Sustainability
The socio‑economic and environmental context has made the transition towards sustainable business models no longer postponable.
Learn more
Press
In the first half of 2026, newly exposed data circulating on the dark web revealed increasingly detailed information about victims. In particular, the number of unique records circulating on the dark web reached 2.5 billion, a valuable resource that cybercriminals can leverage to build detailed profiles and make scams, phishing attempts, and identity theft more effective.
Phishing2, smishing 3, vishing4 and spear phishing5 continue to be among the most significant threats observed in the first half of the year. Added to this are cyberattacks based on artificial intelligence, which use increasingly realistic audio and video deepfakes and, at the business level, flawless e-mails that are difficult to distinguish from genuine communications. In addition, stealer-as-a-service6 malware, capable of capturing a large amount of data and contextual information from infected devices, continues to spread.
These are some of the findings from the CRIF Cyber Observatory, which examines the vulnerability of individuals and companies to cyberattacks. It highlights the key trends relating to data shared on both the dark web and open web.
Italy is certainly not immune to this threat. In the first half of 2026, Italy ranked 4th in Europe (6th in the global ranking) with regard to the number of compromised e-mail addresses circulated on the dark web. Italy was also positioned 6th in Europe (and 22nd in the global ranking) for the amount of credit card data in circulation, a significant indicator of vulnerability. In addition, Italy was 16th in Europe (and 51st in the global ranking) for phone number exposure, a key element in many online scams such as smishing.
“Protecting your personal data is more important than ever. Online fraud is becoming increasingly sophisticated and credible, with AI-based tools such as deepfakes, personalized phishing, and advanced social engineering techniques that leverage personal information often found online or from data breaches. In this context, personal awareness is the first line of defense. At CRIF, we continue to promote a culture of digital security by helping individuals and consumers protect their identities and adopt informed behaviors to recognize and prevent emerging cyber threats,” commented Beatrice Rubini, Executive Director at CRIF.
Infostealer Malware: A Growing Phenomenon
The CRIF Cyber Observatory highlights a steady increase in the circulation of data stolen through infostealer malware, a threat that reached significant levels in the cyber landscape during the first half of 2026. This type of malware is primarily spread through phishing campaigns and counterfeit software and operates silently, collecting credentials and other information from digital devices and passing it on to cybercriminals. The stolen data is then circulated on the dark web as ULP archives (URL, Login and Password) or as richer datasets that include information about the victim and the compromised device. The stealer-as-a-service model, which makes malware, control panels, manuals, and guides available to people without technical expertise, lowers the access barriers for cybercrime, helping to spread the phenomenon.
By analyzing the e-mail addresses in ULP archives, it was possible to classify compromised accounts by country. Italy remains a primary target, ranking third globally, after the United States and France, in terms of the number of accounts stolen and circulated on the dark web through infostealer malware.
Eastern Europe is the epicenter of this criminal industry, with Russia leading the development and commercialization of the main malware on the market. However, in recent years secondary but extremely active crime hubs have also emerged in other areas, notably Southeast Asia and Brazil.
Data Combinations Most Exposed to Fraud
During the first half of 2026, digital credentials continued to rank among the most vulnerable forms of personal data, underscoring their central role as a preferred target for cyberattacks. In particular, the most widespread and vulnerable types of data on the dark web are, in order of importance: passwords, e-mail addresses, usernames, phone numbers, and first and last names.
Looking at the main combinations of exposed data, it can be seen that, in the first part of 2026, the combination of credit card number with security information and expiry date was recorded in 99.8% of cases and is rising sharply: this is worrying because of the risk of financial fraud. Password-related combinations were particularly prevalent, with passwords appearing alongside e-mail addresses in 95.9% of cases and being associated with usernames in 96% of cases. This data confirms that account theft continues to be a primary target for hackers, underlining the need for good password management practices. Phone numbers are another prime target for cybercriminals: they are associated with a password in 61.7% of cases, and with the person’s first and last names in 18.8% of cases.
| Key data combinations at risk of fraud | H1 2026 | % Variation vs H2 2025 |
|---|---|---|
| Full credit card no. + first and last names | 99.8% | +100% |
| E-mail + password | 95.9% | +5% |
| Username + password | 96.0% | +12.2% |
| Full address + phone number | 73.8% | +55.7% |
| Telephone number + password | 61.7% | +100% |
| Phone number + first and last names | 18.8% | -64.7% |
Cross-referencing multiple pieces of personal information makes it easier for cybercriminals to reconstruct detailed profiles of their victims, resulting in much more effective social engineering attacks. In particular, contact details can be used to carry out targeted fraud such as spear phishing and Business E-Mail Compromise (BEC) attacks, also known as CEO Fraud, where criminals pretend to be executives or top-level corporate figures in order to convince employees to transfer funds or share confidential information.
