Cybercrime DB

Carding Forums and Payment Card Fraud Markets

Stolen credit card markets operate like legitimate e-commerce platforms on the open web.

Columnist · · 12 min read
Cover illustration for “Carding Forums and Payment Card Fraud Markets”
dark web markets and forums · September 22, 2026 · 12 min read · 2,635 words

Carding is the trade in stolen credit card data, crypto wallets, and other financial credentials, and it runs on a full underground economy with jobs, storefronts, and reputations to protect. It's not just selling numbers. Carders also trade tricks for keeping a stolen card alive longer, checking its balance without tripping a fraud alert, and dodging platform bans, all of which makes this a service industry as much as a black market.

A line that matters more than most people realize: a carding forum is a discussion board with some shopping features bolted on, while a carding shop is a full automated storefront built to sell stolen card data at scale. Forums often host shops as sub-sections within the same platform. Kankaala calls carding a "more hardcore" strain of cybercrime, riskier and more lucrative than harvesting phone numbers or email addresses, and that distinction shapes who does it and how carefully they cover their tracks.

The commodification is the part that should genuinely unsettle people. F-Secure's 2025 analysis found carding shops with logos, branding, login dashboards, shopping carts, tiered pricing based on how fresh the stolen data is, and even a newsfeed. It's a business. A criminal one, sure, but run with the same instinct for user experience as any legitimate retailer. Understanding that structure, who plays which role, where the money moves, what's rising and what's dying, is what separates real threat intelligence from a scary headline about "dark web hackers." This piece walks through that structure.

The clearnet shift: why carding platforms no longer hide on Tor

Diagram: Carding's Price List: What Stolen Data Actually Costs. Visualizes: Show the underground market pricing tiers for stolen card data as a ranked or layered visual.

Most people still picture carding as an anonymized-network-only affair: hidden special addresses, special browsers, a trip into some digital underworld. That picture is out of date. Every site Kankaala evaluated in 2025 had a plain clear web address. Some kept an.onion mirror around, but it wasn't the front door anymore, the clear web was.

Her read on why is blunt: the open internet "has become a far safer space for all kinds of cyber criminals to operate." That's not a blip, it's a structural change in where this activity lives. Reporting through 2026 backs this up, showing both old-school darknet boards and newer surface-web hubs named side by side as active spots for buying stolen card data and cashout methods, according to an open-source review by factually.co.

Some of these sites promote themselves on the same platforms everyone else uses, Last.fm, Gravatar, Pinterest, even Reddit, according to F-Secure's findings. Carding sites blend into consumer web infrastructure like a con artist wearing a name tag from your own office. Any threat intelligence program that only watches Tor traffic or runs dark web crawlers is missing a growing chunk of the action, sitting in plain sight on the same internet where people check their fantasy football scores.

The forum and market structure: roles, sections, and how stolen cards are sold

Outpost24's KrakenLabs broke down what forums actually do in 2025, and it's more than a bulletin board for crooks. Forums handle the sale and sharing of stolen cards, both one-off and in bulk, and they announce new tools and techniques the way a trade publication covers new equipment. They run tutorials for newcomers, host debates about which fraud methods are working this month, and promote active card shops through banners and pinned threads, essentially running as an ad network for their own marketplace ecosystem.

The markets themselves follow a pattern, too. KrakenLabs found the same basic sections showing up again and again, including a stolen cards section for individual purchases, a dumps section for buying in bulk, a "Fullz" section (combined personal and financial data on a single victim), and checker tools that let a buyer confirm a card is still live before paying full price.

Pricing tells its own story. Individual cards run $3 to $150 per KrakenLabs. CVVs go for under $10 on cards and up to $25 on EU cards from sellers with a track record of high validity, according to the Infosec Institute. Dumps, meaning raw magnetic-strip data, run $20 to $125 depending on the country and how long the card has left before expiration. Fullz packages, the full identity kit with a Social Security number and date of birth thrown in, go up to $100 across multiple sources. Bare card data with no extras attached sells for under $5, per Merchant Cost Consulting.

Payment happens mostly in Bitcoin and Litecoin, and some transactions occur in Monero. Some markets even require payment before you're allowed to register an account, a clever way to filter out researchers and bots who aren't willing to put money down first.

A large chunk of this ecosystem is just teaching. Tutorials walk newcomers through bypassing anti-fraud systems, avoiding IP flags, and draining funds through mobile payment apps and crypto, according to F-Secure's research. And these communities are anything but stable. They run on escrow systems and "trusted seller" reputations, but internal scams are common enough that KrakenLabs describes trust within carder communities as actively eroding. Turns out thieves stealing from other thieves is not exactly a shocking plot twist.

Named active forums and markets in H2 2025 and into 2026

KrakenLabs named specific forums still active in the back half of 2025: Altenens (sometimes spelled Altenen), Club2Crd, Carders[.]biz, and WWH-Club. Altenen has been around longer than most, an English-language forum built around financial fraud and carding that's expanded into cracking, social engineering, and general hacking talk, according to SOCRadar.

