BriansClub

For four years the biggest joke in the stolen-card business was the branding: an underground megastore hawking millions of hacked credit cards under the name, face, and photo of Brian Krebs — the reporter who ends careers like theirs — complete with a mock copyright, “© 2019 Crabs on Security.” Then in September 2019 an anonymous source handed the real Krebs the shop’s entire database: more than 26 million stolen cards, nearly a third of the underground’s whole inventory, nominally worth $566 million. Krebs did the one thing the shop’s name guaranteed he would — shipped it all to the banks so the cards could be flagged and killed. The shop that trolled the namesake got dumped by the namesake. And when Krebs filed a support ticket titled “Your site is hacked,” the administrator’s reply opened with a line for the ages.

No. I’m the real Brian Krebs here

The BriansClub administrator — smiley included — replying to the actual Brian Krebs’s support ticket “Your site is hacked.” The shop had spent four years selling stolen cards under Krebs’s name, likeness, and photo, down to the footer on every page: “© 2019 Crabs on Security.” KrebsOnSecurity, October 2019

WHO
BriansClub (briansclub[.]at) — one of the largest underground stores for stolen credit and debit card data, active since roughly 2015 FACT
THE GIMMICK
Named after, and advertised with, the name, likeness, and photo of security reporter Brian Krebs — who had nothing to do with it — since 2015; site pages carried the mock copyright “© 2019 Crabs on Security” FACT
THE DRAMA
Hacked in 2019; its full database — 26 million+ stolen cards, nearly a third of the underground’s tracked inventory, a collective asking price of $566 million per Gemini Advisory — leaked to the real Krebs, who shared it with the banks to kill the cards
THE HAUL
Roughly 9.1 million cards sold for about $126 million in bitcoin between 2015 and August 2019, per Flashpoint’s analysis of the leaked records — against a Justice Department sentencing yardstick of $500 per stolen card ATTRIBUTED
STATUS
BREACHED, INVENTORY BURNED — the shop stayed online, insisting the leaked cards were off its shelves; Flashpoint and Gemini both reported finding that claim false. No operator has been publicly identified in this record

This file is not about Brian Krebs — he is the impersonated party, and the shop’s only connection to him was theft of his face. It is a record of the cleanest irony the carding underground ever produced: a criminal marketplace that built its brand on trolling a breach reporter, got breached, and watched its namesake do exactly what his job description says — hand the stolen data to the people who could neutralize it. The through-line is the same one as the vDOS file: a shop that sells other people’s compromised data has no plan for the day someone compromises its own, and the leak reads like a full confession of the business model — resellers, commissions, pricing tiers, and 26 million victims’ cards on the shelves.

the drama timeline

ACT I — THE NERVE (2015–2019)

A stolen-card megastore opens under the name and face of the one reporter guaranteed to take it personally — and grows into a top-tier operation while the joke runs.

  1. 2015

    A shop named Brian

    BriansClub opens for business and begins (ab)using Brian Krebs’s name, likeness, and reputation in its advertising — his photo in the ads, his site imitated, a mock copyright at the bottom of every page: “© 2019 Crabs on Security.” Krebs’s own read on the joke: his surname means “crab,” and crab is Russian hacker slang for a carder. In its first year the shop lists 1.7 million stolen card records for sale.

  2. 2015–19

    The inventory curve

    The leaked records chart the growth of a real business: 2.89 million cards added in 2016, 4.9 million in 2017, 9.2 million in 2018, and 7.6 million more between January and August 2019 — over 26 million stolen credit and debit cards in all, taken from hacked online and brick-and-mortar retailers. The product is mostly “dumps”: by effect, data that lets a thief’s counterfeit card ring up electronics and gift cards at big-box stores on someone else’s account. Like most carding shops, BriansClub mostly resold cards stolen by others — resellers who earn a percentage of each sale. Cards from U.S. banks, the bulk of the stock, went for $12.76 to $16.80 apiece.

ACT II — THE HACK (SEPT–OCT 2019)

The shop that sells breach proceeds gets breached — and of all the inboxes on the internet, the database lands in the one belonging to the man on the logo.

  1. SEPT 2019

    The namesake gets the database

    An anonymous source contacts KrebsOnSecurity with a nearly 10 GB set of plain-text files: the full database of cards for sale currently and historically through BriansClub. Multiple reviewers confirm the records match what a funded account could see live on the shop. The math, per the analysts Krebs brought in: Flashpoint valued the unsold inventory at $414 million at the site’s own pricing tiers and counted roughly 9.1 million cards sold for $126 million; Gemini Advisory put the collective price of the entire exposed set at $566 million, with sold records exceeding $162 million — and estimated the 26 million cards represented almost one-third of the 87 million then for sale across the whole underground. One shop. A third of the market. In a text file.

