Dark Web Brokers Resell Old Breaches as New Corporate Data Leaks
Key Takeaways Dark web actors, primarily in Chinese-speaking communities, are marketing old breach data as new corporate leaks. These fraudulent listings flood dark web forums and Telegram channels,...
Key Takeaways
- Dark web actors, primarily in Chinese-speaking communities, are marketing old breach data as new corporate leaks.
- These fraudulent listings flood dark web forums and Telegram channels, often claiming millions of records from financial institutions and other companies.
- The tactic exploits resource-constrained security teams, diverting their attention and resources from genuine threats to investigate non-existent incidents.
- Analysis by Group-IB revealed that these datasets are composites of previously leaked information, often combined with generated or inconsistent data to appear legitimate.
Dark Web Brokers Deceive Organizations with Recycled Breach Data
A troubling trend has emerged across dark web marketplaces and Telegram channels: threat actors are actively peddling outdated breach data, falsely presenting it as newly acquired corporate intelligence. This deceptive practice, predominantly observed within Chinese-language cybercrime circles, is designed to mislead organizations into expending valuable resources on investigating non-existent data breaches.
Table Of Content
The proliferation of these fraudulent claims is placing an increasing burden on global security teams. Listings frequently advertise vast quantities of records, purportedly from banks, investment firms, and other corporations across various geographic regions. The sheer volume and velocity of these posts make it exceedingly difficult for already stretched security operations centers to distinguish authentic threats from fabricated noise.
The Anatomy of a Fake Leak
Cybersecurity firm Group-IB first identified this escalating phenomenon, tracing five principal data sources operating exclusively within Chinese-language dark web environments and Telegram. Their comprehensive investigation concluded that the majority of the advertised datasets were assembled from previously compromised information, incorporated fabricated entries, and lacked any indicators of a recent or ongoing corporate intrusion.
In a detailed report shared with Cyber Security News (CSN), Group-IB highlighted the extraordinary posting frequency of these sources, which routinely publish between 600 and 1,000 messages monthly. Such a volume would be unsustainable if each claim represented a genuine, new breach, further underscoring the deceptive nature of these operations.
The effectiveness of this tactic lies in its partial authenticity. Brokers strategically combine legitimate personally identifiable information (PII) from well-known historical breaches, such as the Facebook 2021 breach and the Eatigo 2020 incident, with generated or inconsistent data. This amalgamation inflates the purported record count and lends an initial veneer of credibility, often sufficient to induce panic within targeted organizations, even when a closer examination reveals the dataset’s inconsistencies.
The Obfuscation Game: How False Claims Distract Defenders
The primary danger posed by these lead data brokers is the opportunity cost they impose on defenders. Security professionals diverted to investigate these false alarms are pulled away from addressing actual, active incidents, inadvertently providing genuine threat actors with a broader window for undetected malicious activities.
Group-IB researchers meticulously tracked five prominent brokers operating in Chinese-language dark web spaces: Exchange Market (also known as Deepmix), Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources. These entities leverage Telegram channels and dark web marketplaces to distribute their alleged data packages. Aiqianjin, for instance, garnered nearly 5,000 subscribers on Telegram before it ceased operations in July 2024, illustrating the extensive reach of these disinformation campaigns.
Upon validating sample data from numerous listings, Group-IB analysts consistently observed the same pattern. Names and phone numbers were traceable to the Facebook 2021 dataset, password hashes linked back to the Eatigo 2020 breach, and email addresses matched records from the Truecaller 2022 leak. In every instance, brokers had artfully pieced together fragments from past incidents and rebranded them as freshly pilfered corporate data. Obvious inconsistencies, such as mixed-language values, anomalous translations, and database field names that defy legitimate conventions, became apparent upon cross-referencing.
What You Should Do
- Verify Data Structure: When confronted with a dark web leak claim, immediately cross-reference the advertised data fields (names, data types, record counts) with your organization’s actual internal records. Significant discrepancies are a strong indicator of a fraudulent claim.
- Validate Identifiers: Do not rely on a few seemingly legitimate email addresses or phone numbers. Perform thorough validation to confirm that a substantial portion of the identifiers in the sample data genuinely belong to your customer or employee base.
- Utilize Threat Intelligence: Leverage reputable threat intelligence platforms to cross-reference reported data against known historical breaches. This helps quickly identify if the “new” data is merely repackaged old information.
- Maintain a Calm, Evidence-Based Approach: Avoid knee-jerk reactions driven by urgency. Implement a structured, analytical process for incident verification to prevent wasting resources on fabricated threats.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.