logo svg
logo

August 24, 2026

Updated: August 24, 2026

What Is BriansClub? The Carding Market Explained

Inside the dark web's biggest card-dump shop, the hack that spilled 26 million stolen cards, and what actually stops card fraud.

Abdalla Mohamed

Featured Image

BriansClub was one of the dark web's largest "carding" shops: a marketplace that sold stolen payment card data, mostly magnetic-stripe "dumps," harvested from breached retailers and point-of-sale systems. It became infamous for two things: mockingly branding itself after the cybersecurity journalist Brian Krebs, and getting hacked itself in 2019, spilling more than 26 million stolen cards that were then handed to banks. This guide explains what BriansClub was, how carding shops work, what happened in that breach, its murky current status, and, most importantly, how to defend against the card fraud it fueled.

Updated: August 2026. A defensive, law-enforcement and threat-intelligence overview for security teams and consumers. It contains no marketplace addresses, mirrors, or access instructions, and does not endorse or assist any illegal activity.

The quick answer

Here is the whole story in one table; the rest of the guide expands each row.

QuestionShort answer
What was it?A major dark web carding shop selling stolen payment card data
Since when?Emerged in late 2015
Why the name?A mocking "tribute" to journalist Brian Krebs, who is not affiliated with it
What did it sell?"Dumps" (magnetic-stripe data) and CVVs (card-not-present data)
What made it famous?A 2019 breach exposed 26M+ stolen cards, which were shared with banks
Is it still up?Status is contested and unreliable; carding shops constantly rebrand and get cloned
Is using it legal?No. Buying or using stolen card data is a serious crime

The one line to remember: BriansClub industrialized card fraud, and its own 2019 hack turned into one of the largest card-recovery events on record.

What is BriansClub?

BriansClub was a specialized dark web marketplace for "carding," the trade in stolen credit and debit card data. Unlike broad markets that sell many kinds of contraband, it focused on payment cards: it aggregated card records stolen by hackers and resellers, organized them by type and quality, and sold them to fraudsters. Threat-intelligence teams tracked it for years as one of the biggest shops of its kind, and it sits inside the wider ecosystem we map in our top dark web marketplaces roundup. Like other hidden services, it operated over anonymity networks, a setup explained in our dark web vs darknet vs Tor guide.

The important framing for a defender: BriansClub was the retail end of a supply chain. It did not usually steal cards directly; it resold what a network of "resellers" harvested from breached businesses, taking a cut of every sale.

Why is it named after Brian Krebs?

The name is a taunt. BriansClub branded itself around the identity of Brian Krebs, the investigative journalist whose reporting has exposed countless cybercriminals, even using his name and likeness on the site. Krebs has no connection to the marketplace; the branding was a deliberate provocation aimed at the reporter who covers operations like it. It is a small detail, but it captures the culture of these shops, and it is why Krebs ended up as the person a source trusted with the stolen database in 2019.

BriansClub timeline

The shop's arc mirrors the rise, persistence, and gradual decline of the magstripe-heavy carding era.

YearEvent
Late 2015BriansClub emerges as a major competitor in the carding market and uses Brian Krebs's identity in its branding
2016 to 2018Grows into a leading card shop, aggregating dumps from breached retailers
2019The shop is itself hacked; 26M+ cards leaked to Krebs and shared with banks
2020 to 2022The carding market remains large but shifts: Group-IB measured growth to about $1.9B before a later 26% drop to $1.4B, driven largely by fewer dumps after Joker's Stash shut down; card-not-present data continued to grow
2023 to 2026Status contested; repeated "shut down" claims, rebrands, and clone impersonations

This timeline is the short version of a broader shift: EMV, contactless payments, and tokenization steadily reduced the usefulness of magnetic-stripe dumps in many markets, while card-not-present fraud and stolen account data remained valuable.

What BriansClub sold: dumps vs CVVs

Carding shops trade two broad kinds of stolen card data, and the difference decides how the fraud is committed.

ProductWhat it isHow criminals abuse it
DumpsCopied magnetic-stripe track data (card number, expiry, sometimes name)Encoded onto blank magstripe cards to make counterfeits for in-store purchases
CVVsCard number, expiry, and security codeUsed for online "card-not-present" fraud

BriansClub was known primarily for dumps. A dump is written onto a blank card with a magnetic-stripe encoder, producing a counterfeit that a "runner" swipes at a big-box store to buy electronics or gift cards that are quickly resold for cash. CVVs, by contrast, power online fraud where no physical card is needed. Understanding this split matters because the defenses that killed dumps (chip cards) did little for CVV fraud, which is where the criminal economy moved next.