  2. OCT 2019

    The cards go to the banks

    Krebs shares all of the stolen card data with multiple sources who work directly with financial institutions, so issuers can monitor or reissue every card in the dump — the entire point of the exercise, and the exact outcome the shop’s branding had been daring him to deliver since 2015. Flashpoint’s Allison Nixon frames the genre: “When people talk about ‘hacking back,’ they’re talking about stuff like this” — and points to the precedent where a leaked crime-service database led to arrests within days: vDOS, whose file sits one shelf over.

ACT III — “I’M THE REAL BRIAN KREBS HERE” (OCT 2019)

Krebs files a support ticket with the shop wearing his face. The shop answers in character — then spends the week on the forums defending the honor of its stolen-card inventory.

  1. OCT 15, 2019

    Your site is hacked

    Krebs requests comment through the shop’s own “Support Tickets” page, subject line “Your site is hacked,” informing the operators their card data is now with the issuing banks. The administrator’s polite reply arrives hours later: “No. I’m the real Brian Krebs here” — smiley attached — insisting the “correct subject would be the data center was hacked” and that everything affected had “been since taken off sales, so no worries about the issuing banks.” Flashpoint’s Nixon spot-checks the live shop against the leak and reports the removal claim is not truthful. The admin does not answer the follow-up: why Krebs’s name and likeness in the first place.

  2. OCT 16, 2019

    Enter MrGreen, exit dignity

    The underground forums are, in Krebs’s word, abuzz. The BriansClub admin takes to them to defend his business, re-stating the removed-from-shelves claim. Competitors gloat. The administrator of Verified, one of the longest-running Russian-language cybercrime forums, says the hack was perpetrated by a rival card-shop operator using the nickname “MrGreen” — who runs a competing shop by the same name and has been banned from the forum, because “sending anything to Krebs is the lowest of all lows” among self-respecting cybercriminals. Krebs, in print: “I’ll take that as a compliment” — and if the rest of the carding market wants to use him to take down its rivals, “I’m totally fine with that.”

  3. OCT 29, 2019

    The cover story collapses on arithmetic

    Gemini’s written analysis dismantles the admin’s two claims. The February-breach story: false, per Gemini — the dump’s million-plus South Korean records match a spike that ran March through July 2019; a February snapshot would hold under ten thousand. The cards-removed story: “Gemini has found this claim to be false as well” — the shop, which sells a “checker service” to test whether purchased cards still work, was likely betting the banks wouldn’t reissue everything. Gemini’s report notes, with a straight face, that the shop’s administrator was “operating under the moniker ‘Brian Krebs.’”

ACT IV — THE CARDS DIE (OCT 2019 ONWARD)

What “rescuing” 26 million stolen cards actually looks like: alerts, reissues, and a market suddenly missing a third of its shelf stock.

  1. OCT 2019

    The banking system digests the dump

    The alerts fan out through Visa and MasterCard. The biggest U.S. banks shrug — their anti-fraud teams had already flagged 90–95 percent of the cards from earlier breach investigations. The small banks and credit unions are blindsided: sources at two credit unions tell Krebs they’d been unaware of about 80 percent of their customers’ cards in the alerts. Gemini’s CEO Andrei Barysevich reports that for European and Asian banks the data was mostly new — “in some cases upwards of 60% of cards were still open and active.” More than 21.6 million of the leaked cards had expiration dates still in the future; every one flagged is a fraud that doesn’t happen. Against the Justice Department’s $500-per-card sentencing yardstick, the 9.1 million cards the shop had already sold represent more than $4 billion in likely losses.

  2. AFTER

    A third of the market, gone soft

    Barysevich’s market read: with over 78 percent of the illicit card trade running through about a dozen dark-web markets, “a breach of this magnitude will undoubtedly disturb the underground trade in the short term” — though other vendors “will undoubtedly attempt to capitalize on the disappearance of the top player.” The shop itself stayed online, still wearing the borrowed face, still insisting nothing was wrong — a store full of merchandise its own customers now had to assume was dead stock. No arrest appears in this record; unlike vDOS, the leaker withheld the user and payment tables that identify people. The inventory, not the operators, took the fall.

both sides, on the record

The case: BriansClub was, per its own leaked database as reported by KrebsOnSecurity, one of the largest stolen-card stores in the underground — 26 million+ stolen credit and debit cards, roughly 9.1 million sold for about $126 million, nearly a third of the entire market’s tracked inventory, fed by 142 resellers and bought by more than 50,000 customers. Every record on its shelves was a real person’s compromised card. And it did all of this while impersonating a working journalist — his name, his likeness, his photo in the ads — as a running joke at the expense of the breach victims whose data paid for it.

The response removes any doubt: caught, the shop’s administrator did not stop selling — he claimed, falsely per both Flashpoint and Gemini, that the leaked cards were off the shelves, while the shop’s own “checker service” existed precisely to sort the dead cards from the live ones. The lie was aimed at his own customers as much as anyone.

The defense, as stated: the administrator’s position, in his own messages, was that the shop itself was never hacked — “the data center was hacked” — and that everything affected had been pulled from sale, “so no worries about the issuing banks.” He answered the reporter who burned him politely, within hours, and never denied the obvious: the shop wore the name as dark-humor branding (“crab” being Russian slang for carder), not as identity theft aimed at Krebs’s wallet.

