Joker's Stash Turkish Card Leak: 2026 Status

- Joker's Stash and the Turkish card leak in 2026: the short answer
- Timeline: from the Turkish batches to the market's closure
- What changed since 2019
- Risks and scams around leaked cards in 2026 (our analysis)
- Six steps to protect your cards
- What is still unknown
- Our original 2019 report
- The sold information comes from different Turkish banks
- JavaScript-based skimmers are the likely culprit of the data leak
- Related guides on 2-Spyware
Joker's Stash and the Turkish card leak in 2026: the short answer
The market that sold the cards is gone. Joker's Stash, the largest dark web shop for stolen payment cards, announced on January 15, 2021 that it was closing, and said it would stay online until February 15, 2021.[6][7] We found no credible report that the original market came back. The trade in stolen cards did not stop, though. Researchers expected its vendors to move to other large markets.[6]
For the 455,000 Turkish card records listed in late 2019, the risk today is mostly about the personal data sold with them: names, emails and phone numbers.[2] Cards expire and banks reissue them, but that contact data still feeds phishing and scam calls years later.
| Question | Answer |
|---|---|
| How many records | About 455,000 Turkish card records in four batches[2] |
| Where they were sold | Joker's Stash, a dark web carding market[2] |
| Price per card | 3 US dollars for the first two batches, 1 dollar for the last two[2] |
| Likely source | Unknown; web skimmers were the main suspect[1][2] |
| Market status | Closure announced January 15, 2021, set for February 15, 2021[6][7] |
| Card market after closure | Estimated at 1.4 billion dollars in 2021, down from 1.9 billion[8] |
Timeline: from the Turkish batches to the market's closure

| Date | Event |
|---|---|
| October 28, 2019 | Batches TURKEY-MIX-01 and TURKEY-MIX-02 listed at 3 dollars a card[2] |
| November 27, 2019 | Batches TURKEY-MIX-03 and TURKEY-MIX-04 listed at 1 dollar a card[2] |
| December 11, 2019 | 2-Spyware publishes its report on the leak |
| January 15, 2021 | Joker's Stash announces its closure[6][7] |
| February 15, 2021 | Announced final day of the market[6][9] |
| December 20, 2021 | CyberScoop reports the carding market at 1.4 billion dollars, down from 1.9 billion[8] |
What changed since 2019
The biggest change is that Joker's Stash no longer exists. Its owner announced a retirement in January 2021, and the real reason for the shutdown stayed unclear.[6] Recorded Future noted that the market had already shown a steep fall in the number of new records posted in the six months before the announcement.[6]
The closure did not end card fraud. Recorded Future assessed with high confidence that the vendors behind Joker's Stash would move to other top-tier markets, and that the wider card economy would stay largely unaffected.[6] A year later, CyberScoop reported research that put the illicit card market at 1.4 billion dollars, down from 1.9 billion the year before.[8] So the market shrank, but it is still large.
For the Turkish cardholders of 2019, time helped. Most cards from those batches have long expired or been replaced. What stays valid is the personal data that came with them, which criminals can reuse to make phishing messages look real.
Risks and scams around leaked cards in 2026 (our analysis)
This list is our own analysis of how old card leaks are still used, based on the data types listed in the 2019 sale.[2]
- Fake bank calls and SMS. A caller who already knows your name, card type and phone number can sound like your bank and ask for a one-time code.
- Phishing that quotes the leak. Messages that say your card was found on the dark web and send you to a fake page to "verify" it.
- Copycat Joker's Stash sites. Pages that use the old brand to sell fake card data or to infect visitors with malware.
- Paid dark web scans that are not real. Services that promise to remove your card from the dark web. Nobody can do that.
- Reused card numbers. A card that was never replaced can still be tested with small charges.
Six steps to protect your cards

