelligence tools provide teams with access to illicit online communities including closed sources across forums, the open web and chat services platforms, as well as indicators of compromise (IOCs), and technical data as analyzed by Flashpoint intelligence analysts. Sign up for a free trial today.

Getting started is easy.