Cybercriminals Are Selling Corporate Executives' Social Security Numbers for Just 25 Cents
Corporate executives’ most sensitive identity data is being sold on dark web marketplaces for as little as a quarter, according to new threat intelligence from Rapid7.
Unlike stolen credit cards, which can be canceled within minutes, a compromised Social Security number remains a permanent liability, and cybercriminals are exploiting that durability to build a thriving underground economy around executive identity theft.
Since early 2026, Rapid7 has tracked 476 instances of compromised SSN records tied to 395 unique corporate personnel. The exposure skews heavily toward senior leadership: C-suite executives account for 44.6% of affected profiles, while presidents make up another 28.6%.
Because SSNs are a U.S.-specific identifier, 95.6% of leaks originated from U.S.-headquartered companies, with the financial sector hit hardest at over 25%, followed by industrials at 17%.
Rapid7’s research focuses on three platforms that account for 81.5% of all executive SSN leaks identified: Xilo, Bankomat, and PeopleFinder.
Xilo, active since March 2025, operates as a Tor hidden service with clear-web mirrors and sells SSN records for a flat 25 cents each, with an optional $0.50 reverse-lookup feature that enriches profiles with additional phone and contact details.
Bankomat, running since 2022, charges $4 per record but doubles as a full carding marketplace, bundling stolen payment card data and validation tools alongside identity records.
PeopleFinder, a rebranded successor to the law-enforcement-seized SSNDOB Marketplace, still runs on a legacy database of more than 24 million U.S. PII records and charges $1.50 per lookup.
These storefronts don’t generate the data themselves.
They function as downstream clearinghouses, purchasing bulk records from large-scale breaches of data aggregators, healthcare systems, and financial institutions, while infostealer malware and phishing campaigns supply fresher, more targeted profiles pulled from personal devices and documents like tax returns.
| Marketplace / Platform | Operating Model & Price Point | Database Profile & Capabilities |
| Xilo | Tor hidden service / $0.25 flat per record | Optional $0.50 reverse lookup for contact and phone enrichment |
| Bankomat | Active since 2022 / $4.00 per record | Full carding hub bundling stolen credit cards, CVVs, and SSNs |
| PeopleFinder | SSNDOB successor / $1.50 per lookup | Legacy repository containing 24M+ U.S. personal identity records |
| Data Sourcing | Aggregator breaches, infostealers, phishing | High concentration of C-suite (44.6%) and Presidents (28.6%) |
Passwords can be reset, and cards can be frozen, but an SSN is a fixed identity attribute that retains criminal value indefinitely.
Combined with other personally identifiable information, it becomes the foundation for synthetic identity fraud, fraudulent credit lines, tax scams, and, for high-profile targets, highly convincing executive impersonation and business email compromise schemes.
Enriched with publicly available biographical details from corporate filings or social media, a stolen SSN can dramatically increase the credibility of a phishing or social engineering attack aimed at an entire organization.
Rapid7 recommends organizations treat executive identity exposure as an ongoing risk rather than a one-time incident.
Continuous dark web monitoring tied to executives’ names and known identifiers can flag leaked records early, while takedown or purchase options can remove listings before other buyers acquire them.
Limiting executives’ public digital footprint, enforcing out-of-band verification for sensitive financial or administrative requests, and training C-suite members and executive assistants on impersonation tactics round out a layered defense.
As underground marketplaces grow more efficient and accessible, the message for security teams is clear: once an executive’s SSN is exposed, the clock doesn’t reset, so detection speed and response now matter more than ever.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…