Trend Micro report finds hacking or malware behind 25% of data breaches in last ten years, payment card data breaches up 169% in past five years
The price of your identity in the Dark Web? No more than a dollar — If you or your company is a victim of cyberattack, where does this stolen data go, and to what purpose?
Context & Ripple Effects
Trend Micro's report quantifies where a decade of breaches that compromised nearly 1B records in 2014 alone has led: identity data is now a commodity priced at roughly a dollar on the dark web, while payment card data — up 169% in five years — has become attackers' preferred target. The finding reframes earlier volume counts as supply-side metrics for a functioning stolen-data market.
The economics cut both ways: the same period saw remediation costs climb toward the $3.92M average IBM reported by mid-2019, meaning sellers monetize each record cheaply while buyers pay millions per incident. Later findings of 21M Fortune 500 credentials listed for sale confirm the market Trend Micro described kept scaling.
First-order effects
- Companies holding payment card data face a fivefold-accelerated threat surface — a 169% jump means card processors and retailers are now the highest-volume targets, not just large credential stores.
- Breach victims learn their exposed identities trade at commodity prices (~$1), so the direct harm is volume-driven resale rather than targeted exploitation of any single record.
Second-order effects
- With hacking/malware behind only a quarter of incidents, buyers of security spend shift budget from pure perimeter defense toward insider-risk and process-failure controls covering the other three-quarters of causes.
- Insurers and boards can now price breach risk against hard numbers — cost curves rising year over year per IBM's tracking — pushing cyber coverage premiums and mandated security controls upward for firms handling card data.
Third-order effects
- If stolen-identity pricing stays near $1 while remediation runs into the millions, the asymmetry favors attackers structurally — pointing toward regulation that forces breach-cost internalization onto breached firms rather than treating leaks as one-off losses.
- The persistent dark-web supply of credentials (Fortune 500 logins among them) pushes authentication away from static passwords toward models that assume credentials are already compromised.
The trend: Data breaches are maturing from episodic incidents into a liquid criminal marketplace where stolen identities are commodities sold for about a dollar while victim-side costs compound annually.