Two and a half billion records surfaced on the dark web in the first half of 2026. That is the figure from the Crif Observatory, and like most figures of that size it does very little work. Nobody has an intuition for two and a half billion of anything, which is precisely what makes a number this large easy to publish and easy to survive. The numbers underneath it are the ones worth reading slowly.
Italy ranks third in the world for accounts stolen and circulated through infostealers, behind the United States and France. Third, in a ranking where the position is not a prize.
The malware that does not make a scene
Ransomware announces itself. It locks the screen, posts a countdown and demands money. An infostealer works the other way round. It arrives through a phishing campaign or bundled inside counterfeit software, installs itself and harvests credentials and other information from the device, operating quietly. The Crif data shows this category growing.
The delivery routes are not exotic. Think of a cracked copy of software somebody did not want to pay for, a free utility that does what it promises and one extra thing it does not mention, an attachment dressed as ordinary correspondence. These are illustrations of the technique as it is described, not case files. What they have in common is that the victim does nothing dramatic and sees nothing dramatic.
None of this makes the theft undetectable. Monitoring services do raise alerts, which is why these numbers exist at all, and infections can be found and cleaned. The uncomfortable part is what an alert actually tells you: that something of yours is already in circulation. It reads less like an alarm than like a receipt.
Phishing, smishing and vishing have not gone anywhere, and they now arrive alongside AI-driven attacks using increasingly convincing audio and video deepfakes. In plain terms, a familiar voice on a call proves less than it used to. Controls that do not depend on recognition still hold: calling back on a number you already hold, confirming through a separate channel, requiring a second person to approve. What deepfakes are killing is the lazy version, the belief that recognising the voice is the verification.
The 99.8% worth reading precisely
Here is the figure I would put in front of every payments executive in Europe, with its boundaries intact. In the combinations the Observatory records, a credit card number appears together with the security code and the expiry date in 99.8% of cases, and that combination is growing fast. That is a statement about what the recorded combinations look like, not about every card on the planet, and a complete record does not convert automatically into a successful payment: issuers, fraud scoring and strong customer authentication can all still get in the way.
With the boundaries in place, the implication is unpleasant enough. The comfortable argument has always been that these elements live apart, that the number on its own does not take anyone far, that the three digits on the back add a layer. Whatever useful role the security code plays, it is not an independent factor held separately by the cardholder: it is another string printed on the same piece of plastic and typed into the same form. In what circulates, these fields travel together, and any reassurance that depends on their separation has earned its retirement.
The most common data types in circulation are, in order: passwords, email addresses, usernames, phone numbers, names and surnames. Which is to say the full kit for presenting yourself as somebody else to any institution whose identity check is a quiz.
Not your grandmother, and not a national census either
The demographic breakdown is useful if you read it for what it is. Among Italian private users alerted by Crif’s protection services, the most affected age brackets are 51 to 60 at 26.7%, then 41 to 50 at 26.6%, then the over-60s at 20.3%. Men account for 64.3% of those alerted. Lombardy, Lazio, Sicily, Emilia-Romagna and Piedmont lead by volume of alerts.
Read the denominator before building a theory on it. These are shares of one population: the private users those services cover and alert. They are not national infection rates. They say nothing about anybody’s job title, mandate or signing authority, and they do not show criminals selecting targets by age or gender. Who subscribes to credential monitoring in the first place is itself a filter on the sample. What the breakdown does puncture is the most comfortable story in circulation, the one in which the victim is always a bewildered pensioner who clicked the wrong thing. The brackets at the top of this table are people in the middle of their working lives.
Then there is where the credentials belong. Usernames found on the dark web are most often tied to service accounts, job boards and news portals, at 26.6%, ahead of social network accounts at 20.8% and forums and websites at 16.3%. Resist the easy inference: a credential in circulation is not evidence that the portal behind it was breached or handled anything badly. The question it legitimately raises is a design question, addressed to the whole sector. Why does reading three articles require an account and a password at all? Every service that insists on a credential it does not need adds one more item to the pile that can be carried out of an infected laptop.
Across countries, the United States leads for stolen emails and passwords, followed by Russia, Germany, France and the United Kingdom, with Italy sixth.
The word doing all the work
Which brings me to the vocabulary. Two and a half billion records were exposed. Exposed. A beautiful verb with no subject, as though the data had wandered off on its own, caught in a draught, left out in the rain.
Records do not expose themselves. Every one of them was collected by an organisation that decided it needed it, and held under decisions that real people took and defended in meetings. A headline figure will not tell you which decisions, and that asymmetry is the thing worth naming: the individual who receives an alert is described down to age bracket, gender and region, while everything on the other side of the exchange arrives in the passive voice.
The individual duties are real and worth repeating: unique passwords, a manager to hold them, multi-factor authentication wherever it is offered, and no pirated software. Do all of it. It reduces your own exposure, and enough people doing it would show up in the totals as well. What it cannot do is carry the whole weight of a number like this one, and it is very convenient for everyone else that the advice is always addressed to you.
Two and a half billion in six months is not a wave of personal carelessness. It is the output of an arrangement that treats personal data as an asset while it is being collected and as weather once it is gone. Until that changes, I would not bet against the same passive verb in the next report, nor against somebody calling it a wake-up call.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
