Joker’s Stash, one of the largest dark web marketplaces for stolen payment card data, announced it would permanently close after allowing users roughly 30 days to withdraw balances and complete partner payouts. The operator said the market would remain online until February 15, 2021, then wipe servers and backups. The shutdown followed months of instability, including a reported decline in newly posted card records, customer complaints about poor card validity, and claims by the administrator that illness from COVID-19 had disrupted operations.
The closure also came after suspected law enforcement pressure, including reports that blockchain-linked domains briefly displayed FBI and INTERPOL seizure notices and allegations that proxy servers tied to the marketplace had been seized by the U.S. Department of Justice and INTERPOL. Researchers said the broader underground payment-card economy was unlikely to collapse, with displaced vendors and buyers expected to migrate to rival carding markets such as Brian’s Club, Vclub, Yale Lodge, and UniCC, which moved quickly to attract former Joker’s Stash users through promotions and other incentives.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Joker’s Stash said it would cease operations on February 15, 2021, ending the 30-day wind-down period announced in January. The operator also said the site’s servers and backups would be wiped after that date.
From February 3 to 9, 2021, UniCC reportedly added almost 300,000 new credit card details, reflecting efforts by rival marketplaces to absorb users displaced by Joker’s Stash’s closure.
On January 15, 2021, Joker’s Stash announced on its site and underground forums that it would close permanently and that the administrator was retiring. The operator said the marketplace would remain open for 30 days so users could spend balances and partners could be paid.
In December 2020, several Joker’s Stash blockchain domains were temporarily replaced with an FBI and Interpol seizure notice, prompting speculation about law enforcement pressure. The administrator later regained control of the affected domains.
In October 2020, the alleged Joker’s Stash operator said he had contracted COVID-19 and spent more than a week in the hospital, which reportedly disrupted forum activity, inventory replenishment, and other operations.
Gemini Advisory reported that Joker’s Stash had operated since 2014 and was one of the oldest observed dark web marketplaces in the payment card underground.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourceke-la.com
Open sourcegeminiadvisory.io
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.