From January to June this year, something like 2.5 billion unique pieces of data circulated on the Dark Web. It’s a huge wealth of information that cybercriminals can use to learn more about their victims. By cross-referencing emails, passwords, telephone numbers, names and other personal data, in fact, it becomes possible to build increasingly detailed profiles and make phishing, online fraud and identity theft more credible. Italy is among the countries most affected by the attacks, at least if we consider the number of accounts stolen through infostealers and subsequently spread on the Dark Web. This situation is photographed by the Cyber Observatory of CRIF (Financial Intermediation Risk Centre), which in a new report analyzed the presence of data exposed in the first half of 2026 both on the open Web and on the Dark Web.
The infostealer phenomenon: sophisticated malware
Among the cyber weapons that have contributed most to the placing of over 2.5 billion unique data points on the Dark Web are infostealers. These are very sophisticated malware designed to automatically steal information from infected devices. They can be installed, for example, through phishing campaigns or counterfeit software and, once nestled on the user’s device, these malware can act silently by collecting credentials and other sensitive information on the device and then sending them to criminals. Once cybercriminals have obtained the data they were looking for, they can end up with it in ULP archives, i.e. collections that associate a site address (URL), username and password, or in even more complete and structured databases.
Making the situation even more worrying is the spread of the so-called “stealer-as-a-service” model, which enormously reduces the entry barrier to overcome to use these IT tools. In practice, these malware are made available together with tools, control panels and operating instructions, which allow even people with relatively limited IT skills to use them to perpetrate cyber attacks. According to CRIF, the epicenter of this criminal industry is located in Eastern Europe, with Russia indicated as the main area of development and commercialization of these malware, but other centers that have become particularly active and located in South-East Asia and Brazil should not be underestimated.
The amount of data available in bulk is worrying
What is worrying is not only the silence with which these tools operate, but also the amount of information that can be stolen in one fell swoop. In the first half of 2026, passwords are the most widespread data, followed by emails, usernames, telephone numbers and even names and surnames. Also emblematic is the fact that in 99.8% of the cases analysed, credit card data is associated with the relevant security information and expiry date. The password appears together with the email in 95.9% of cases and together with the username in 96% of cases. The telephone number, however, is associated with a password in 61.7% of cases and with a name and surname in 18.8%.
You understand well that the more information is found and combined together, the easier it becomes to carry out social engineering attacks, which exploit information about the victim to convince them to carry out certain actions. An example is spear phishing, which uses personalized messages to steal information from victims who have been studied by cyber criminals thanks to the enormous amount of personal information available on them on the Dark Web.
Another type of sophisticated attack is the BEC, acronym for Business Email Compromisealso known as the “CEO scam”: the criminal pretends to be an executive and tries to convince an employee to make a payment or share confidential information. The employee, seeing that those on the other side present convincing information and reasoning, could easily fall into the trap set by the cyber criminal who is impersonating his boss.
In addition to all these attack methods, we must not forget the tools based on artificial intelligence, capable of making fraud even more credible. Among the examples cited in the report drawn up by CRIF are audio and video deepfakes, now increasingly realistic and, in the corporate sector, particularly carefully crafted emails that are difficult to distinguish from authentic communications.
Italy is sixth in the world: the situation
Zooming in on our country we see that in Italy, at least in the first half of the year, 32.3% of users monitored by CRIF protection services received at least one alert relating to data identified on the Dark Web. The age groups most involved are those between 51 and 60 years (26.7%), between 41 and 50 years (26.6%) and the over 60s (20.3%). Men represent 64.3% of alerted users. The regions with the highest overall number of alerts are Lombardy (15.7%), Lazio (12.3%), Sicily (11.3%), Emilia-Romagna (9.7%) and Piedmont (9.5%). Considering instead the relationship with the population, Umbria, Molise, Lazio, Piedmont and Friuli-Venezia Giulia emerge.
It is also clear from the report that Italy is among the countries most affected by cyber attacks. If we consider the number of accounts stolen and spread through the infostealer malware we see that Italy comes in third place: only the United States and France are worse than us, which, respectively, are in first and second place in this unfortunate ranking.









