Bots stole the internet data of 48,000 South Africans, and here is how much it sells for on the black web
According to NordVPN's study, at least five million people worldwide have had their online identities stolen and sold on bot markets. The organisation examined three main bot markets and discovered that 48,000 South Africans are victims, with stolen data selling for an average of R102 on the dark web. The term "bot" in this context

Bots stole the internet data of 48,000 South Africans, and here is how much it sells for on the black web

According to NordVPN’s study, at least five million people worldwide have had their online identities stolen and sold on bot markets.
The organisation examined three main bot markets and discovered that 48,000 South Africans are victims, with stolen data selling for an average of R102 on the dark web.
The term “bot” in this context does not relate to an independent programme; rather, it refers to data-harvesting malware, according to NordVPN.
Bot markets are internet marketplaces where hackers sell data taken from their victims’ devices via bot malware. The data is sold in packages that comprise logins, cookies, digital fingerprints, and other information — a hacked person’s whole digital identity.
“What differentiates bot markets from other dark web markets is that they can get large amounts of data about one person in one place. And after the bot is sold, they guarantee the buyer that the victim’s information will be updated as long as their device is infected by the bot,” said Marijus Briedis, CTO at NordVPN.
“A simple password is no longer worth money to criminals when they can buy logins, cookies, and digital fingerprints in one click for just R102.”
The Genesis Market, the Russian Market, and 2Easy were the three largest bot markets studied by the researchers. At the time of investigation, all of the marketplaces were live and available over the surface web.
The bot market data was produced in collaboration with independent third-party researchers that specialise in cybersecurity incident investigation. RedLine, Vidar, Racoon, Taurus, and AZORult are the most common forms of malware that steal data.
What information do hackers sell on bot markets?
- Screenshots of a device. During a malicious attack, a virus might take a snapshot of the user’s screen. It can even take a picture with the user’s webcam.
- Logins and other credentials. When a virus attacks the user’s device, it may grab logins saved to their browser. The research found 26.6 million stolen logins on the analyzed markets. Among them were 720 thousand Google logins, 654 thousand Microsoft logins, and 647 thousand Facebook logins.
- Cookies. These are also usually stolen from a user’s browser and help criminals bypass two-factor authentication. The research found 667 million stolen cookies on the analyzed markets.
- Digital fingerprints. A person’s digital fingerprint includes screen resolution, device information, default language, browser preferences, and other information that makes the user unique. Many online platforms track their users’ digital fingerprints to make sure they properly authenticate them. The research found 81,000 stolen digital fingerprints on the analyzed markets.
- Autofill forms. Many people use the autofill function for their names, emails, payment cards, and addresses. All of these details can be stolen by malware. During the research, 538,000 autofill forms were found on the analyzed market.
The ideal crime
The deadliest aspect of bot marketplaces, according to NordVPN, is that they make it easier for hackers to abuse the victim’s data.
“Even a rookie cybercriminal can connect to someone’s Facebook account if they have cookies and digital fingerprints in place, which help them bypass multi-factor authentication,” the group said.
After getting into a user’s account, a cybercriminal might attempt to contact others on the victim’s friends list and offer harmful links or request money transfers. They can also spread false information through the victim’s social media feed.
Information obtained through autofill forms or merely by snapping a device snapshot might assist these acts appear more genuine and trustworthy – “and you will have no way to detect who used your data”.
“Some tactics are even simpler. A hacker can, for example, take control of a victim’s Steam account by changing the password. Steam accounts are sold for up to $6,000 per account and can be easy money for a criminal,” said Briedis.
More advanced fraudsters purchase this information and use it to launch phishing attacks against organisations, impersonating workers.
“To protect yourself, use an antivirus at all times. Other measures that could help – a password manager and file encryptions tools to ensure that even if a criminal infects your device, there is very little for them to steal,” Briedis said.