Where the cards came from: the carding supply chain

BriansClub was fed by a network of suppliers, and breaking that chain is where defense actually happens.

The shop's job was aggregation and resale: organize millions of stolen records, price them by issuing bank, card type, and freshness, and move them to buyers. That is why a single successful shop could hold hundreds of millions of dollars of card data at once.

How stolen cards were turned into cash

Understanding the cash-out side explains why certain fraud patterns are red flags, which is useful for anyone building detection. A dump on its own is just data; criminals had to convert it into money, and that conversion left signatures defenders can watch for.

For issuers and merchants, this is why fraud models weight signals like sudden high-value electronics or gift-card purchases, mismatched geography, and rapid testing of many cards. The defense is not to memorize the criminal playbook but to recognize that stolen card data has a predictable monetization path, and to instrument for it. This is the same detection-and-response mindset we apply in an incident response plan.

The 2019 BriansClub breach

The 2019 BriansClub breach

The defining event in BriansClub's history is that the card shop itself got hacked, and the outcome was unusually good for the public.

In 2019, a source shared BriansClub's stolen database with Brian Krebs, who broke the story. The numbers, as Krebs reported them, were staggering.

DetailFigure (per Krebs, 2019)
Card records exposedMore than 26 million
Time span of theftRoughly the prior four years
Uploaded in 2019 aloneAlmost 8 million records
Value of cards for saleAround $414 million by the site's own pricing
Cards sold since 2015 (est.)~9.1 million, earning the operation an estimated ~$126 million

Crucially, the recovered data was shared with the financial industry and card-issuing banks, so they could cancel and monitor the affected cards before criminals could use them. As Krebs put it, when card shops play dirty, consumers can end up winning. The breach turned a criminal database into one of the largest pre-emptive card-recovery efforts on record, a rare case where a hack of a hacker helped the victims.

Is BriansClub shut down? The honest answer

This is one of the most-searched questions about BriansClub, and the honest answer is: the status is contested and unreliable, and that uncertainty is itself the important lesson.

For a defender, the takeaway is not a date. It is that the underground is deliberately opaque, and any confident claim about a specific market's live status, especially one that invites you to go check, should be treated as bait.

"Which BriansClub is legit?" is the wrong question

Queries asking which version of the site is "real" or "legit" are common, and the safe answer is a warning, not a directory:

If your card may be compromised, the answer is your bank and the fraud-reporting channels below, not the underground.

Why carding declined: EMV chips and tokenization

Why carding declined EMV chips and tokenization

BriansClub's core product, magstripe dumps, became less useful as the payment industry moved toward EMV, contactless payments, and tokenization.

DefenseHow it kills the fraud
EMV chipGenerates a unique cryptogram per transaction that cannot be reused; magstripe clones fail where chip is enforced
Contactless / mobile walletsTokenized, per-transaction data with no reusable card number exposed
TokenizationReplaces the primary account number with a controlled surrogate token, reducing the value of intercepted payment data outside its intended context
Point-to-point encryption (P2PE)Encrypts card data at the terminal so it is never exposed in the clear

EMV chip cards, governed by the EMVCo specifications, make straightforward cloning much harder because chip transactions use dynamic cryptographic data. As chip and contactless adoption increased, traditional magstripe dumps became less useful where EMV was properly enforced. But the carding market did not simply disappear: Group-IB measured it growing to roughly $1.9 billion in one review period, then falling 26% to about $1.4 billion in the next, with the later decline attributed largely to fewer dumps after the Joker's Stash shutdown. At the same time, sales of card-not-present text data increased.

The wider carding-market collapse

BriansClub did not decline in isolation. The biggest card shops fell one after another, through takedowns, retirements, and obsolescence.

MarketFateNote
Joker's StashShut down ~Feb 2021FBI/Interpol disrupted its infrastructure; operator reportedly hospitalized with COVID
UniCCRetired Jan 2022Announced exit after ~$358M in crypto sales since 2013
BidenCashSeized in June 2025U.S. authorities seized about 145 domains and cryptocurrency tied to the marketplace after it trafficked more than 15M payment-card records
BriansClubContested / repeatedly disruptedStatus unreliable; rebrands and clones muddy the picture

We track these operations in dark web marketplace takedowns. The pattern is consistent: as chip-and-token defenses ate into card fraud, both law enforcement pressure and shrinking margins pushed the ecosystem elsewhere.