On the market side, KrakenLabs listed Rescator, Brains'club (also called Brian's Club), KFCClubs, B1ack's Stash, PP24Shop, SharkShop, Vclub, Jerry's, Cards4Money, Ouhennie CC, and Bingo[.]lc as active. A separate, Russian-language forum called XSS appears repeatedly in threat intelligence reporting from Dexpose, tied historically to credential sales, phishing infrastructure, malware distribution, and initial access brokering, with close links to ransomware crews like REvil, LockBit, and Conti during their busiest years. Russian Market appears alongside Brian's Club in open-source threat intelligence reporting as a notable hub.

"Legendary Rescator," active since the early 2010s and active since the early 2010s and tied to Rescator Market, appears repeatedly across sources, a tenure that in internet-crime years counts as ancient. But activity level varies a lot from section to section. KrakenLabs describes most of what's publicly visible as "relatively unsophisticated," which is a polite way of saying the real professionals aren't the ones posting where analysts can see them.

The scale of payment card fraud these markets fuel

A fraudulent credit card transaction happens somewhere in the world every 14 seconds, according to coinlaw.io. That's the backdrop against which all this forum activity plays out.

U.S. Losses hit $13.7 billion in credit card fraud in 2025, the highest of any country, per coinlaw.io, though Merchant Cost Consulting puts the figure closer to $12.5 billion. The gap between those two numbers says something on its own: even the people counting this stuff can't agree on the count, which tells you how murky the underlying data actually is.

Card-not-present fraud, meaning purchases made without swiping a physical card, now makes up roughly 81% of all fraud cases globally, and accounts for 65 to 70% of total card losses, according to coinlaw.io. That tracks directly with carding, since almost all of it happens online. CNP losses are projected to hit $28.1 billion by 2026, about 40% above 2023 levels.

Merchants absorb a multiplier effect on top of the raw loss. SQ Magazine puts the total cost at $4.61 for every $1 actually lost to fraud, once you count chargebacks, investigation time, and lost goods, and estimates 3.3% of e-commerce revenue disappears to payment fraud annually. Dark web listings of stolen card details rose 20%, with 14.5 million card records up for sale, per coinlaw.io.

Recorded Future's annual payment fraud report, cited by Mastercard, found the number of stolen card records actually available for sale dropped almost 20% in 2025 compared to the year before. Losses are still climbing, supply is shrinking. That contradiction is a clue the ecosystem is under real strain, even while the damage keeps mounting. For cardholders, 51% have now experienced suspicious transactions two or more times, according to security.org. Once a card number leaks, it doesn't just get used once and vanish, it circulates for months or years.

How stolen card data is produced: infostealers, Magecart, and the upstream supply chain

None of this works without a supply chain feeding it, and that supply chain runs mostly on infostealer malware. These are programs built to quietly siphon off credentials, browser cookies, credit card numbers, and crypto wallet keys, then package the haul into "stealer logs" that get traded openly, according to DeepStrike's research.

The contrast with ransomware is instructive. Ransomware announces itself, it locks your files and demands payment. Infostealers do the opposite: they stay quiet, often undetected for long stretches, which makes them a far more durable and harder-to-catch source of stolen data.

The scale here is hard to overstate. Alluresecurity puts 2025 numbers at more than 1.8 billion stolen credentials, harvested from about 5.8 million infected devices, an 800% jump over recent years. A separate Flashpoint figure runs even higher: over 11.1 million infected machines producing more than 3.3 billion stolen credentials and cloud tokens. Stolen passwords and session cookies show up in 86% of breaches, according to shattered.io, making infostealer output the single most common way attackers get through the front door.

The delivery side is growing fast too. IBM X-Force logged an 84% year-over-year jump in infostealers delivered through phishing emails in 2024. Stolen credentials, many pulled straight from infostealer logs, were the second most common way attackers got initial access in 2024, involved in 16% of incidents, according to DeepStrike.

RedLine dominated the field from 2020 to 2023, responsible for 51% of infections, before a takedown disrupted it in October 2024, and Vidar picked up the slack afterward. RedLine dominated the field from 2020 to 2023, responsible for 51% of infections, before a takedown disrupted it in October 2024. Vidar accounted for 73% of infected hosts in early 2026, according to alluresecurity. Acreed launched in 2025 with stealthy injection techniques built to slip past endpoint detection tools. The infostealer landscape continued to diversify in 2025, with new strains emerging to target a broader range of devices and credential types.

The scale of what accumulates from this became visible in January 2026, when security researcher Jeremiah Fowler found an unprotected database sitting open with 149 million unique login-password pairs, including 48 million Gmail accounts, 17 million Facebook accounts, and 900,000 Apple iCloud accounts. Not one breach. A compilation, built entirely from infostealer logs scraped across who knows how many separate infections. Flashpoint's Global Threat Intelligence Report describes ransomware crews increasingly using stolen session cookies to operate as if they were the legitimate account holder, a shift Flashpoint sums up as cybercrime moving "from breaking in to logging in."

