2.5 billion pieces of data ended up on the Dark Web in 2026: Italy among the countries most affected by phishing

2.5 billion pieces of data ended up on the Dark Web in 2026: Italy among the countries most affected by phishing

Credits: CRIF.

From January to June this year something like 2.5 billion unique data have circulated on the Dark Web. It is a huge wealth of information that cybercriminals can use to learn more about their victims. By cross-referencing emails, passwords, telephone numbers, names and other personal data, in fact, it becomes possible to build increasingly detailed profiles and make phishing, online fraud and identity theft more credible. Italy is among the countries most affected by the attacks, at least if we consider the number of accounts stolen through infostealers and subsequently spread on the Dark Web. This situation is illustrated byCRIF Cyber ​​Observatory (Financial Intermediation Risk Centre), which in a new report analyzed the presence of data exposed in the first half of 2026 on both the open Web and the Dark Web.

The infostealer phenomenon: sophisticated malware

Among the cyber weapons that have contributed most to the placing of over 2.5 billion unique data points on the Dark Web are infostealer. These are very sophisticated malware designed to automatically steal information from infected devices. They can be installed, for example, through phishing campaigns or counterfeit software and, once nestled on the user’s device, these malware can act silently by collecting credentials and other sensitive information present on the device to then send them to criminals. Once cybercriminals have obtained the data they were after, they can end it in ULP archivesi.e. collections that associate the address of a site (URL), username and password, or in even more complete and structured databases.

Making the situation even more worrying is the spread of the so-called “stealer-as-a-service” modelwhich greatly reduces the barrier to entry to use these IT tools. In practice, these malware are made available together with tools, control panels and operating instructions, which allow even people with relatively limited IT skills to use them to perpetrate cyber attacks. According to CRIF, the epicenter of this criminal industry is located in Eastern Europe, with Russia indicated as the main area of ​​development and commercialization of these malware, but other centers that have become particularly active and located in South-East Asia and Brazil should not be underestimated.

The amount of data available in bulk is worrying

What is worrying is not only the silence with which these tools operate, but also the amount of information that can be stolen in one fell swoop. In the first half of 2026 passwords are the most widespread datafollowed by emails, usernames, phone numbers and even first and last names. The fact that in 99.8% of the cases analyzed, credit card data are associated with the relevant ones safety information and expiration date. There password appears together with the email in 95.9% of cases and together withusername in 96% of cases. The telephone number, however, is associated with a password in 61.7% of cases and with a name and surname in 18.8%.

Image
The main combinations of data exposed to fraud. Credits: CRIF.

You understand well that the more information is found and combined together, the easier it becomes to carry out social engineering attacks, which exploit information about the victim to convince them to carry out certain actions. An example is spear phishingwhich uses personalized messages to steal information from victims who have been studied by cybercriminals thanks to the enormous amount of personal information available on them on the Dark Web.

Another type of sophisticated attack is the BECacronym for Business Email Compromisealso known as “CEO scam”: The criminal poses as a manager and tries to convince an employee to make a payment or share confidential information. The employee, seeing that those on the other side present convincing information and reasoning, could easily fall into the trap set by the cyber criminal who is impersonating his boss.

We must not forget about all these methods of attack AI-based toolscapable of making fraud even more credible. Among the examples cited in the report drawn up by CRIF are audio and video deepfakes, now increasingly realistic and, in the corporate sector, particularly carefully crafted emails that are difficult to distinguish from authentic communications.

Italy is sixth in the world: the situation

Zooming in on our country we see that in Italyat least in the first half of the year, the 32.3% of the users monitored by CRIF protection services have received at least one alert relating to data identified on the Dark Web. The age groups most involved are those between 51 and 60 years (26.7%), between 41 and 50 years (26.6%) and the over 60s (20.3%). Men represent 64.3% of alerted users. The regions with the highest overall number of alerts are Lombardy (15.7%), Lazio (12.3%), Sicily (11.3%), Emilia-Romagna (9.7%) and Piedmont (9.5%). Considering instead the relationship with the population, Umbria, Molise, Lazio, Piedmont and Friuli-Venezia Giulia emerge.

It is also clear from the report that Italy is among the countries most affected by cyber attacks. If we consider the number of accounts stolen and spread via infostealer malware we see that theItaly comes in third place: only the United States and France are worse than us and, respectively, are in first and second place in this unfortunate ranking.