Website peddling 26 million stolen credit and debit cards got hacked

But wait, it gets better.
 By 
Jack Morse
 on 
Website peddling 26 million stolen credit and debit cards got hacked
You get a card! You get a card! You all get cards! Credit: alexialex / getty

Not even professional digital fraudsters are immune to getting hacked.

This was made abundantly clear today following a report by Krebs on Security that an online shop offering approximately 26 million stolen debit and credit card numbers for sale was itself the victim of a hack. And, perhaps best of all, the site's entire purloined library might have been tainted in the process.

Krebs on Security notes that the carding site in question, BriansClub, appears to have gathered its stolen card numbers over the course of the past four years from both online and physical retail stores. The site's FAQ page explains that it "[sells] the dumps (track2/track1) with country, state, city, zip information (optional) and CVV2 cards."


You May Also Like

Track 1 and Track 2 refer to different bits-per-inch encoded data on credit cards' magnetic stripes.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

According to Brian Krebs, the noted cybersecurity reporter who runs Krebs on Security, last month he was sent a file allegedly containing BriansClub's entire database of stolen cards. Some of the cards in the file matched redacted versions on sale at BrainsClub, lending credence to the claim that the file was legitimate.

This hack might have simply been a reminder that nothing online is secure — even sites designed to thrive off that insecurity — were it not for what came next.

"All of the card data stolen from BriansClub," writes Krebs, "was shared with multiple sources who work closely with financial institutions to identify and monitor or reissue cards that show up for sale in the cybercrime underground."

In other words, there is a decent chance that a large percentage of these card numbers are now flagged as having been compromised.

To make this entire situation even more ridiculous, BriansClub was reportedly named after Brian Krebs as some sort of joke.

Notably, for all those stressing carde out there, BriansClub does claim to offer refunds. "For invalid cards you will get refund immediately," reads the site's FAQ.

We reached out to the BriansClub site admin via its support ticket page for comment on the alleged hack and the possibility that its cards are now worthless. We received no immediate response.

Perhaps whoever runs BriansClub is too busy processing refund requests.

Topics Cybersecurity

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
The European Commission got hacked for the second time this year
Europe flag

A controversial dating app uses credit scores to create matches
By Jack Dawes
Man using a smartphone to check his credit score to apply for a loan to the bank. Online credit score ranking check concept. - stock photo

Amazon has the Ninja Slushi on sale for $50 off and it comes with a free $15 Amazon credit
the Ninja Slushi with drinks around it on a pink and purple background

Reserve a new Galaxy device before Samsung Unpacked and get a free $30 credit
the Samsung logo on a purple oval with a green background


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


You can track Artemis II in real time as Orion flies to the moon
Victor Glover and Reid Wiseman piloting the Orion spacecraft

NYT Connections hints today: Clues, answers for April 2, 2026
Connections game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!