Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites

Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites

By: Jordan Vector — Cybersecurity Expert

Last updated: October 2, 2026

Human Written
Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites
  • A forum actor is seeking valid WordPress administrator access, with unique credentials and higher-traffic sites reportedly attracting more interest.

  • The buyer asks for a line format common in data taken by password-stealing malware.

  • The request highlights the growing value of stolen browser credentials and session data, which can give criminals access without exploiting a WordPress flaw.

A user in a Russian-speaking dark web forum is reportedly shopping for access keys to other people’s websites. In the newly surfaced underground market listing, the buyer says they want unique and working credentials for WordPress administrator login and admin pages.

The listing also places more value on websites with higher traffic. The buyer says they’ll check credentials before making payment. They may also ask for a small number of samples to test before completing a deal.

It’s worth noting that the request didn’t name any particular victim, specific website, company, or organization. So for now, the post remains just an unverified dark web market listing.

Details of the Listing

The buyer wants admin-level access that is “good,” with no “10 neighbors.” That means the login should not have been sold to many other people. Each one should be unique. Busy websites are a plus, according to the post.

Additionally, the buyer requires lines with web addresses, usernames, and passwords. They’ll run them through a checker, it is a tool for testing whether logins are valid. If the login passes this test, it can be sold. The price of the items will be negotiated privately. The price of the item is given as “0-2” without specifying any currency.

Two requirements of the buyer are declined logins and “CIS lines.” The buyer may also request five to ten samples at the beginning of the interaction to make sure the material meets their criteria. The profile is a seller and is registered in December 2024 with 74 posts.

There is a line below the post that indicates that the user is seeking work. There is nothing in the post that could prove the transaction took place. It is a request, not a purchase.

What WordPress Admin Access is Valuable

WordPress runs a large percentage (about 42.6%) of all websites, according to stats from W3Techs. That makes it a big target. An admin login lets a person install plugins, edit themes, and reach the site’s database. Hacked sites are then put to work. Attackers plant spam links, redirect visitors, and spread malware.

Traffic is likely the draw here. The attacker needs popular websites, and a network of attacks known as VexTrio exploited around 20,000 hacked WordPress sites to redirect users and make money from ads. In addition, some attackers use hacked sites to display fake verification pages containing the Lumma Stealer, password-stealer malware. The cycle feeds itself.

Another way attackers exploit WordPress is by hiding a backdoor in the lesser-known folder mu-plugins. Any plugins stored in this folder load automatically without showing in the dashboard. This gives attackers time to go undetected for a long time.

This kind of login data pattern is frequent in stolen files. As explained by Hudson Rock, password-stealing malware generates stealer logs containing username, password, and cookies. Threat actors trade these files on Telegram and other private forums.

The post does not say where the buyer wants to get logins. But the format points that way. One industry guide says this type of malware took 1.8 billion credentials in 2025. Bulk logins can sell for as little as ten dollars, according to Wikipedia. Buyers often test them first, which matches the checker step in this post.

The CIS Exception

A lot of Russian-language forums have since banned attacks on CIS countries, which are mostly old Soviet states. Researchers call it an unwritten rule. You can see it in the malware, too some malware even refuses to run on a computer set to Russian.

But things have shifted, so that rule seems to have weakened. After Russia invaded Ukraine, the forum XSS reportedly stopped counting Ukraine as part of the CIS. Even so, the buyer’s decision lines up with the old habit. Maybe they just want to stay out of trouble at home. Russian authorities often overlook crimes committed against foreigners.

Stolen Admin Logins Create a Much Bigger Threat

This post falls into a broader trend. In March 2026, Brinztech announced the existence of a listing that included full administrator privileges to a Dutch online shop. In April, researchers warned about a plugin vulnerability, CVE-2026-1492, that let someone without a password gain administrator access.

WordPress plugins have also been used to plant persistent access, with hackers recently placing a backdoor in more than 30 plugins and triggering an emergency security patch. Also, SOCRadar talked about a toolkit that collected over 2.1 million WordPress admin passwords from more than 600,000 websites. The most popular one was admin:admin, found at 10,548 websites.

What Site Owners Can Do

Most of the fixes are simple. Use a long, unique password for every admin account. Turn on two-step login. Delete admin accounts nobody uses. Update plugins as soon as fixes come out.

Check your user list for admins you do not recognize. Attackers often add hidden ones. If a computer catches malware, clean it, change every password, and log out all active sessions. Stolen session cookies can still work after a password change.

Ask your host or a security plugin to scan for odd files, too. A new admin account or strange code in your theme files can be the first sign of a break-in.

Buyers like this one create demand, and demand rewards the people who steal logins. A forum post is only talk. But the request shows how routine this trade has become. For site owners, the safest move is to assume someone is already looking for the weak login.

Share this article

You might also like

Hacker Claims Over 300,000 Mexican Tuberculosis Records are for Sale

Hacker Claims Mexico’s Tuberculosis Database is for Sale with 305,000 Patient Records

Someone on a cybercrime forum claims to hold 305,852 tuberculosis records from Mexico’s national disease tracking system, and is selling…

September 30, 2026
Polish Healthcare Software Firm Qbusoft Confirms Patient Data Breach

Qbusoft Cyberattack Exposes Sensitive Patient Data as Polish Regulators Investigate

Hackers broke into Qbusoft, a Polish company that builds software for hospitals and clinics, and stole patient data. The stolen…

September 30, 2026
ZachXBT Says Bitget Hack Launderers Seek Help in Public Chat Rooms

ZachXBT Says Bitget Hack Launderers Seek Help in Public Chat Rooms

Blockchain investigator ZachXBT says Chinese groups are helping move stolen crypto from the Bitget hack. Bitget confirmed hackers stole $387.5…

September 30, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.