Hackers are guessing your credit card details - and there's nothing you can do about it

Credit card information for sale
(Image credit: Shutterstock)

Cybersecurity researchers have revealed hackers have discovered a way to find card numbers without breaking into a database, and there’s also a booming underground black market for them. 

Researchers at popular VPN service provider, NordVPN analyzed statistical data that was collated by independent researchers from dark web markets and learnt that most of the card numbers sold on the dark web are brute forced.

The attackers are able to pull this off because the digits on most cards follow a fixed pattern, and can be deduced. For instance, the first couple of digits indicate the financial service provider, while the sixteenth is a checksum, and so on. Furthermore, the CVV is made up of three digits, which also helps with the guesswork.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

“Clever hackers can significantly cut down how many numbers they need to guess and check to find your payment card number. In fact, researchers at Newcastle University estimate that an attack like this could take as few as six seconds,” note the researchers, adding that an average hacked card’s data costs less than $10.

Numbers game

Crunching the available data, NordVPN says that of the 4,481,379 stolen cards, the maximum (1,561,739) belonged to US citizens. By comparison, only 134,607 cards for sale on the dark web belonged to UK residents. 

Also, the researchers discovered that debit cards were more common than credit cards, which is particularly worrisome since NordVPN says that debit cards don’t have the same level of protections as credit cards. Furthermore, Visa cards were the most common, followed by Mastercard, and American Express.

“There is little that users can do to protect themselves from this threat short of abstaining from card use entirely,” note the researchers, suggesting that users should keep an eye out for suspicious entries in their statements. 

Shield yourself online with these best identity theft protection services

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
Dark Web cybercriminals are buying up ID to bypass KYC methods
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
Cartoon illustration of multiple smartphones
Are you oversharing? These are the 10 pieces of information you don't want to give away – ranked
Latest in Security
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Dark Web monitoring
A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
Latest in News
FCC filing for the Nothing CMF Buds 2 Plus
Nothing’s next-gen CMF cheap earbuds slated to arrive within the month, but don’t expect hi-res audio support
John Loeffler holding the Ryzen 7 7800X3D
Great news! The best gaming CPU ever made is finally available for it's original MSRP again
Garmin Instinct 3
A new Garmin study hints at the link between burning calories and happiness, and I've got good and bad news
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
MacBook Air M4
Apple's rumored foldable iPad tipped to launch sooner than expected with an exciting software twist
A phone displaying the Google Messages logo
Google Messages could finally be getting this WhatsApp-style group chat feature