
By Andréanne Bergeron, Security Researcher
Stolen medical records sell for $300 on the dark web. Stolen credit card numbers sell for $18. Yet the credit card thief faces an average of 55 months in federal prison, while the health data thief faces roughly 13. Cybercriminals, it turns out, are better at pricing risk than legislators are at sentencing it. That’s the uncomfortable central finding of our study that mapped dark web PII prices against US federal sentence lengths.
This asymmetry is a signal about where sophisticated threat actors concentrate their efforts, and it has direct implications for how security teams should prioritize their defenses and threat exposure monitoring.
Key Findings About Cybercriminal Market Pricing and Sentencing
- The most valuable data on the dark web is often associated with relatively short prison sentences, revealing a gap between economic incentives and legal deterrence. Personal health data ($300/unit) and PINs ($196/unit) are associated with average sentences of only 13 to 18 months, while credit card numbers ($18/unit) carry roughly 55 months. The misalignment between cybercrime markets and legal sentencing creates a rational incentive for capable actors to target high-value, low-sentence categories.
- High-value data attracts more sophisticated attackers. Expensive PII such as health records, PINs, and bank details tends to be targeted by more capable and cautious threat actors operating in lower-risk environments.
- Low-priced data is not low risk, but high volume and noisy. Email addresses and similar data are cheap because they are abundant and heavily traded, often linked to less sophisticated actors.
- Dark web prices reflect attacker strategy, not just utility. Pricing signals where criminals concentrate effort: high-value, low-sentence categories indicate areas of “arbitrage” where risk is under-punished relative to reward.
- The legal system punishes traceable crime more harshly than irreversible harm. Credit card fraud is reversible and leaves a dense evidentiary trail, which has produced severe sentencing. Health data theft causes permanent, compounding harm but generates less prosecutorial traction, creating a deterrence vacuum.
Identity-First Cyber Threat Intelligence
Detect When Your High-Value Data Surfaces on the Dark Web
Sophisticated threat actors concentrate where value is high and legal deterrence is low, especially with PHI. Flare continuously monitors dark web marketplaces, forums, and illicit Telegram channels to detect when your organization’s most sensitive data appears for sale, before it’s weaponized.
The Inverse That Should Worry You
In two previous studies, we compiled 348 dark web price observations spanning 2008 to 2026, alongside 209 federal criminal cases prosecuted under 43 different statutes. After running an iterative attribution model to isolate the per-unit value of each PII category, we plotted price against average sentence length.
What emerged was a striking inverse relationship: the most expensive data attracts surprisingly light sentences.

Credit card numbers average around $18 per unit but are associated with roughly 55 months in federal prison for convicted offenders: the highest sentence exposure in the dataset. Social Security numbers follow a similar pattern, priced at around $4 but tied to approximately 31 months of imprisonment if maliciously used. On the opposite end, personal health data commands around $300 per unit and PINs around $196, yet both are associated with average sentences of only 13 to 18 months. Bank account credentials sit at roughly $68 per unit with similarly modest legal sanction when used to commit a crime.
The criminal market has already solved the optimization problem: sophisticated actors are concentrating in the high-value, low-sentence quadrant, while impulsive, low-skill operators churn through cheap, high-sentence data in volume.
What the Price Signal Actually Means
The findings are a signal about where your most consequential exposure lives. Dark web prices encode the collective intelligence of the threat actor population about detection risk, not just criminal utility. Cheap, high-sentence PII moves in bulk and leaves large evidentiary footprints. Expensive PII circulates through tighter, more specialized channels populated by operationally sophisticated actors who are genuinely harder to catch.
Breach Volume vs. Value
To contextualize the threat landscape, we examined which categories of personal information appear most frequently in breach datasets. The distribution, illustrated in the pie chart below, reveals a clear concentration of exposure around a small number of data types.

The most breached data types (email addresses, passwords, usernames, and names) are also among the cheapest on the dark web. This is not a coincidence. These categories dominate breach volumes precisely because they are easy to harvest at scale, easy to trade, and generate minimal friction in the criminal ecosystem.
Why Credit Cards Remain a Target Despite High Sentences
Credit cards occupy a particularly instructive position in this landscape. They carry the highest legal sentence of any PII category we studied, yet they remain a persistently attractive target. The reason is operational simplicity: a stolen credit card number can be monetized almost immediately, requires little technical sophistication, and fits neatly into well-established criminal workflows. The barrier to entry is low, the conversion to cash is fast, and the underground infrastructure supporting card fraud is mature and widely accessible.
