It’s Not Hard to Find Scammers Selling Credit Card Information on Major Social Media Sites

Platforms say that violates their rules, but some of the posts have lingered online for years.

Getty Images

Fight disinformation: Sign up for the free Mother Jones Daily newsletter and follow the news that matters.

Major technology companies have let their platforms become home to one of the earliest scourges of the internet—credit card based cybercrime.

In the wake of a recent Wired story which found over 70 Facebook groups created to sell stolen credit card information, Zach Allen, director of threat operations at ZeroFOX, a cybersecurity company, ran his own analysis targeting a variety of platforms, including YouTube, Reddit, Medium, and Github.

Allen told Mother Jones that he’d found dozens of instances of internet criminals appearing to be openly selling stolen credit card information on those platforms in just about 15 minutes, and was confident that with more time, he could have found many others. It wasn’t hard: Scammers frequently included common terms indicating fraudulent or stolen card information—like “credit card insider” and “carder”—in their usernames.

While credit card scammers often operate on harder to access parts of the internet, using mainstream platforms can help lower the barriers to entry to capture new business by providing a wider audience of people seeking to buy the numbers. It can even help scammers scam would be credit card scammers by taking money from customers and never actually coming through with credit card information.

Many of the posts Allen found were as recent as the last several months, however, some were posted within the last several years—some on Github appeared to have on the site since 2016 without being noticed.

“This is a large and persistent issue and much broader than just Facebook. Carders are marketing across the full range of ‘social’ platforms,” Allen wrote in a document accompanying his findings.

After being alerted to Allen’s findings by Mother Jones, the tech companies quickly responded, pointing to their existing rules barring the content.

Google immediately deleted most of the flagged examples, saying they violated terms of service. A spokesperson said in a statement that “YouTube has strict policies that prohibit the sale of many illegal or regulated goods, including stolen credit card information. We quickly remove videos violating our policies when flagged by our users.”

Reddit said in a statement that its “site-wide policies prohibit content that shares personal and confidential information, and this is inclusive of credit card information. Communities focused on this content and users who post such content will be banned from the site.”

Allen says the massive size of technology platforms and the vast amounts of information shared on them can make it difficult to address such cybercrime. “It’s easy to criticize, but when you see the swaths of data and scale of the problem they’re dealing with, you can see how difficult it is,” he said.

Still, If Allen was able to find such content with a search tool, ostensibly multibillion-dollar companies would be able to as well.

Cybercrime isn’t a new issue for the platforms, and while they’ve taken steps to curb it, egregious examples have still slipped through the cracks, suggesting that some companies might not have prioritized the issue enough. In August, for example, Motherboard found that Facebook had hosted stolen Social Security numbers and other sensitive, identifying information for years.

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate