Dark-web markets show how ordinary email, cloud and social-media accounts have become low-cost commodities — and why European organisations need to rethink identity security
The economics of cybercrime can be deceptively mundane. On underground marketplaces, a compromised German Microsoft 365 account is currently advertised for an average of just $26.50. Stolen payment-card data can be found for around $12.68, while access to some streaming services costs less than five dollars.
The prices are strikingly low. The potential consequences are not.
A recent analysis published by NordVPN around International VPN Day illustrates how extensively digital identities are now being broken down into individual components and traded as commodities. The findings are particularly relevant for European organisations because they highlight a fundamental change in the economics of cybercrime: attackers do not necessarily need to obtain an entire identity, compromise a highly privileged administrator or steal a complete financial profile. Sometimes a valid login to an ordinary account is enough to begin a much longer attack chain.
The German market data provide a useful case study of a problem that extends well beyond national borders. In increasingly interconnected European businesses, identity systems, cloud services and email platforms often form the connective tissue between employees, suppliers, customers and internal applications. Once one of these identities is compromised, the value to an attacker can be far greater than the price paid for the credentials themselves.
Digital identities are being sold in pieces
Consumers often associate identity theft with passports, payment information, tax records or bank accounts. Underground markets operate according to a more granular logic.
Instead of treating a person’s identity as one complete dataset, criminals can trade individual elements separately and later combine them with information obtained from other sources.
According to the NordVPN analysis, digital copies of German passports were advertised for an average of around $33, driving-licence data for approximately $35 and identity-card information for about $34. So-called “Fullz” — packages combining several pieces of personal information belonging to one victim — were also offered for roughly $33.
Physical documents command considerably higher prices. German passports and identity cards were reportedly offered for as much as $1,897. Compromised financial accounts can be more expensive still: NordVPN cites average prices of approximately $803 for Wise accounts and more than $1,700 for Revolut accounts.
Yet focusing only on these premium assets risks overlooking the most industrialised part of the market.
Telegram accounts were offered for about $12, TikTok accounts for around $60 and some streaming subscriptions for less than five dollars. Their usefulness does not necessarily come from their direct monetary value. A compromised account can reveal contacts, messages, personal interests, associated email addresses or other information that can support subsequent fraud and social-engineering operations.
This is one of the defining characteristics of the modern underground economy: the value of stolen information increasingly depends on what criminals can combine it with.
Email has become part of the identity infrastructure
Among the most consequential assets are email and cloud accounts.
An email inbox is no longer simply a repository for messages. For most users it functions as a central component of their digital identity. Registrations, security notifications, purchase confirmations and password-recovery procedures frequently converge on the same address.
In a corporate environment, the consequences are even broader.
A compromised Microsoft 365 identity can, depending on permissions and configuration, potentially provide access not only to email but also to corporate files stored in services such as OneDrive or SharePoint. A legitimate mailbox can also be abused for fraudulent communication with colleagues, suppliers or customers — one of the mechanisms frequently associated with Business Email Compromise.
This helps explain why an underground-market price of $26.50 says almost nothing about the potential financial or operational damage.
What the buyer acquires is not merely a username and password. The attacker may gain access to an already established identity with a history of legitimate communication, trusted contacts and a position within real business processes.
That dramatically changes the nature of the attack.
Instead of attempting to break through a technical security control from the outside, criminals equipped with valid credentials can initially resemble legitimate users. The challenge for defenders therefore shifts from simply preventing unauthorised access to identifying when an apparently authorised identity is behaving in an unauthorised way.
Credentials are part of an increasingly specialised criminal supply chain
The commoditisation of accounts also reflects a broader transformation of cybercrime.
The criminal who steals credentials does not have to be the same actor who ultimately uses them. Infostealer operators, phishing-service providers, Initial Access Brokers and groups conducting fraud or extortion can occupy different positions within the same criminal supply chain.
ENISA, the European Union Agency for Cybersecurity, continues to identify infostealers as an important component of this ecosystem. Such malware can harvest credentials and session tokens that can subsequently be used to gain access to systems or sold to other criminal actors.
At the same time, the professionalisation of Phishing-as-a-Service has lowered the technical barrier for attackers. Ready-made infrastructures can provide phishing pages and campaign capabilities to criminals who would previously have needed considerably more technical expertise.
Phishing therefore remains relevant not only as a method for stealing passwords, but as an entry point for session hijacking and malware deployment. Manipulated websites and fraudulent CAPTCHA-style interactions can also be used to persuade victims to execute malicious commands or install information-stealing malware.
That does not mean credentials are the only security problem organisations face.
The Verizon Data Breach Investigations Report 2026 points to an important shift in initial-access patterns: exploitation of software vulnerabilities reached 31 per cent and, for the first time, overtook stolen credentials as the leading initial-access vector observed in the report.
The implication is not that identity-based attacks are disappearing. Rather, organisations are facing a broader attack surface in which vulnerability management and identity protection have to operate simultaneously.
