RSA Europe: The growth of the underground hacker ‘economy’
Credit card data dealing on underground forums laid bare – service level agreements and efficient cash conversion that even the stock market could take lessons from.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The last few years have seen some of the biggest ever changes in IT security, especially with the new breed of financially motivated hacker.
This was according to Hugh Thompson, chief security strategist for People Security, who was talking at a keynote at RSA Europe 2008. He said that IT security had to deal with many shifts in the last three or four years, such as in internet environments.
But it was the attacker in the forum who Thompson most focused on. He talked of an efficient and effective underground economy where there was the dealing of credit card data. In his research, he revealed that users dealing with credit card data now have service level agreements between the buyer and stolen credit card brokers.
He picked out the example of a broker who was trying to sell various credit card numbers: "He makes a couple of guarantees instant replacement if he sells you bad credit card numbers, good discounts for big orders."
He added: "You can even check the merchandise by giving you a sample set of ten stolen credit card numbers to see if they work for you."
Thompson said that he felt it was incredible that the criminals had the maturity in the underground market that they felt they had to differentiate themselves by the quality of service that they were giving on stolen merchandise.
The strategist then led on to talk about how these transactions were now leading on to secondary markets. Thompson gave an example of how rather than deal with stolen credit card numbers, users would make a profit by converting different types of electronic currency.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He described the transactions the user could make: "PayPal to e-gold, PayPal to Western Union which is probably the best deal.
"What's fascinating about this is that it was in August, and then went back to look at all the posts from this individual. I found one three months before that, and the rates were different.
"It turns out that one of those e-money providers had just announced they had added an extra layer of security. So the market was so efficient that it priced in that extra problem the broker had to go through."
For more coverage and photos from the RSA show, click here.
-
Cohere's Aleph Alpha merger could create a transatlantic sovereign AI powerhouseAnalysis The merger between Cohere and Aleph Alpha aims to capitalize on the burgeoning sovereign AI market
-
Everything you need to know about OpenAI's new workspace agentsNews New ‘workspace agents’ from OpenAI will automate tasks for workers and can be customized for specific roles
-
The key risks security teams face in 2026From AI-related flaws to supply chain risks, cyber professionals now contend with overlapping challenges
-
Observability will be key to agentic AI safety, says Microsoft Security execNews Agentic AI adoption will require a re-evaluation of enterprise risk management, according to Microsoft corporate VP
-
Enterprises need to think of agents as ‘digital co-workers’ – and that means implementing the same security safeguardsNews Practices such as zero trust and least privilege will be needed as agents gain access to sensitive enterprise data
-
Safe AI adoption rests on cybersecurity professionals, says RSAC chairmanNews With AI security a key talking point at RSAC 2026, executive chairman Hugh Thompson believes the industry can lead by example
-
RSAC in focus: Key takeaways for CISOsThe RSAC Conference 2025 spotlighted pivotal advancements in agentic AI, identity security, and collaborative defense strategies, shaping the evolving mandate for CISOs.
-
RSAC in focus: Quantum computing and securityExperts at RSAC 2025 emphasize the need for urgent action to secure data against future cryptographic risks posed by quantum computing
-
RSAC in focus: How AI is improving cybersecurityAI is revolutionizing cybersecurity by enhancing threat detection, automating defenses, and letting IT professionals tackle evolving digital challenges.
-
RSAC in focus: Collaboration in cybersecurityExperts at RSA Conference 2025 emphasised that collaboration across sectors and shared intelligence are pivotal to addressing the evolving challenges of cybersecurity.