Site navigation

Hackers Selling Police Email Accounts for Just £4 on the Dark Web

Staff Writer

,

dark web hackers, email compromise dark web, Abnormal AI
Hackers are advertising official government and police email accounts for sale that can issue fake legal requests and bypass security measures.

Security researchers have uncovered a dark web economy of compromised government and police email accounts, with attackers able to purchase stolen credentials for as little as £4.

Laying out their investigation into this underground criminal market, researchers from cyber firm Abnormal AI found hackers selling access to active government and law enforcement email accounts from powerhouses such as the UK, US, and Germany, as well as rapidly emerging economies like India and Brazil. 

One listing, for example, offered access to a ‘bundle’ of official US government accounts, including five addresses for the US Postal Service, eight for the Federal Bureau of Prisons, and even one for the FBI.

Similar listings were found for compromised law enforcement email accounts around the world, across swathes of Africa, Asia and Europe, promising access to the likes of the Italian police force, the Brazilian Army Police, and the Mexican judicial service.

While some accounts were being sold for a few hundred dollars, others, like those for the Royal Thai Police and Nepal law enforcement, are being marketed for $100 (£74), with Abnormal finding attackers able to buy some credentials in bulk for just $5 (£4). 

Worryingly, as well as giving cyber-criminals the ability to extract sensitive data, hackers can use these accounts to pose as officials and issue fake legal requests, with emails sent from .gov and .police addresses among the most likely to evade technical defences and bypass suspicion. 

According to the researchers, law enforcement accounts have been quietly sold on the dark web for years, but there has been a surge in the number of compromised credentials on hacking forums.

These accounts have become more valuable to malicious actors as official systems become more integrated, giving criminals a digital toolkit that goes beyond simple email impersonation.

Detailing their findings in a blog post, Abnormal said that just one dark web salesman claimed to have access to hundreds of accounts, providing screenshots to back this up. 

The seller had access to investigative tools and databases meant only for law enforcement, including those for looking up license plate information and police reports. By using an active, compromised email address, hackers could log in to these systems and abuse the sensitive information held within.


Recommended reading


“The most concerning aspect of this threat lies in its ability to circumvent traditional email security measures,” wrote the researchers.

“Attackers aren’t spoofing domains or sending emails from known-bad IP addresses. They’re utilising actual accounts, often directly from the official email servers.

“This means standard filters that rely on domain reputation, sender authentication, or known malicious content signatures often fail to identify these threats.”

Last year, the FBI released an advisory on the use of US and other government email accounts being used by hackers to access sensitive data, a trend it has been following for at least the last three years. 

The FBI’s advisory recommends that governments and other official organisations, as well as those subject to emergency data requests, document and monitor external connections, limit access to resources, regularly update privileges for users, and implement time-based access for accounts.  

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data