The silent thieves in our PC: so passwords, emails and accounts end up on the dark web

Cybercrime has never been so “rich”. In the first six months of 2026, the number of unique data in circulation reached 2.5 billion. A “treasure” of information that does not concern isolated codes, but actual …

The silent thieves in our PC: so passwords, emails and accounts end up on the dark web

Cybercrime has never been so “rich”. In the first six months of 2026, the number of unique data in circulation reached 2.5 billion. A “treasure” of information that does not concern isolated codes, but actual digital identikits that cybercriminals can use to build detailed profiles of victims, making scams and identity theft increasingly difficult to intercept. Not only that. In addition to threats that have now become traditional, such as phishing, during the first half of 2026 there was a notable increase in crimes based on artificial intelligence, capable of cloning voices and faces with audio and video deepfakes. A scenario, the one photographed in the latest report from the Crif Cyber ​​Observatory, which sees Italy among the countries most at risk. At a European level, our country ranks fourth for email addresses violated and put up for sale, sixth for the dissemination of data linked to credit cards and sixteenth for phone numbers stolen and used for smishing, scams via text messages or WhatsApp messages.

Infostealer, the silent threat

One of the fastest growing threats is represented by the so-called infostealers, malware designed to infiltrate victims’ devices completely silently through infected files or counterfeit software. Once inside the PC or smartphone, the virus automatically copies banking credentials, access keys and financial data without the user realizing anything. A “loot” which is then packaged in archives ready for the dark web. Italy ranks third globally for the number of accounts stolen via infostealers, surpassed only by the United States and France. According to the report, behind this wave of attacks there is a real map of global crime: if the technological base and the creation of viruses remain concentrated in Eastern Europe, under the leadership of Russia, in recent months new hacker groups have also been very active in Brazil and South-East Asia.

The “right” combinations

What also gives even more value to the data is the right combination between them, the intersection of information that can allow hackers, in the most extreme cases, to empty a bank account. According to the Crif report, in the first half of 2026 the most widespread and vulnerable types of data on the dark web are, in order: passwords, emails, usernames, telephone numbers, names and surnames. The security details of credit cards, including the secret code and expiry date, were intercepted and put on sale in 99.8% of cases of financial theft. As mentioned, it is essential for cybercriminals to find the “winning” combination: the password travels together with the e-mail address in 95.9% of cases and is associated with the username in 96% of violations.

One of the tables present in the Crif Observatory

Even the telephone number is now a primary objective, almost always combined with the password or name and surname. This puzzle of private information allows fraudsters to engage in social engineering, setting up tailor-made traps such as spear phishing or corporate attacks known as “CEO fraud”, where criminals pose as executives to pressure employees into making urgent transfers to overseas accounts. Taking a look at the profiles most present on the black market, after e-mail, job offer services and news portals stand out (26.6%), followed by social profiles (20.8%) and forums or websites of various types (16.3%). The victims are above all private citizens: the analysis of the violated domains shows an overwhelming prevalence of personal emails (92.1%), compared to 7.9% of company accounts.

The global map

The world ranking of email and password theft sees the United States in first place, followed by Russia, Germany, France and the United Kingdom, while Italy is in sixth place. In terms of cloned credit cards, the USA and Russia are always in first place, with our country in 14th place, eight positions higher than last year’s report. Instead, on a continental scale, North America is the area most affected by cloned card trafficking (55.9%), followed by Europe (18.8%) and Asia (13.9%).

Alerts in Italy

As for Italy, the observatory recorded a record increase in danger warnings sent to users. In the first six months of the year, as many as 32.3% of Italians protected by monitoring systems received at least one alert for data intercepted on the dark web. At a territorial level, the regions that record the highest volume of alerts are Lombardy (15.7%), Lazio (12.3%) and Sicily (11.3%), although proportionally it is the inhabitants of Umbria, Molise and Lazio who receive the most alerts. The traces left on the network, and consequently the cybercriminals’ loot, change depending on the environment. While mainly emails and physical addresses are intercepted on the web, the real threat travels on the darkweb, where the most “hot” data packages are put up for sale, such as telephone numbers and private access keys, ready to be transformed into yet another scam.