English.Elpais Dark Web Study Reveals Limited Criminal Content Scope
Article Content
- •Only 16% of dark web sites with suspicious content are unique, indicating limited criminal activity.
- •The majority of dark web sites are mirrors, complicating the understanding of its size.
- •The buying and selling of stolen credit cards remains a significant but volatile market.
A team of Spanish researchers mapped the dark web, revealing that only 16% of sites with suspicious content are unique, totaling 4,008 original potentially criminal sites out of 29,911. The study indicates that while the dark web contains a significant number of duplicate sites, the ecosystem of illicit content is more limited than previously believed. The research highlights the prevalence of mirror sites that replicate content, complicating the perception of the dark web's size. The study also notes that the buying and selling of stolen credit cards is a major activity, characterized by volatility as cards are canceled by their owners. Accessing the dark web requires the Tor browser, which anonymizes users and uses .onion domains. The findings suggest that while there is a substantial amount of illicit activity, it is not as extensive as often assumed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…