1. Check statements. Read your card statements for the last few months. Test charges are often tiny, so look at every line, not only large payments.
2. Turn on alerts. Set your banking app to send a message for every card payment. You will see fraud the same minute it happens.
3. Replace the card. If you think your card was exposed, ask the bank for a new card number. A new number makes the stolen record useless.
4. Never share codes. Your bank will not ask you to read out a one-time code or your full card details on a call. Hang up and call the number on the back of your card.
5. Check your email. Use our leak check to see whether your email appeared in a known breach, and change passwords that were reused.
6. Report fraud. Contact your bank at once about unknown charges, ask for a refund, and report phishing messages. Our guide on how to report phishing explains where.
What is still unknown
- The real source of the 2019 Turkish card data. Group-IB said it remained unknown.[1][2]
- Why Joker's Stash really closed. The research we read calls the true reason unclear.[6]
- Which markets took over the Turkish card trade after 2021. We found no public report on that.
Our original 2019 report
The text below is our report as first published in 2019. We keep it unchanged for the record; the sections above bring it up to date.
Security researchers at Group-IB[1] discovered a new data leak – this time, it concerns Turkey-issued credit card details. According to several news networks, more than 450,000 payments cards are being sold on the underground credit card market Joker's Stash, and it is one of the largest data bumps of such kind in recent years.
According to news outlet ZDNet,[2] the data was uploaded in four different batches between October 28 and November 27 this year, and each consisted of 30,000 30,000, 190,000, 250,000 entries, respectively. If malicious actors were to sell all the data, they are bound to earn more than half a million US dollars.
It is not the first time Joker's Stash was mentioned in the news. In late October, 1.3 million credit and debit card details (making it the biggest posting to date) were listed on the same underground forums, mainly belonging to users of various Indian banks.[3] Without a doubt, if malicious actors can sell sensitive information for merely 1 – 3 dollars a piece, the data must be easily obtainable, and more users need to be aware of the dangers of such exposure.
The sold information comes from different Turkish banks
The offered information included data from various user accounts (Personal, Gold, Classic, etc.) and also referred to credit, as well as debit cards. The listing by malicious actors explained that all the information presented in the database includes all the necessary details in order to make online purchases and other non-card related transactions, such as CCV's, expiration dates, and other data, as explain Group-IB researchers:
All the compromised credit and debit cards records in this database were identified as raw cards data also known as 'CCs' or 'fullz' and contained the following information: expiration date, CVV/CVC, cardholder name as well as some additional info such as email, name and phone number.
Card details uploaded on October 28 (named TURKEY-MIX-01 and TURKEY-MIX-02) were listed for $3 each, while the latter two batches pasted on November 27 (TURKEY-MIX-03 and TURKEY-MIX-04) included a "special price" of $1 per credit/debit card. The post claimed that 85% to 90% of the cards posted are still valid and in working order.
Because most of the credit card details came from various (top) Turkish banks, experts believe that the hack is not related to a single bank, ad there are three possibilities oh how the data ended up in threat actors' hands:
- JavaScript skimmers installed on the eCommerce sites that handle online payments
- Malware that could harvest data was installed on thousands of users' computers
- Victims entered the credit card details themselves into spoofed/phishing websites crafted specifically for the purpose.
JavaScript-based skimmers are the likely culprit of the data leak
While malware infections and spoofing sites still remain a possibility, the fact that most of the data came from Turkey suggests that card skimmers were the likely attack vector, although Group-IB experts said that "the source of this compromise remains unknown."
Credit card skimmers have gained popularity in recent years, and multiple high-profile hackers employ the technique in order to mass-harvest credit card details. For example, the notorious Magecart[4] hit targets like Shopper Approved, Macy's, Garmin, Ticketmaster,[5] and many others, resulting in millions of users' credit card detail compromise.
Without a doubt, Turkish users should immediately start monitoring their online banking to ensure no money is taken directly from the account. After data compromise like this one, victims might face money loss, targeted phishing campaigns, or even identity fraud. Upon detection of malicious activity, users should immediately contact the corresponding bank, request a refund, and cancel your credit/debit card immediately.
Related guides on 2-Spyware
Frequently asked questions
What was Joker's Stash (joker ccs)?
Joker's Stash was the largest dark web marketplace for stolen payment card data, often searched as "joker ccs".{6} It sold raw card records, called CCs or fullz, with numbers, expiry dates, CVV codes and cardholder details. In late 2019 it listed about 455,000 Turkish card records in four batches.{2} The shop announced its closure on January 15, 2021.{6}{7}
Is Joker's Stash still online in 2026?
No, as far as we can find. The administrator announced on January 15, 2021 that the market would stay open only until February 15, 2021.{6}{7} We found no credible report that the original market returned. Sites that use its name today are best treated as scams or copycats, and visiting them is risky.
Did the Turkish card leak stop when Joker's Stash closed?
No. Closing the shop did not cancel the stolen cards. Researchers expected the vendors who supplied Joker's Stash to move to other large dark web markets.{6} Any card from the 2019 batches that was not replaced could have been resold elsewhere. Most of those cards have since expired or been reissued, but the personal details sold with them do not expire.
How do I know if my debit card was leaked?
You usually learn it from your bank or from a charge you did not make. Banks receive alerts about compromised cards and often reissue them without a public notice. Check your statements, turn on transaction alerts, and ask your bank to replace the card if you see anything unknown. Our leak check can tell you whether your email appeared in a known breach.
Is there a Turkish dark web forum selling cards today?
We do not track or link to criminal forums. The 2021 research we read says card vendors move between top-tier markets when one closes, so card sales continue under other names.{6}{8} For a cardholder in Turkey the practical answer is the same: watch your account, use alerts, and replace any card that shows strange activity.
How were the Turkish cards stolen?
The exact source was never confirmed. Group-IB said the source of the compromise remained unknown.{1}{2} The main suspects named at the time were JavaScript skimmers on online shops, malware on victims' computers, and phishing pages where people typed their card details themselves. Skimmers were considered the most likely cause.
Log in to comment
No comments yet. Be the first.