Answer first
The "joker website" most people mean is Joker's Stash, a dark web marketplace that sold stolen payment card data. It ran from about 2014 until February 2021, when its operator posted a retirement notice and the site went offline. It was not a normal store. It was a criminal market, and buying or selling card data there violated US federal law.
What Joker's Stash sold
Listings fell into two groups.
- Dumps. Magnetic stripe data copied from the back of a card, used to make a counterfeit card.
- CVV data. Card number, expiration date, and the card verification value, used for online purchases.
Data came from breaches at retailers, hotels, and payment processors, and from malware and skimmers installed on point of sale systems. Sellers rated each batch with a "valid rate," a percentage of cards that still worked. That figure was self-reported and often inflated.
Timeline
- 2014. The market opens on Tor. The operator uses the alias JokerStash.
- 2015 to 2020. Volume grows. Security researchers rank it among the largest card markets by number of records offered.
- February 2021. The operator posts a retirement notice. Bitcoin held by the market moves to other wallets. The site stops taking new listings.
Why the shutdown matters
Joker's Stash was not the only card market. Carder forums and Telegram channels took over some of the traffic. Card networks and banks added better fraud scoring, and the US rollout of EMV chips cut counterfeit card fraud at physical terminals. Online card fraud did not fall by the same amount, because a chip does not protect a card number typed into a web form.
Legal exposure
US law treats card data as an "access device." Trafficking in it falls under 18 U.S.C. § 1029. Most offenses carry prison terms of up to 10 years and fines. Some carry 15 years. Prosecutors have charged buyers as well as sellers. A person who buys a dump and uses it also faces identity theft and wire fraud counts.
Buyer risk beyond the law
Card markets have no enforcement. Fraud researchers report the same patterns.
- Sellers take payment and send nothing.
- Cards are sold twice, so the first buyer to use one gets the order declined.
- "Fresh" and "100% valid" claims are marketing. The seller has no way to verify a card beyond a small test charge.
- Some markets are run by law enforcement from day one.
Cardholder protections
Under Regulation Z, a credit card holder's liability for unauthorized charges is capped at $50, and most issuers waive it. Debit card liability under Regulation E depends on how fast the holder reports the loss. In most cases the cardholder is made whole. The merchant, the processor, or the bank absorbs the loss.