Your data enters a pipeline

The moment someone submits their details on a phishing page, that information is transmitted to the attacker, often within seconds. From there, it gets bundled with data from other victims and sold in bulk on Dark-Web forums.

These bulk archives are relatively cheap because they are raw and unverified. A buyer cannot know which entries are still active, which passwords have been changed, or which accounts have value. So a second group enters the picture: analysts who sort and verify the data.

Sorting, verification, and resale

These buyers test credentials against live services to confirm they still work. They check whether the same password is reused across other accounts, and they cross-reference entries with data from older breaches to build a fuller picture of each individual. What comes out the other end is a verified dataset worth significantly more than what was paid for it, and it gets resold at a higher price.

Account access is priced by value. Access to bank accounts and cryptocurrency platforms commands the highest prices; social media accounts and messaging apps are cheaper but still traded in volume because they are useful for launching further attacks against the victim's contacts.

The follow-up attack

Once a cybercriminal purchases a verified profile, the original phishing incident is almost beside the point. The attacker now knows who the victim is, where they work, which services they use, and potentially has access to their accounts. That information gets used to craft targeted attacks: a convincing email impersonating a senior staff member, a message to a client pretending to be the victim, or an extortion attempt using compromising material pulled from a hacked account.

This is the part most business owners never connect back to the original click. A staff member's credentials stolen in a phishing attack this month can be the starting point for a business email compromise attempt six months from now.

What to do if your business has been affected

The window for action is short, but the actions themselves are straightforward. Any staff member who entered credentials on a suspicious site should change that password immediately across every service where it is reused. If payment details were entered, the relevant cards need to be cancelled, not just monitored. Two-factor authentication should be enabled on any account that supports it, using an authenticator app rather than SMS where possible.

Beyond the immediate steps, it is worth reviewing which accounts your staff have access to and whether those access levels are still appropriate. A credential compromised today is as dangerous only as the access it carries.

If you would like help reviewing your business's exposure or putting response steps in place, get in touch. This is exactly the kind of situation where having a managed-IT provider on your side makes a real difference.