Join

Enter Details

Comment on stories, receive email newsletters & alerts.

@
This is your permanent identity for Business Insider Australia
Your email must be valid for account activation
Minimum of 8 standard keyboard characters

Subscribe

Email newsletters but will contain a brief summary of our top stories and news alerts.

Forgotten Password

Enter Details


Back to log in

Here's how much thieves make by selling your personal data online

Attached imageReutersA man wearing a Guy Fawkes mask surfs the web during a ‘Campus Party’ Internet users gathering in Sao Paulo January 30, 2013.

With a record number of breaches in the U.S. during 2014, more personal information is floating around on the internet than ever before. But your banking data, health records and even your Facebook account all come with a price tag on the dark web.

The dark web is where the marketplaces for stolen data exist. The dark web exists on the “deep web,” which is the part of the internet that is not catelogued by normal search engines, like Google. To access these dark corners of the internet special software called Tor must be used.

While credit card information can sell for only a few bucks on black market websites, health records run about $US50 per record, according to a report by Dell SecureWorks. Bank account information is a higher ticket item and can sell for $US1,000 or more depending on how much money is in the account.

Buyers can even buy someone’s social media account for about $US50 or get an entirely new identity plus a matching utility bill for only about $US350.

Here’s a quick look at what other personal information goes for on the dark web, according to the report:

  • Bank credential: $US1,000 plus (6% of the total dollar amount in the account)
  • U.S. credit card with track data (account number, expiration date, name and more): $US12
  • EU, Asia credit card with track data: $US28
  • Hacking into a website: $US100 to $US300
  • Counterfeit social security cards: $US250 and $US400
  • Counterfeit driver’s licence: $US100 to $US150

But criminals aren’t the only ones paying for your lost personal information. Companies that are affected by data breaches are having to shell out a lot of money for each record that gets leaked in a data breach.

The average global cost of a lost or stolen data record for a company in 2014 was $US154, that’s a 23% increase since 2013, according to a study by IBM and the Ponemon Institute published Wednesday. The cost includes the forensic and investigative work needed to address a breach, as well as the cost of identity theft programs for people whose records were leaked.

Healthcare companies are having to pay the most with the average price for a lost data record coming to $US363. And retailers’ cost per record went from $US105 in 2013 to $US165 in 2014.

The surge in data breaches, specifically those caused by organised crime, is driving the cost of lost or stolen records for companies, said Marc van Zadeloff, vice president of strategy and product for IBM security.

In the US alone, there was a total of 783 data breaches last year, a 27.5% increase from 2013, according to the Identity Theft Resource Center. And according to the IBM report, 47% of breaches in its study were caused by a malicious or criminal attack.

“As you see the rise of malicious organised criminals, they become harder to track and trace and remediate,” Zedeloff said. “These criminals on the dark web are collaborating, sharing techniques and malware and when they break in, they are very good. They are able to stay on systems longer, they are stealthier and therefore they are more costly for organisations.”

While consumers who are affected by a breach may be provided identity theft insurance, there’s still a few things they can do to take their security into their own hands, Zedeloff said.

First, never use the same password for a service and change passwords regularly. Second, make sure to have the latest security on all of your devices and use two factor authentication when available. And last, keep an eye out for any kind of suspicious activity. Whether it’s a shady email, a friend request from someone you don’t know or odd activity on any of your accounts, be proactive in monitoring everything from your social accounts to your bank accounts.

NOW WATCH: How to make texting on your iPhone as private as possible

NOW WATCH: Tech Insider videos

Business Insider Emails & Alerts

Site highlights each day to your inbox.

Follow Business Insider Australia on Facebook, Twitter, LinkedIn, and Instagram.