Public information makes stolen credentials more useful
The second part of NordVPN’s research demonstrates why relatively ordinary credentials can become increasingly valuable when combined with publicly available information.
In the German survey, 60 per cent of respondents said they had published their full name online, while 63 per cent had shared their date of birth. Some 46 per cent reported having disclosed their full address and 36 per cent their relationship status.
More strikingly, 26 per cent said they had shared banking information online, while seven per cent reported having disclosed their tax identification information. Seven per cent said they had subsequently regretted publishing personal information.
None of these data points automatically results in an account takeover.
The danger comes from aggregation.
Names, email addresses, telephone numbers, dates of birth, addresses, customer details, employer information and publicly visible relationships can be assembled into increasingly convincing profiles. Such information can make social-engineering attempts more credible and can become particularly valuable where account-recovery procedures rely on knowledge-based verification.
For security teams, this requires a different way of thinking about data value.
The risk associated with a piece of information is not determined solely by how sensitive it appears in isolation. Its value may emerge only when it is correlated with other information already available to an attacker.
Private identities can become a corporate security issue
The distinction between personal and professional identities is also becoming harder to maintain.
Employees access private and corporate services from the same devices. Personal email accounts may serve as recovery addresses. Password reuse can allow credentials compromised in one environment to be tested elsewhere. Public social-media profiles may reveal an employee’s role, colleagues, reporting relationships or technologies used by an organisation.
A compromised private account does not automatically mean that the employer has been breached. It can, however, provide attackers with intelligence that supports further targeting.
The risk changes significantly when the compromised identity belongs directly to the organisation.
Once a corporate account is under an attacker’s control, defenders may need to consider more than password theft. Malicious mailbox forwarding rules, fraudulent emails, abuse of active sessions and access to connected cloud resources all become relevant.
Microsoft’s guidance for compromised Microsoft 365 accounts therefore extends well beyond simply changing a password. Response measures can include blocking the affected account, resetting credentials, revoking active sessions and reviewing multi-factor authentication methods, permissions and forwarding rules.
The traditional advice to “use a strong password” is no longer an adequate security strategy on its own.
Identity security has to extend beyond the password
Unique passwords remain important. Password managers can substantially reduce the risk that one stolen password will expose several services through credential reuse.
But passwords increasingly need to be treated as only one layer of authentication.
Multi-factor authentication can prevent possession of a password alone from being sufficient for account access. Where available, organisations are also moving towards passkeys and other phishing-resistant authentication methods, which reduce reliance on credentials that users can inadvertently disclose to fraudulent websites.
For enterprise environments, the challenge is broader still.
Effective identity protection increasingly requires disciplined Identity and Access Management, restrictions on privileged accounts, Conditional Access policies, monitoring of suspicious sessions and rapid investigation of anomalous sign-in behaviour.
Endpoint security is equally important because modern information stealers do not necessarily limit themselves to passwords. Session cookies and authentication tokens can also be targeted, potentially allowing criminals to bypass some controls that focus primarily on password theft.
This is an important distinction when assessing technologies such as VPNs.
A VPN can add protection to network communications, particularly when users connect through untrusted networks. It cannot, however, prevent a user from entering credentials into a convincing phishing site, nor can it neutralise malware that is already executing on the endpoint. Network protection, strong authentication and endpoint security therefore solve different parts of the problem.
Low prices are a sign of industrialisation, not low risk
Perhaps the most important lesson from the underground-market data is that price should not be confused with impact.
The fact that credit-card data, streaming accounts or email credentials can be advertised for single- or double-digit dollar amounts is not evidence that these assets are insignificant. Quite the opposite: low prices can indicate that particular types of compromised data are available at scale and traded efficiently within a mature criminal marketplace.
Their full value may only emerge later in the attack chain.
An email account can be combined with a reused password. A public social-media profile can be correlated with personal information. A compromised browser may contain an active authenticated session. Individually inexpensive fragments can gradually be assembled into a usable digital identity.
For European security leaders, the message is therefore broader than the Dark Web price list itself.
Cybersecurity strategies cannot focus exclusively on protecting assets that organisations traditionally classify as highly sensitive. In a criminal economy built around aggregation, resale and specialised attack services, even an apparently ordinary account can provide the first foothold in a far more consequential operation.
The price of the credential may be measured in tens of dollars.
The cost of the identity behind it can be dramatically higher.
Methodology
The NordVPN findings combine two separate studies. The consumer survey was conducted by Cint between 1 and 17 April 2026 among more than 20,000 internet users in 20 countries. The German sample consisted of 1,001 respondents aged 18 to 74, selected using quotas for age, gender and place of residence. The underground-market analysis was conducted using NordStellar’s threat-exposure-management platform and covered offers observed between January 2025 and February 2026 across indexed, non-indexed and specialised marketplaces. After deduplication, the dataset contained more than 28,000 unique listings across 16 categories. The quoted figures represent advertised marketplace prices. They should therefore not be interpreted as verified transaction prices or evidence of actual sales volumes.