And the record has real limits: no operator of BriansClub is publicly identified anywhere in this file’s sources; no court has ruled on any of it. The MrGreen attribution is one forum administrator’s claim about a pseudonym. The revenue and valuation figures are analysts’ estimates from a stolen snapshot — careful ones, from Flashpoint and Gemini, but estimates. The only adjudicated fact in this story is arithmetic: the South Korean card counts that broke the February alibi.

YOU DECIDE

The carding underground ran a four-year bit at one reporter’s expense, and the bit had a structural flaw: if you name the store after Brian Krebs, the universe knows exactly where to deliver the database. Whoever did the breaking — a rival, per one forum admin — understood the joke better than the shop did. Twenty-six million stolen cards went from shelf stock to bank alerts in a month, the cover story died of arithmetic, and the administrator was left telling the actual Brian Krebs that he, the man selling stolen cards under a crab pun, was the real one. The victims’ cards got flagged. The market lost a third of its inventory. The archive notes that of everyone in this story, the only Brian Krebs who profited from crime was the fake one — and the only one who ended it was real.

The archive does not deify. It keeps the support ticket — and the smiley.

evidence locker

PRIMARY / REPORTING ON THE LEAK

  1. KrebsOnSecurity — “‘BriansClub’ Hack Rescues 26M Stolen Cards” FACT — the foundational report: the 26M+ card database leaked to Krebs, the shop’s use of his name/likeness and the “© 2019 Crabs on Security” footer, the year-by-year upload figures, the data shared with bank-facing sources, Flashpoint’s $414M/$126M/9.1M-sold analysis (attributed), the “Your site is hacked” ticket and the admin’s verbatim “I’m the real Brian Krebs here” reply, and Nixon’s hacking-back framing with the vDOS precedent. krebsonsecurity.com/2019/10/briansclub-hack-rescues-26m-stolen-cards/
  2. KrebsOnSecurity — “When Card Shops Play Dirty, Consumers Win” ATTRIBUTED — the rivalry angle: the Verified forum administrator’s claim that the hack was perpetrated by rival card-shop operator “MrGreen,” the ban, the “sending anything to Krebs is the lowest of all lows” line, the admin’s forum defense of the shop, and Krebs’s standing offer to help the rest of the market destroy itself. krebsonsecurity.com/2019/10/when-card-shops-play-dirty-consumers-win/
  3. KrebsOnSecurity — “Takeaways From the $566M BriansClub Breach” FACT — the accounting: Gemini’s $566M collective price and $162M sold (attributed), the one-third-of-the-underground estimate, 142 resellers and 50,000+ buyers, the 21.6M still-unexpired cards, the big-bank/small-bank split in the alert response, and Gemini’s findings that both of the admin’s claims — the February breach date and the removed cards — were false. krebsonsecurity.com/2019/10/takeaways-from-the-566m-briansclub-breach/

CONTEXT & CROSS-LINKS

  1. troll.fan — vDOS CROSS-LINK — the sibling irony: the other crime service that got its own database leaked to Krebs, cited by Flashpoint’s Nixon in this very story as the precedent for what such a leak sets in motion. troll.fan/dossiers/vdos.html
  2. troll.fan — Crew Rivalries CROSS-LINK — the underground’s oldest weapon: hacking the rival’s shop, which is exactly what the Verified admin says happened here. troll.fan/crew-rivalries.html
  3. troll.fan — Timeline CROSS-LINK — the 2019 breach in the scene’s wider chronology. troll.fan/timeline.html
  4. troll.fan — Rescator CROSS-LINK — the carder who supplied the underworld this shop retailed to: the Target/Home Depot breach vendor, unmasked and interviewed a decade later. troll.fan/dossiers/rescator.html
The standard. BriansClub is documented here entirely from KrebsOnSecurity’s October 2019 reporting on the leaked shop database. Stated as fact: the shop’s existence and its use of Brian Krebs’s name, likeness, and photo in its advertising since 2015; the “© 2019 Crabs on Security” footer; the leak of 26 million+ card records to Krebs in September 2019; the sharing of that data with sources working with the issuing banks; and the administrator’s verbatim messages, reproduced as Krebs published them. Attributed and never adopted: Flashpoint’s and Gemini Advisory’s valuations and sales estimates; Gemini’s findings that the admin’s February-breach and cards-removed claims were false; and the Verified forum administrator’s claim that a rival operator called “MrGreen” carried out the hack — a pseudonymous accusation by a pseudonymous accuser, reported as exactly that. Brian Krebs appears as the impersonated party and the reporter, nothing more. No operator of BriansClub is publicly identified in this record and none is named or guessed at here. No card data, card numbers, or cardholder identifiers are reproduced — the breach victims already paid once. If a line here couldn’t survive scrutiny, it wouldn’t be on the page.