Stolen SSNs of Corporate Execs Sold for 25 Cents on Dark Web
Key Takeaways Highly sensitive Social Security Numbers (SSNs) of corporate executives are being sold on dark web marketplaces for as little as $0.25. Unlike credit card numbers, compromised SSNs...
Key Takeaways
- Highly sensitive Social Security Numbers (SSNs) of corporate executives are being sold on dark web marketplaces for as little as $0.25.
- Unlike credit card numbers, compromised SSNs represent a permanent liability, fueling an underground economy around executive identity theft.
- Since early 2026, Rapid7 has identified 476 instances of compromised SSN records linked to 395 unique corporate personnel, with C-suite executives and presidents disproportionately affected.
- The leaks predominantly originate from U.S.-headquartered companies, with the financial and industrial sectors being hit hardest.
- Three primary dark web platforms—Xilo, Bankomat, and PeopleFinder—account for over 80% of identified executive SSN leaks, acting as clearinghouses for data obtained through large-scale breaches and infostealer malware.
The most critical identity data belonging to corporate executives is readily available on dark web marketplaces, with some Social Security Numbers (SSNs) trading for as little as 25 cents. This alarming trend, highlighted by new threat intelligence from Rapid7, underscores a significant and persistent cybersecurity risk.
Table Of Content
Unlike financial credentials such as credit card numbers, which can be quickly canceled and reissued, a compromised SSN represents a permanent vulnerability. Cybercriminals are exploiting this immutable nature of SSNs to cultivate a robust underground market centered on executive identity theft.
Since the beginning of 2026, Rapid7 has meticulously tracked 476 instances of exposed SSN records associated with 395 distinct corporate individuals. The data reveals a strong bias toward senior leadership, with C-suite executives making up 44.6% of the affected profiles and company presidents accounting for an additional 28.6%.
Cybercriminals Monetizing Executive Social Security Numbers
Given that SSNs are a unique identifier specific to the United States, 95.6% of the observed leaks originated from U.S.-based organizations. The financial sector has been particularly impacted, accounting for over 25% of exposures, followed by industrial companies at 17%.
Rapid7’s research focuses on three dominant platforms responsible for 81.5% of all identified executive SSN leaks: Xilo, Bankomat, and PeopleFinder.
Key Dark Web Marketplaces
Xilo, operational since March 2025, functions as a Tor hidden service with accessible clear-web mirrors. It offers SSN records for a flat fee of $0.25 each. For an additional $0.50, users can opt for a reverse-lookup feature that enriches profiles with supplementary phone and contact details.
Bankomat, active since 2022, prices each record at $4. However, it serves as a comprehensive carding marketplace, offering stolen payment card data and validation tools alongside identity records.
PeopleFinder, a successor platform to the previously seized SSNDOB Marketplace, continues to operate using a legacy database containing over 24 million U.S. Personally Identifiable Information (PII) records. Lookups on this platform cost $1.50 per query.
These dark web storefronts do not generate the stolen data themselves. Instead, they operate as downstream clearinghouses, acquiring bulk records from significant breaches of data aggregators, healthcare systems, and financial institutions. Concurrently, information-stealer malware and targeted phishing campaigns provide newer, more specific profiles harvested from personal devices and sensitive documents like tax returns.
While passwords can be reset and credit cards can be frozen, an SSN is an unchangeable identity attribute that retains its criminal value indefinitely. When combined with other PII, a compromised SSN forms the bedrock for various illicit activities, including synthetic identity fraud, the creation of fraudulent credit lines, tax scams, and, for high-profile individuals, highly convincing executive impersonation and business email compromise (BEC) schemes.
Furthermore, when enriched with publicly available biographical information from corporate filings or social media, a stolen SSN can significantly enhance the credibility and success rate of phishing or social engineering attacks targeting an entire organization.
What You Should Do
- Implement Continuous Dark Web Monitoring: Treat executive identity exposure as an ongoing risk. Deploy continuous monitoring solutions that track executives’ names and known identifiers across dark web marketplaces to detect leaked records promptly.
- Consider Takedown or Purchase Options: If leaked records are identified, explore options for takedown requests or even purchasing the listings to prevent further acquisition by other malicious actors.
- Limit Public Digital Footprint: Advise executives to minimize their public digital footprint, especially regarding personal details that could be cross-referenced with stolen SSNs.
- Enforce Out-of-Band Verification: Mandate robust out-of-band verification protocols for all sensitive financial or administrative requests, particularly those involving executive approval.
- Provide Targeted Training: Conduct specialized security awareness training for C-suite members and their executive assistants, focusing on identifying and resisting impersonation tactics, social engineering, and sophisticated phishing attempts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.