LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › B1ack's Stash Marketplace Releases 4.6M Stolen Credit Cards

CRITICAL severityReportedHow we verify

B1ack's Stash Marketplace Releases 4.6M Stolen Credit Cards: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 19, 2026
B1ack's Stash Marketplace Releases 4.6M Stolen Credit Cards

Reported May 19, 2026. Approximately 4.6M people affected.

CRITICAL
Severity
4.6M
People affected
4
Data types exposed
May 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

B1ack's Stash Marketplace released 4.6 million stolen credit cards on May 19, 2026. Individuals whose payment-card, personal, address, or contact information may be involved should check their accounts and consider placing fraud alerts or credit freezes.

Severity & verification
CRITICAL severityReported
Exposes financial data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
4.6M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On May 19, 2026, B1ack's Stash Marketplace released 4.6 million stolen credit card records for free public download. The action followed reported seller misconduct on the platform. The records contain card numbers, CVV values, expiration dates, names, addresses, emails, phone numbers, and IP addresses. Validation by external observers indicated that many entries remained active and usable at the time of release. This incident places the affected individuals at direct risk of financial fraud and identity misuse. Large-scale releases of payment data on underground forums increase the likelihood that the information will circulate among actors who attempt unauthorized transactions or further exploitation.

Breaking down the breach

The reported event centers on a deliberate release rather than an external intrusion. B1ack's Stash Marketplace, described as a dark web carding site, made the dataset available without charge after internal disputes with sellers. No information has been provided on how the records were originally obtained by the sellers or the marketplace. The total volume is stated as 4.6 million records. Timing details beyond the May 19, 2026 report date remain undisclosed, as do any prior warnings or internal security measures that may have been in place.

How a breach like this happens

Marketplaces that traffic in stolen payment data sometimes distribute batches openly when sellers violate platform rules or fail to meet transaction terms. Such releases can occur after disputes over payment, quality of goods, or attempts to undercut fees. The data itself typically originates from earlier compromises of retailers, payment processors, or individual accounts, after which it is aggregated and resold. Once posted for free, the records become accessible to a wider set of users who may test them for validity or combine them with other information for fraudulent activity.

Who is B1ack's Stash Marketplace Releases 4.6M Stolen Credit Cards?

B1ack's Stash Marketplace operates as a dark web site focused on the exchange of stolen payment card details. Sites of this type function as intermediaries between individuals who obtain card data through various means and buyers seeking to use or resell it. They typically maintain forums, escrow systems, and rules intended to facilitate repeated transactions. When a marketplace itself distributes large volumes of records, the action can expand the pool of available data beyond its usual paying customers and increase overall exposure for the people whose information appears in the files.

What data was at risk

The released dataset is described as containing payment-card information together with personal information, addresses, and contact details. Specific fields listed include card numbers, CVV codes, expiration dates, names, addresses, emails, phone numbers, and IP addresses. No confirmation has been issued on whether additional categories such as account passwords, government identifiers, or transaction histories were included. The exact scope of records tied to any single individual therefore remains unconfirmed beyond the fields noted in the release summary.

What's at stake

Individuals whose records appear in the dataset face the possibility of unauthorized charges, account takeovers, and downstream use of their details in further schemes. Payment-card data combined with contact information allows actors to attempt both immediate fraud and longer-term impersonation. For the marketplace, the release may affect its internal reputation among sellers and buyers, though the direct operational consequences for the platform itself have not been stated. The broader circulation of validated card records can raise fraud rates across financial institutions that issued the affected cards.

Were you affected?

Monitor bank and credit-card statements for unrecognized transactions. Contact the issuing bank to request new card numbers if suspicious activity appears. Review credit reports from major bureaus for accounts opened without authorization. Individuals can also submit a free exposure scan using their email address through established breach-notification services to determine whether their information has appeared in previously indexed datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

AssuranceAmerica Breach Exposes 6.9M Driver's LicensesJuly 8, 2026SBI Software Hit by Genesis Data LeakJuly 6, 2026Aflac Japan Discloses Breach Impacting 4.38M CustomersJune 30, 2026Kodak Confirms Data Breach Claimed by ShinyHuntersJune 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the B1ack's Stash Marketplace Releases 4.6M Stolen Credit Cards →

Source: SecurityWeek

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram