Podcast
Root Causes 295: Genesis Criminal Marketplace Taken Down


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
April 17, 2023
A large, public criminal marketplace for stolen logins and other information was rolled up by law enforcement across seventeen countries. Genesis Marketplace offered not only traditional login credentials but also associated data needed to defeat MFA.
Podcast Transcript
Lightly edited for flow and brevity.
And this site was pretty brazen. Apparently, it started around 2017 and wasn’t even completely hidden behind the dark web. It was basically publicly exposed. You could just go there and purchase things. One of the things I found interesting is apparently one of the big electronic arts hacks that happened recently was based on a credential that was purchased through this site for $10.00. So, amazing.
Law enforcement agencies from 17 countries were involved in the raids which began on Tuesday. The operation was led by the FBI in the U.S. and the Dutch National Police working alongside the NCA in the UK, the Australian Federal Police, and countries across Europe. Globally 200 searches were carried out and 120 people were arrested.
So, it’s big and it’s broad and it’s all over the place. But, like big and broad that’s interesting in and of itself. The other thing though that I think you and I both found was interesting was this was more than just traditional log in credentials that you could purchase. It was more than username and password.
But I think the reason we are pointing this out, Tim, is that there is an underground economy that you might not be aware of. This story really breaks, what’s out there because the details get written nicely and there it is. It’s the bad guys have ways of not just stealing credentials and then selling them on mass, not just uniquely identifying you but also, they know. They know that a lot of you are using weaker forms of MFA and, as part of the package of what’s available to defeat your defenses, those things are also out there as part of the underground economy. That should make you think that as a security architect when you are choosing forms of authentication, you gotta put stronger locks on the door because literally the bad guys now have commoditized ways to bypass MFA, Tim.
I would say though I’m not here, you’re not here, Tim, to make a lot of comment about people in the underground economy. We know it’s always going to exist. There’s always going to be black markets for these kinds of things. What I would say to everybody else, everybody on the defense side of things, is it really highlights again what is this Genesis site selling? The core of what they are selling is ways to bypass authentication. In other words, credentials. Ways to bypass MFA, which is passwords plus another form factor. Therefore, for all of you, the big lesson here is not all multifactor authentication are created equal. It's always been time to think about stronger locks on the doors because the bad guys have completely commoditized picking the locks of the weaker locks. It’s just the truth.

