In a 2016 controlled experiment, security firm Bitglass placed phished Google Apps credentials for a fictitious employee on the Dark Web and monitored a linked Google Drive account and fake bank portal. SecurityWeek reported that the credentials drew more than 1,400 visits and that some people who reached the Drive tried the same password at the bank portal. The test illustrates the danger of password reuse; it does not measure how often real bank accounts are compromised.
How Bitglass set up the experiment
SecurityWeek reported on February 18, 2016, that Bitglass’s Project Cumulus was its second annual “Where’s Your Data” experiment. Bitglass created a fictitious employee identity for a fictitious retail bank, set up a functional bank portal and a Google Drive account, then exposed phished Google Apps credentials on the Dark Web and tracked what followed. The bank account and identity were fabricated; this was a controlled tracking study, not a real customer breach.
As an Amazon Associate I earn from qualifying purchases.
Within 24 hours, the researchers recorded five attempts to log in to the fake bank portal and three to Google Drive. Files were downloaded within 48 hours. Over the following month, the account was viewed hundreds of times, and the report said many hackers successfully accessed the victim’s other online accounts.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat the reported figures show
The counts and percentages below are Bitglass’s observations as reported by SecurityWeek in 2016. They describe this experiment’s accounts and activity, not the prevalence of bank-account theft, the behavior of all Dark Web users, or conditions today.
#1 Best Overall
| Observation | Reported result |
|---|---|
| Visits to the Dark Web credentials and fictitious bank portal | More than 1,400 |
| Google Drive visitors who successfully accessed the fake personal banking account using the leaked password | 36% |
| Hackers who accessed Google Drive, uncovered other online accounts and attempted to log in to the bank portal | 94% |
| Hackers who successfully accessed Google Drive and attempted to download sensitive files | 12% |
| All logins coming from Tor-anonymized IP addresses | 68% |
| Non-Tor visits to the fake bank portal by apparent origin | Russia: 34.85%; United States: 15.67%; China: 3.5%; Japan: 2% |
| Countries across six continents from which login attempts came | 30 |
The clearest pattern is movement between accounts: people who reached the Drive often searched for other accounts and attempted logins at the bank portal, and a portion succeeded with the leaked password. The figures do not establish that a particular visitor was a criminal, that each visit represented a different person, or that the same rates apply to real customers.
Why password reuse creates a financial risk
A password exposed through phishing or a data breach can become a key to other accounts when people reuse it. In this experiment, access to Google Drive gave visitors an opportunity to discover other accounts, while the reused password let some of them enter the fictitious banking account. For a real person, an email or cloud account may also expose account notices, password-reset messages, financial documents, or clues to other services. This study demonstrates a possible path, not how often every step occurs.
Ways to reduce the risk
- Use a unique password for every financial and email account. If one password is exposed, uniqueness limits the chance that it will unlock another service.
- Turn on multifactor authentication where available. Prefer an authentication method designed to resist phishing when the provider supports one; methods and recovery options differ by service.
- Secure the email account used for financial recovery. An attacker who controls that inbox may be able to pursue password resets on linked accounts.
- Respond promptly to signs of compromise. Change exposed passwords to unique ones, review account activity and recovery details, and contact the bank through its official channel if banking access may be affected.
- For organizations, detect suspicious access and limit data exposure. Bitglass’s stated takeaway was to use more secure authentication and enable IT to identify breaches quickly and control access to sensitive data; the report did not test or endorse a specific product.
What this 2016 report can and cannot tell you
SecurityWeek’s report attributes the study and its findings to Bitglass and linked to a Bitglass PDF report. The findings here are therefore attributed reporting, rather than independently verified details from that primary document. The experiment is useful as a demonstration of how credentials can be reused and accounts explored, but its fabricated identity, small set of observed logins, and 2016 date make it unsuitable as a current estimate of bank fraud or credential theft.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




