Photo of a Login Box on Screen
© JMiks/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Nearly 34 million stolen Roblox credentials have surfaced on the dark web since 2021, Kaspersky said in a report on Thursday.

The report also notes a 112% increase in the average number of leaked accounts across across gaming platforms like Twitch, Electronic Arts, Sony PlayStation, and Steam.

Besides gaming platforms, there’s also a strong interest in stolen credentials for AI services on dark web markets. According to Kaspersky, there was a 33-fold increase in the number of ChatGPT credentials posted on the dark web in 2023 compared to the previous year.

“These accounts are often initially stolen using data-stealing malware and then leaked on the dark web via infostealer log-files, where they can be further monetized as valuable assets within the realm of cybercriminal activity,” the report explained.

A Record Number of Stolen Roblox Credentials

The large volume of stolen Roblox credentials poses a major threat to children, Kaspersky said.

According to the report, cybercriminals are able to harvest vast amounts of Roblox credentials as children are more susceptible to the social engineering schemes used to deliver info-stealing malware.

“For instance, cybercriminals can hide infostealers in files containing cheat codes to deceive young gamers. In some cases, this deception may appear genuine, as malicious download links can be posted on legitimate and popular social media platforms like YouTube,” Yuliya Novikova, the head of Kaspersky Digital Footprint Intelligence, said.

Despite the large volume of Roblox credentials on sale, Kaspersky’s report notes that Steam login details are more in demand than Roblox logins.

“Criminals target game accounts to steal valuable items, such as real money, in-game currency, and various in-game items, such as expensive skins. Steam accounts seem to be more appealing to cybercriminals criminals due to the potential to find and steal real money on them,” Novikova explained.

Demand for Compromised AI Accounts

According to Kaspersky, there was a dramatic increase in stolen credentials for OpenAI’s services, including ChatGPT, in 2023, with 664,000 records discovered on the dark web.

The report notes a spike in demand for ChatGPT accounts in March 2023, following the release of ChatGPT 4. This finding is echoed in a Check Point report from April 2023, which highlighted “an increase in discussion and trade of stolen ChatGPT accounts” on the dark web starting March 2023.

Check Point said cybercriminals were not only selling stolen premium ChatGPT accounts but also leaking credentials for free and offering tools to hack ChatGPT accounts.

Since March 2023, the demand for stolen ChatGPT accounts has stabilized, Kaspersky’s report said. “This suggests that demand for ChatGPT accounts will remain steady,” Novikova noted.

Besides ChatGPT, Kaspersky said AI-powered services, like Canva and Grammarly, are also being targeted, with over one million Canva credentials and around 839,000 Grammarly credentials leaked over the past three years.

How to Keep Your Credentials Safe

Kaspersky suggests using unique passwords for each service and enabling two-factor authentication (2FA) across all your accounts. The report also recommends dark web monitoring (particularly for businesses) to identify compromised accounts.

In addition to these tips, Kaspersky suggests using reliable security solutions to safeguard your devices and block info-stealers. For starters, we recommend using trusted antivirus software.

For more news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment