DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Japenese Payment Card Fraud Contrasts with Regional Patterns – Gemini Advisory

Posted on February 11, 2019 by Dissent

Stas Alforov writes:

  • Based on the proprietary Gemini Advisory telemetry data collected from various dark web sources over several years, we have determined that in 2018, nearly 1.4 million cards were compromised in the East Asia region, nearly a 100% increase from 2017.
  • Despite the overarching trend of increased fraud in East Asia, Japanese compromised card levels decreased by over 100% in 2018, largely due to what appears to have been a massive upload of 280,000 Japanese CNP payment records posted for sale in January of 2017.
  • Gemini Advisory identified an out-of-pattern spike in Japanese payment records added to the dark web in November and December of 2018; this spike of newly added records appeared to run parallel to a growing demand in Japanese-issued cards. Gemini Advisory identified that during this timeframe, a number of Japanese cardholders published various complaints regarding a newly released Japanese payment app called PayPay.
  • Cybercriminals likely utilized this app as a means of monetizing stolen Japanese payment cards, as well as compromising and monetizing the credentials of existing legitimate PayPay users. Based on the overlapping timeframes between PayPay fraud and the spike in Japanese payment cards added to dark web marketplaces between November and December 2018, Gemini Advisory assesses with moderate confidence that these two events are related

Read more about their findings on GeminiAdvisory.io.

Category: Commentaries and AnalysesID TheftNon-U.S.

Post navigation

← Users complain of account hacks, but OkCupid denies a data breach
Chinese bank’s software chief jailed after finding way to withdraw US$1m in ‘free’ cash from ATMs →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Cyberattack pushes German napkin company into insolvency
  • WMATA Train Operators Arrested in Health Care Fraud Scheme
  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.