Most Frequent Types of Accounts on the Dark Web
Through a qualitative analysis of the contexts in which this information circulates, the CRIF Observatory revealed that, excluding e-mail services, usernames found on the dark web were primarily linked to service accounts, such as job portals and online news outlets, which account for the largest share at 26.6%. This is followed by accounts related to social networks (20.8%) and to forums and websites (16.3%).
| Most frequent types of accounts found on the dark web | H1 2026 | % Variation vs H2 2025 |
|---|---|---|
| Digital services and subscriptions | 26.6% | -52.4% |
| Social networks | 20.8% | +82.9% |
| Forums and websites | 16.3% | +100% |
| Public sector bodies/institutions | 12.4% | +100% |
| Gaming | 5.8% | -24.1% |
| E-commerce platforms | 4.4% | -15.1% |
| Financial services | 3.9% | +100% |
| Streaming services | 3.9% | +100% |
| Other | 2.4% | -14.2% |
Stolen credentials can be used for a variety of purposes, such as to hack victims’ accounts, fraudulently use services, send messages with money requests or phishing links, or spread malware or ransomware to extort or steal money. In this scenario, the “human factor” continues to play a crucial role in this type of data theft: user carelessness and the use of weak or reused passwords are among the most common causes.
Through the qualitative analysis of the domains of e-mail accounts exposed on the dark web, the CRIF Observatory shows a clear prevalence of personal addresses, representing 92.1% of the total, while business accounts stand at 7.9%. This trend suggests, on the one hand, that private users continue to provide inadequate protection for their digital data, thereby remaining the preferred target of cybercriminals; on the other hand, it indicates that businesses, while investing more and more in security measures, are not immune.
Countries Most Affected by Data Theft
In terms of the countries most affected by online e-mail and password theft, the USA is in top spot, followed by Russia, Germany, France, and the UK, with Italy ranked 6th.
With regard to the illicit exchange of credit card details, the USA is the most affected country, followed by Russia and the UK, while Italy ranks 14th in the global ranking, climbing 8 places compared with last year.
The ranking of the continents most affected by the exchange of stolen credit card data sees North America at the top (55.9%), ahead of Europe (18.8%). They are followed by Asia (13.9%) and South America (6%). Africa stands at 3.2%, while Oceania (1.3%) remains at the bottom of this unenviable ranking.
Focus on Italy
According to the CRIF Cyber Observatory, hacker activities continued to pose a significant threat in the first half of 2026, with an increase in the share of users receiving alerts relating to the theft of monitored data on the dark web. Overall, 32.3% of users received at least one alert.
Among Italian consumers alerted by CRIF’s protection services, the most affected age group was 51-60 year olds (26.7%), followed by the 41-50 age group (26.6%), and the over 60s (20.3%). In terms of gender, men account for the majority of users sent an alert (64.3%).
The regions with the highest number of alerts were Lombardy (15.7%), Lazio (12.3%), Sicily (11.3%), Emilia-Romagna (9.7%), and Piedmont (9.5%), but proportionately it was the inhabitants of Umbria, Molise, Lazio, Piedmont, and Friuli-Venezia Giulia who received the most alerts. Geographically, the South (29.2%) and the Northwest (27.5%) had the highest number of alerts, but proportionately it was the inhabitants of the Northeast and Center who received the most alerts.
In the first half of 2026, the most commonly identified data on the open web, in other words, publicly accessible information, was e-mail addresses (51.4%) and residential addresses (16.3%), followed by tax codes (14.8%), phone numbers (14.3%), and usernames (3.1%). On the dark web, on the other hand, it was e-mail credentials that were most frequently found, followed by phone numbers, with tax codes in third place.
1Infostealer: Malware designed to automatically steal confidential information from infected devices.
2Phishing: Cyber fraud aimed at stealing personal information through deceptive e-mails.
3Smishing: Cyber fraud through SMS or messaging apps such as WhatsApp.
4Vishing (voice phishing): A cyber scam that uses phone calls or voice messages to steal personal data.
5Spear phishing: A cyber scam that uses personalized messages to steal information from targeted victims.
6Stealer-as-a-service: A criminal service offering malware designed to harvest credentials, personal data, and financial information.