Danny Weber
RED Security SOC analyzed almost 80,000 illicit listings: leaked databases led with 47%, followed by hacked accounts and malware.
Sales of leaked databases have become the largest category on the dark web marketplaces and forums studied. RED Security SOC reached this conclusion after analyzing almost 80,000 listings for illegal services and digital goods.
According to the study, stolen-data databases accounted for 47% of all reviewed posts. Another 18% involved hacked accounts, while 14% offered malware. Roughly one in ten listings concerned financial fraud, including carding and documents used to obtain banking products.
Within the malware segment, 58% of listings covered ransomware, information stealers, loaders and remote-access trojans. The remaining 42% involved crypto-wallet drainers designed to steal digital assets. RED Security SOC links their popularity to relatively low prices and a modest entry barrier for criminals.
Access to corporate infrastructure, zero-day exploits and hacking-for-hire appeared far less often, each representing about 1% of listings. Despite the small share, analysts found more than a thousand new posts in these categories since the start of the year.
Seller activity peaked in the first quarter of 2026, with more than 42,000 new listings. In the second quarter, the figure fell by about 23% to just over 32,000. RED Security SOC says the decline may reflect both the shutdown of illegal platforms and sellers moving into more closed channels.
© RusPhotoBank