The New IT Reality — Part 9 of 12
A series examining how technology, AI, and cyber threats are reshaping business.

Right now, as you read this, there is a marketplace where someone is selling login credentials for Greek businesses at approximately two euros per account. Full identity packages — name, tax identification number, bank details — go for fifteen euros. Your company's database? Price negotiable.

This is not speculation. This is the dark web, and it operates with the efficiency and customer focus of any legitimate e-commerce platform — except everything for sale was stolen from people and organisations like yours.

Beyond the Myths: What the Dark Web Actually Is

The popular image of the dark web is a shadowy digital underworld populated by hooded hackers. The reality is far more mundane — and far more unsettling. Dark web marketplaces are structured commercial operations. They feature product listings with detailed descriptions, user reviews and seller ratings, escrow payment systems that protect both buyer and seller, dedicated customer support channels, and return policies for defective "products" (credentials that no longer work, for instance).

These are not disorganised criminals operating from basements. They are businesses, complete with marketing strategies, competitive pricing, and loyalty programmes. Some of the larger marketplaces have processed hundreds of millions of euros in transactions before being taken down by law enforcement — only to be replaced by successors within weeks.

What Is for Sale — and What It Costs

Research from institutions including the Rand Corporation, Privacy Affairs, and numerous cybersecurity firms has catalogued the going rates for stolen data. The figures are sobering in their modesty:

  • Email credentials: €1–3 per account. At this price, attackers can afford to buy thousands and test them against other services, exploiting the password reuse that most people still practise.
  • Credit card details with CVV: €5–15 per card. Cards from EU countries with higher spending limits command a premium.
  • Full identity packages (name, date of birth, national ID, tax number, bank account, utility bills): €10–30. These enable identity fraud, fraudulent loan applications, and social engineering attacks against the victim's employer.
  • Corporate databases: €100–10,000+, depending on size, freshness, and the industry involved. A database of customer records from a financial services firm is worth significantly more than a newsletter subscriber list.
  • Healthcare records: €50–250 per record — the most valuable category of personal data. Medical records contain enough information for comprehensive identity theft and cannot be easily changed, unlike credit card numbers.
  • Zero-day exploits: €10,000–500,000+. These are vulnerabilities unknown to the software vendor, and their value reflects the unrestricted access they can provide to target systems.

Consider the economics. If a hacker breaches a company database containing 50,000 customer records, even at the low end of the market the haul is worth hundreds of thousands of euros. The risk-reward calculation overwhelmingly favours the attacker.

The Supply Chain of Stolen Data

Stolen data follows a supply chain as structured as any legitimate commodity. It begins with a breach — whether through phishing, exploitation of a vulnerability, or an insider threat. The initial attacker may sell the raw data in bulk to a broker, who then sorts, verifies, and repackages it for different buyers. Credentials are tested and categorised by value. Personal data is enriched by combining it with information from other breaches. The refined product is then sold to end users: fraudsters, corporate espionage operators, or state-sponsored actors.

This is the critical point that most organisations fail to grasp: data is not stolen once. It is stolen, sold, resold, combined, repackaged, and weaponised repeatedly over months and years. A breach from 2022 can fuel targeted attacks in 2026 because the stolen data has been merged with newer information to build comprehensive profiles of individuals and organisations.

The Three Currencies of the Modern Economy

We are often told that data is the new oil. This is an understatement that obscures the true nature of the shift. The modern digital economy runs on three currencies: knowledge, compute power, and personal data. Of these, personal data is the only one that is routinely stolen in bulk and traded on criminal marketplaces.

Unlike money, stolen data does not expire. A stolen credit card can be cancelled. A stolen password can be changed. But a stolen identity — your name, your national identification number, your biometric data, your medical history — cannot be un-stolen. It exists permanently in databases controlled by people whose interests are directly opposed to yours.

The Greek Reality

Greece is not exempt from this economy. Greek personal data — AFM (tax identification numbers), AMKA (social security numbers), and associated personal details — are increasingly appearing on dark web marketplaces. Several factors make Greek organisations particularly vulnerable:

Delayed detection. Greek businesses often do not discover they have been breached until their data surfaces on the dark web or is used in a subsequent attack. The average time to detect a breach globally is 194 days. In Greece, anecdotal evidence suggests it may be significantly longer.

GDPR notification obligations. Under GDPR, organisations must notify the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of a personal data breach. When data is discovered on the dark web, this clock starts ticking — and many organisations are unprepared for the procedural and legal obligations that follow.

The "it won't happen to us" mentality. This is, without exaggeration, the single greatest risk factor for Greek businesses. The assumption that cybercriminals only target large multinational corporations is dangerously incorrect. Small and medium enterprises are targeted precisely because their defences are weaker and their data is still valuable.

Interconnected exposure. Even if your organisation has not been directly breached, your data may be compromised through a supplier, a partner, or a service provider who has. Supply chain breaches account for an increasing proportion of data exposure incidents.

Dark Web Monitoring: Finding Your Data Before It Is Used Against You

Dark web monitoring services continuously scan marketplaces, forums, and data dumps for indicators related to your organisation — domain names, email addresses, IP ranges, employee credentials, and proprietary information. When matches are found, you are alerted and can take action: forcing password resets, revoking compromised credentials, notifying affected individuals, and strengthening defences against the specific attack vectors that the exposed data enables.

This is not a luxury service for large corporations. It is a fundamental component of any organisation's security posture. IWH provides dark web monitoring and breach assessment services tailored to Greek and European organisations, including GDPR-compliant notification support when compromised data is discovered.

The Uncomfortable Truth

If your organisation has ever experienced a breach — even a minor one, even one you considered inconsequential — your data is almost certainly already on the dark web. If your employees use corporate email addresses to register for third-party services, some of those credentials have likely been exposed in breaches of those services. If your organisation has been operating for more than a few years, the probability that some of your data exists on the dark web approaches certainty.

Key Takeaway
The dark web is not a distant threat — it is a functioning marketplace where stolen data, including data from Greek businesses, is bought and sold daily. Your data does not expire once stolen; it is reused, combined, and weaponised over years. Proactive dark web monitoring is no longer optional — it is a necessary component of modern cybersecurity and GDPR compliance.

Money can be replaced. Data cannot be un-stolen. Once your client list, your financial records, or your employees' personal information is on the dark web, it stays there forever. The only question is whether you will find out from a monitoring service — or from a journalist.

Is your data already on the dark web?
IWH provides dark web monitoring and breach assessment services. Contact us to find out.