Diagram: Carding's Structural Decline: Supply Falls, Damage Rises. Visualizes: Visualize the contradiction at the heart of 2025 carding data: stolen card records for sale dropped nearly 20% year-over-year (Recorded Future), yet U.S.

Law enforcement actions in 2025 and how the ecosystem absorbs them

Takedowns happened in 2025, and they were significant ones. The BidenCash market fell in June, in an operation run by a federal law enforcement agency. Secret Service and FBI, backed by the Dutch National Police, The Shadowserver Foundation, and Searchlight Cyber. The site had accumulated millions of leaked credit cards and pulled in more than $17 million in revenue since it launched in 2022, according to Outpost24 KrakenLabs.

In July, Ukrainian law enforcement arrested the alleged administrator of XSS, acting on a request from French authorities with Europol's support, in an investigation led by French police working with Europol, per KrakenLabs and Dexpose. Reporting points to a coordinated operation that took down several more carding sites at once, scattering users and vendors across the ecosystem, according to factually.co.

None of this kills the underlying activity, though. Dark web carding markets have a habit of changing names, domains, and technical setups the moment a takedown hits. When a big player retires, like Joker's Stash did, copycats and successors fill the gap fast, per factually.co. Displaced communities tend to land on clearnet variants and smaller specialized forums, which loops right back to the shift described earlier: crime moving toward the open web because it's simply easier to operate there.

KrakenLabs points to something just as damaging as any police raid: internal scams and repeated shutdowns have "severely weakened confidence within carder communities." Telegram channel disruptions and higher barriers to entry get cited separately as further squeezing operational sustainability. Law enforcement is one kind of pressure. Carders robbing other carders might be doing just as much damage from the inside.

Signs of structural decline in carding and where criminal activity is migrating instead

KrakenLabs doesn't hedge on this point: carding, as a distinct criminal specialty, is in decline. That's the headline finding after a full 2025 pass through the ecosystem, not a side observation.

Several things are driving it. Law enforcement, payment networks, banks, and regulators have all rolled out better fraud detection, making the old carding playbook far less effective than it used to be. Trust inside these communities keeps eroding from scams and shutdowns. And there's a labor problem: not enough skilled operators left, and not enough new ones coming in to replace them.

Criminals aren't sitting idle, though, they're just moving to easier targets. Synthetic identities, account takeovers, and cryptocurrency scams are pulling cybercriminals away from carding, offering, in KrakenLabs' words, "fewer hurdles and greater success" than the traditional card-stealing grind. Some established carders are experimenting with AI agents to try to modernize their operations, but the same skilled-labor shortage raises real doubts about the adaptation's long-term staying power.

KrakenLabs has a name for the overall trajectory: "demographic collapse." Veteran carders are drifting toward more profitable crime, fresh recruits aren't showing up to replace them, and the ones who stick around are struggling to keep pace. Recorded Future's nearly 20% drop in stolen records for sale in 2025 backs this up from a completely different angle, using pure supply data rather than community sentiment.

The label "carding is dying" oversimplifies what's actually happening, though. Infostealers, stolen credentials, and the whole upstream supply chain continue producing card data at a steady pace. It's redirecting into synthetic identity fraud, account takeover schemes, and crypto scams. Anyone tracking this space needs to follow where the activity is going.

What this ecosystem structure means for security vendors communicating with practitioner audiences

Most surface-level security content still describes "dark web carding markets" like the structure, location, and direction of the whole thing are obvious and settled. They're not. Getting the clearnet shift right, getting the decline narrative right, tracing the infostealer supply chain accurately, and tracking the move toward synthetic identity fraud all take real, specific domain knowledge, not a quick skim of a crowdsourced encyclopedia and a confident tone.

Security engineers and threat analysts who work near this data catch shallow content almost instantly. Call a forum a market by mistake, place carding activity on Tor when it's largely moved to the clearnet, or describe a market that got taken down last year as still up and running, and a technically literate reader stops reading right there. Trust doesn't survive that kind of error.

The research that holds up names specific platforms, describes current market structures, cites disruptions with actual dates, traces the malware families feeding the supply chain, and points to the decline indicators with real numbers behind them. That kind of grounded, specific detail is what earns credibility with buyers who already know the subject well enough to spot a fake. Distinguishing carding from the fraud types it's bleeding into takes threat-informed research grounded in live criminal ecosystem data, not a generic framework pulled from a template. Cyberou works in that mode, building content off real threat intelligence rather than surface-level summaries, which is one credible way to close the gap between what a headline claims and what the underground economy is actually doing.

Sources

  1. Carding ecosystem: The fall of traditional financial cybercrime
  2. Carding 2025: How Crooks Sell Stolen Credit Cards & Teach Fraud | F‑Secure
  3. Card fraud in the deep web | Infosec
  4. Dark Web Forums 2026 | Status, Leaked Data & Onion Links
  5. Top carding darkweb sites
  6. Top 10 Deep & Dark Web Forums in 2026
  7. mastercard.com
  8. merchantcostconsulting.com

More in dark web markets and forums