Threat actors pursuing credit card data are not necessarily making a sentence-adjusted calculation. Most do not have a precise map of the legal consequences awaiting them. What they do understand is that credit card fraud leaves traces: transactions trigger alerts, banks have fraud detection systems, cards get flagged, chargebacks get filed, and the evidentiary chain from criminal act to attribution is shorter than in almost any other category of financial crime. When actors are caught they discover that the sentence is severe. The legal system has responded to the volume and visibility of the crime.
Two Dynamics Driving Threat Actor Behavior
For a security practitioner, this means that a data breach involving medical records or financial PINs is likely to attract a different caliber of adversary than a breach involving names and email addresses. But the picture is more complicated than a simple story of sophisticated actors making rational calculations. Two parallel dynamics are at play.
Dynamic One: Criminal Adaptation
Some actors operating in the health data and PIN market are making deliberate, calculated risk decisions. They might have mapped the regulatory environment, identified the legislative lag, and positioned themselves in the gap. These would not be impulsive actors but rational ones responding correctly to a misaligned incentive structure. Their migration toward high-value, low-sentence PII is an emergent response to enforcement pressure elsewhere.
Dynamic Two: A Failure the Market has Quietly Exposed
The sentencing landscape does not reflect the actual harm inflicted on victims, which is a failure of the legal system. A victim of credit card fraud exists within a system built to absorb that crime: the card is cancelled, the fraudulent charges are reimbursed, and a new card arrives within days. The harm is real but largely reversible. Credit card fraud also leaves a dense evidentiary trail (transactions, timestamps, merchant records) that makes prosecution more easily managed, and the legal system has responded accordingly with severe sentencing. The deterrence infrastructure followed the visibility of the crime, not its severity.
Personal health data operates under an almost inverse logic. A victim whose medical history, diagnoses, prescriptions, or mental health records are compromised carries that exposure for life. The data cannot be cancelled or reissued. It can resurface years later in insurance discrimination, employment decisions, or targeted manipulation. The harm compounds silently and indefinitely. Yet the sentencing framework does not appear to weigh this permanence.
The result is a legal environment that punishes the monetizable, traceable crime more harshly than the invisible, irreversible one. It is possible that sophisticated threat actors, whether consciously or through market feedback, have found that gap and priced it in.
What This Means for Breach Triage
This is a signal about where protective investment is most urgent. The legal system will not fill this gap quickly; legislative cycles move slowly, and harm that is diffuse, delayed, and hard to quantify does not translate easily into prosecutorial priority. In the interim, the organizations holding health data, biometric records, and similarly permanent PII are operating in a deterrence vacuum.
The practical implication is that standard breach triage that ranks sensitivity by volume of records exposed can miss the point entirely. The pie chart of real-world breach exposure is dominated by credentials and contact data which is the high-volume, low-friction categories. But 50,000 medical records is a more strategically valuable target than five million email addresses, and the threat actor who went after the medical records almost certainly planned the operation more carefully, covered their tracks better, and is harder to attribute. Volume is not a proxy for strategic intent.
Where Security Teams Can Focus Now
Security teams that monitor dark web sources for mentions of their organization or data should weight signals differently based on this framework:
- A spike in interest around credential data or healthcare records is not the same threat as a spike in credit card data. The former implies a more capable, more patient, and more evasive adversary. Incident response planning, detection logic, and monitoring coverage should reflect that asymmetry.
- Prioritize protection of permanent, non-revocable data. Health records, biometric data, and similarly irreversible PII represent the highest-value intersection of attacker incentive and deterrence gap. These categories warrant disproportionate investment in access controls, monitoring, and segmentation.
- Do not rely on legal deterrence as a downstream control. In environments with low detection rates and jurisdictional complexity (which describes most cybercrime), sentence severity has essentially no deterrent effect on the actors you most need to deter. The sophisticated threat actor has already internalized that the probability of being caught is low enough to render the hypothetical sentence irrelevant.
- Invest in detection certainty over response severity. The probability that malicious activity will be identified and attributed is the variable that actually shapes criminal behavior. That puts the burden squarely on technical defenses and threat intelligence programs, not the justice system.
Organizations that understand this framework can allocate monitoring and protective resources where the threat model actually concentrates risk, rather than where breach headlines and record counts draw attention.
Identity-First Cyber Threat Intelligence
Detect When Your High-Value Data Surfaces on the Dark Web
Sophisticated threat actors concentrate where value is high and legal deterrence is low, especially with PHI. Flare continuously monitors dark web marketplaces, forums, and illicit Telegram channels to detect when your organization’s most sensitive data appears for sale, before it’s weaponized.





