Report on the hack-for-hire market: attacks that phish 2FA to access email accounts cost $100-$400; such attacks can be prevented with physical security keys
Ariana Mirian / Communications of the ACM : Tweets: @uhoelzle and @dinodaizovi Tweets: Urs Hlzle / @uhoelzle : The bad news: a targeted attack on your account costs $100-300. The good news: Gmail/Google is the most expensive because it has the best security :-) Plus, a Security Key defeats all of these attacks since they're phishing based. So get one already! https://cacm.acm.org/... Dino A. Dai Zovi / @dinodaizovi : Love using market prices as a signal on where security improvements are working: https://twitter.com/...
Context & Ripple Effects
This report turns account takeover into a price list: the Google and UCSD study that contacted 27 hacking service providers found a working market where phished 2FA on an email account costs $100-$400, with Urs Hölzle noting Gmail commands the top of the range because its defenses are the strongest. Dino Dai Zovi's framing — market prices as a signal of where security is working — is the analytical hook.
The pricing data lands against prior coverage from both directions: the Iran-linked phishing campaign that bypassed SMS-based 2FA on US government officials' Gmail and Yahoo accounts showed the attack works even on high-value targets, while Google's Advanced Protection Program requiring two $20 physical keys already offered the fix the report says defeats every one of these attacks.
First-order effects
- Buyers of account-takeover services now face a published price floor of roughly $100 per target, and the report hands defenders (Google, email providers) a measurable benchmark: Gmail's premium pricing is direct evidence its security raises attacker cost.
- Users relying on SMS or app-based 2FA are the exposed population right now — the same phishing-based attacks the report prices were demonstrated in the wild against government officials' Gmail and Yahoo accounts.
Second-order effects
- Physical security key vendors get a demand catalyst backed by research rather than marketing: at $20 per key against a $100-$400 attack price, the economics argument writes itself, pressuring other email providers to match Gmail's pricing premium by adopting comparable hardware-key support.
- Hack-for-hire operators must absorb the cost of defeated attacks — if keys truly defeat the phishing vector, their pricing either rises toward harder targets or shifts toward alternative vectors like the third-party breaches behind the bulk of the 3.3 billion stolen credentials in the Google/UCB study.
Third-order effects
- Security effectiveness becomes legible through market prices rather than vendor claims — if attackers' quotes reliably track each provider's defenses, published pricing could function as a continuous, adversarial audit of platform security.
- The pattern points toward hardware-backed authentication becoming table stakes for high-value accounts, narrowing the hack-for-hire market to whoever cannot deploy keys and pushing attack volume toward breach-sourced credentials instead of live phishing.
The trend: Account takeover is maturing into a priced service market where quoted rates double as a public scoreboard for which platforms' security actually raises attacker costs.