Your Site's Password Is for Sale on the Dark Web
Digital Cybersecurity

Your Site's Password Is for Sale on the Dark Web

15 billion stolen credentials circulate on the dark web. Yours could be among them. Find out how to protect yourself before it's too late.

A126 Team 4 min read

It is not a question of "if". It is a question of "when".

As you read this article, somewhere in the world someone is selling packages of stolen credentials. Emails, passwords, phone numbers. Perhaps even yours.

The price? Less than a coffee at the bar.

The crime price list

According to the latest research by Kaspersky, published a few days ago, on the dark web criminals sell verified credential packages starting from 50 dollars for wholesale batches. But if you buy retail, prices drop even further: personal documents for 15 dollars, credit cards from 6 dollars, email accounts for a few euros.

Italian payment cards? According to NordVPN they cost on average 9.34 euros each. We are among the most "expensive" in Europe. A record we could do without.

But the most disturbing figure is another one: around 15 billion stolen credentials circulate on the dark web. Two for every inhabitant of the planet.

Italy in the crosshairs

If you think these things only happen to big American companies, the numbers will wake you up fast.

The Clusit Report 2025 is merciless: Italy suffers 10% of global cyberattacks, despite representing less than 2% of world GDP. In the first half of 2025, serious attacks rose by 36%. 80% of incidents are classified as "critical" or "serious".

And guess who the favourite targets are?

SMEs. 43% of cyberattacks hit small and medium-sized enterprises. The ones that think they are "too small to interest hackers". The ones with the WordPress site not updated for months. The ones with the password "admin123".

How they steal your credentials (without you noticing)

You don't need genius hackers in hoodies in dark basements. Most thefts happen in mundane ways:

Phishing. In 2025, more than 131 million phishing links were clicked in Europe. That email from the bank asking you to "verify your details"? It is probably fake. But 58% of employees cannot recognise it.

Reused passwords. Do you use the same password for your company site, your email and Netflix? If one of the three is breached, they all fall.

Outdated plugins. That WordPress plugin you haven't updated in 8 months? It is a wide-open door. Criminals use automated scanners that search for known vulnerabilities 24 hours a day.

Sites you registered on years ago. Remember that forum from 2018? That one was breached. And you had the same password as now.

The bill to pay

When your site gets breached, the damage is not only technical.

According to the Clusit Report, the average cost of an attack for an Italian SME is around 59,000 euros. But it can easily rise above 300,000 euros if you have an e-commerce site or handle sensitive data.

And we are not just talking about money:

  • Business shutdown for days or weeks
  • Loss of customers who no longer trust you
  • GDPR fines if you lose personal data
  • Reputational damage that is hard to recover from

The average ransom demanded from an SME for a ransomware attack? 35,000 dollars. And paying does not guarantee you get your data back.

The truth no one wants to hear

Only 15% of Italian SMEs have a structured approach to cybersecurity.

Translated: 85% are flying blind, hoping it won't happen to them.

But cybercriminals do not choose their victims one by one. They launch automated attacks on thousands of sites at once. If yours has a flaw, they will find it. It is not a question of "if". It is a question of "when".

What you can do now (seriously)

You don't need to spend a fortune. You need the basics done well.

1. Check whether you have already been breached. Go to haveibeenpwned.com and enter your email. You will find out which data breaches it ended up in. If the answer is "none", you are lucky. But change your passwords anyway.

2. Unique and complex passwords. A different password for each service. Use a password manager (Bitwarden is free and excellent). Enable two-factor authentication wherever possible.

3. Update everything. Now. WordPress, plugins, themes. Everything. Today. That orange banner you have been ignoring for weeks could be the only thing between you and a disaster.

4. Automated and tested backups. An untested backup is like an insurance policy you have never read. Make regular backups, keep them off the main server, and every now and then try restoring them.

5. Staff training. 35% of incidents in Italy are caused by social engineering. It only takes one employee clicking the wrong link. Invest in training, even just half an hour every three months.

Not tomorrow. Today.

Your credentials could already be for sale as you read these lines. The dark web never sleeps. The automated scanners never stop. Criminals make no distinction between the multinational and the small provincial business.

The only difference? The multinational has a security team. You probably don't.
But you can have the basics. And the basics, done well, stop 90% of attacks.

The best time to take care of your site's security was yesterday. The second-best time is now.

Share this article