Skip to main content
Research

Two Years With Your Stolen Data: What the Underground Actually Does With Breaches

John Sabo 7 min read

Two Years With Your Stolen Data: What the Underground Actually Does With Breaches

I co-founded a company that recovered breached data sets. Over about seven years we recovered close to 400 petabytes of stolen records, built a classifier that profiled more than 200 data points per identity, and ran a passive DNS platform that watched 192 million domains and roughly 30 billion hosts.

That work gave me an unusual view of the underground economy. The most useful thing I learned is this: a breach is not an event. It is a schedule. The first month is the loud part. The next two years are the part that actually costs you money.

Here is how that schedule runs.

Week one: the dump

A breach usually surfaces as a file, a folder, or a post on a forum that sells them. The seller wants attention and a quick sale. Prices are often low because the data has not been sorted yet and the seller does not know what it is worth.

This is also the stage where a lot of companies find out, because the first buyer sells it again and someone tells a journalist. The news cycle lasts a week. The data lasts forever.

Weeks two to six: the sorting

This is where the real work happens and where most people stop paying attention.

Buyers run the raw dump through classifiers. A good classifier reads each record and decides what it is: an email address with a password hash, a name with a phone number, a corporate account with a job title, a payment record. It deduplicates against everything else the buyer already owns. It merges records that describe the same person into one profile.

That merging is the thing to understand. A single dump of your company's customer list is not very valuable. The same list joined to four older dumps is a detailed dossier on your customers, and it is worth far more than the parts.

Months one to six: cracking

If the dump contains passwords, someone is guessing them. Attackers use graphics cards, the same chips that render video games, to try billions of candidate passwords per second against stolen password hashes.

I built that kind of cracking platform, so I can tell you what makes it work: people reuse passwords. A password leaked from a hobby forum in 2019 unlocks the same person's work account in 2026, because it never changed.

Where a site used good password hashing and unique passwords, the cracking mostly fails and that data quietly rots. Where it did not, the record moves to the next stage within hours.

Months three to twelve: the use

Stolen credentials get spent. The patterns are consistent:

  • Credential stuffing, which is trying leaked username and password pairs against many other sites automatically.
  • Account takeover, where the attacker signs in as a real person and reads their mail. Business email compromise lives here: no exploit, just a valid login and a plausible invoice.
  • Payment fraud and gift card draining, using accounts that already have a card on file.
  • Session theft, where a stolen token lets an attacker skip the password and sometimes the second factor entirely.

Notice that none of this requires breaking into your network. It requires a login you already gave someone, reused somewhere else.

Months six to twenty-four: resale and recombination

The data does not get used up. It gets resold.

By this point the same record has appeared in several bundles, each one slightly better than the last. Sellers package it by industry, by geography, by income bracket. Someone buys your industry list specifically because a well-crafted email to a known customer of yours gets opened.

Two years out, the record surfaces in places that have nothing to do with the original breach. It turns up in a lookup site your customer finds while googling their own name. It turns up in a phishing email that greets them by their old address. It turns up in a scam that names their kid's school, because the merged profile includes a decade of unrelated leaks.

What this means for a business

You cannot un-leak data. You can shorten the window where it is useful, and you can notice when your name shows up.

Five things worth monitoring:

  • Your domain in new dumps. Watch for staff email addresses and corporate credentials appearing in fresh leaks. When they appear, the clock starts that day.
  • Password reuse across your staff. You cannot see their personal accounts, but you can require unique credentials at work, deploy a password manager, and turn on multi-factor authentication. Any one of those breaks most of this chain.
  • Session tokens and API keys. These leak through code repositories and browser extensions and they bypass passwords entirely. Rotate them on a schedule and watch for them in public places.
  • Your name-alikes. Watch for domains that resemble yours, because they get used against your customers. Watch for subdomains pointing at services you retired, because those can be claimed.
  • Your public footprint over time. A quarterly exposure report tells you what changed. One snapshot tells you almost nothing.

If a breach involves personal information, you may also owe notifications under state law. That is a legal question and you should ask a lawyer, not me. My point is simply that the notification deadline is usually shorter than the time it takes to figure out what was taken.

The part I would emphasize

I have watched companies spend their whole response budget on the first thirty days and nothing on the next two years. The thirty days feel urgent because everyone is watching. The two years are where the fraud, the account takeovers, and the angry customers actually happen.

The businesses that come out of this well do three unglamorous things. They assume the credentials are gone and rotate everything. They keep watching instead of declaring victory. They tell their customers the truth early, in plain language, which is the only thing that reliably protects a reputation.

Work with me

This is the service I call Deep Intelligence Research. I run exposure reports on your domains and your people, look at passive DNS and domain history, and research the actors and campaigns pointed at you. Ongoing monitoring is available if you want it to keep running after the first report.

Every engagement starts with a free 30-minute consult and a written quote. Bring a domain name and I will show you what is already public.

Book a free 30-minute consult at /book, or call 602.501.0772. I answer the phone.

John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere

JS

John Sabo

John Sabo — 30 years in cybersecurity, GoDaddy WAF architect

Work with me

Every engagement starts with a free 30-minute consult and ends with a written quote.

Book a free consult