Where the crime went next

Card fraud did not end; it migrated. As magstripe dumps lost value, criminals shifted toward two things that chip cards do not stop:

In other words, the BriansClub era, industrialized theft of magstripe data, gave way to an era of stolen identities and sessions. The defenders' job shifted with it, from protecting the card's magnetic stripe to protecting the customer's accounts and the merchant's checkout code.

How to defend against card fraud: consumers

You cannot shut down a carding shop, but you can make stolen card data useless against you.

How to defend against card fraud: merchants and enterprises

For any business that handles cards, the goal is to keep card data out of criminal hands in the first place.

ControlWhat it protects
EMV + contactless acceptanceRemoves the magstripe data that dumps depend on
Tokenization and P2PERenders intercepted card data useless
PCI DSS v4.0.1 complianceBaseline handling, storage, and segmentation requirements
POS malware and skimmer monitoringCatches terminal-level theft
E-commerce integrity monitoringDetects Magecart-style checkout skimmers
Network segmentation of the cardholder data environmentLimits breach blast radius
Regular penetration testing of the payment flowFinds the gaps before criminals do

The last row is where a card breach is usually prevented or missed. A carding shop's inventory starts with a breached merchant, and testing the payment path the way an attacker would is how you stop being that merchant.

Why this matters for security teams

BriansClub is a case study in how the criminal economy adapts. Shut one channel and it moves to the next: from magstripe dumps to CVV fraud to infostealer logs and account takeover. For defenders, that means card security cannot be a one-time chip upgrade; it is continuous validation that your checkout, your POS environment, and your customer accounts are not the weak link that fills the next shop's inventory. Our dark web statistics roundup shows how much of that stolen data is measurable, and how quickly it circulates.

That is why testing has to model a real attacker against your payment and identity systems. DeepStrike's penetration testing is manual-first and adversary-realistic: our team probes the actual paths card and credential thieves use, from e-commerce checkout code to POS segmentation to authentication, and hands you the concrete fixes before your data ends up for sale. For US-based organizations, see our US penetration testing services.

FAQ

What is BriansClub?

BriansClub was one of the dark web's largest carding marketplaces, selling stolen payment card data, mainly magnetic-stripe "dumps," aggregated from breached retailers and point-of-sale systems. It emerged in late 2015, resold cards harvested by a network of criminal suppliers, and became a major hub for card fraud.

Why is BriansClub named after Brian Krebs?

The name was a mocking provocation aimed at journalist Brian Krebs, whose reporting exposes cybercriminals. The site used his name and likeness despite having no connection to him. Fittingly, Krebs was the reporter a source trusted with the stolen BriansClub database when the shop itself was hacked in 2019.

What happened in the 2019 BriansClub breach?

In 2019 a source gave Brian Krebs BriansClub's own stolen database, exposing more than 26 million card records, valued at roughly $414 million by the site's pricing. The data was shared with card-issuing banks so they could cancel and monitor affected cards before criminals could use them.

Is BriansClub shut down or still active?

The status is contested and unreliable. Credible reporting shows the marketplace was still generating substantial sales in 2024, but there is no authoritative public confirmation that any current domain in 2026 is the verified continuation of the original operation, and much of the "shut down" or "official link" content online is rumor, clone promotion, or SEO spam. Carding shops routinely go dark, rebrand, and spawn phishing clones, so external claims about live status are untrustworthy.

What is a card dump?

A dump is an electronic copy of a card's magnetic-stripe data, its number, expiry, and sometimes the cardholder name. Criminals encode dumps onto blank magstripe cards to make counterfeits for in-store purchases. Chip and contactless payments, which do not expose reusable magstripe data, have made dumps far less useful.

Why did carding markets like BriansClub decline?

EMV chip cards generate a unique code per transaction that cannot be cloned, and tokenization replaces card numbers with useless tokens. As chip and contactless became standard, magstripe dumps lost their value, shrinking the carding market and pushing criminals toward online CVV fraud and infostealer-driven account takeover.

How do I protect myself from card fraud?

Use chip, contactless, or a mobile wallet instead of swiping; use virtual or tokenized numbers online; enable transaction alerts; review statements; and freeze or replace a card at the first suspicious charge. Report fraud to your bank and the FTC or FBI IC3, never to any underground service.

How can businesses prevent card data theft?

Accept EMV and contactless, apply tokenization and point-to-point encryption, meet PCI DSS requirements, segment the cardholder data environment, monitor for POS malware and e-commerce skimmers, and penetration test the payment flow regularly. The goal is to keep card data from ever reaching a carding shop's inventory.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us