Dark Web Sells Executive Social Security Numbers for Just $0.25, Rapid7 Warns
Corporate executives are increasingly becoming targets of an underground identity economy where sensitive personal information is packaged and sold on dark-web marketplaces for surprisingly low prices.
According to research documented by Rapid7, Social Security numbers (SSNs) belonging to corporate personnel can be purchased for as little as $0.25 per record.
The findings demonstrate how cybercriminals are shifting beyond stolen passwords and payment cards toward persistent identity attributes that can be enriched with additional information and repeatedly exploited for fraud, impersonation, and corporate intrusion.
Unlike a compromised payment card, which can generally be canceled and replaced, a Social Security number is a long-term identity identifier that is difficult to change.
Dark Web Sells Executive Social Security
Criminals can combine leaked SSNs with names, addresses, dates of birth, telephone numbers, employment information, and publicly available executive profiles to construct detailed identity records.
These enriched profiles can provide attackers with the background necessary to impersonate high-value individuals or conduct convincing social-engineering campaigns against organizations.
Rapid7 reported tracking 476 compromised SSN records associated with 395 unique corporate personnel since early 2026. Senior executives represented a disproportionate share of the exposed identities, with C-suite personnel accounting for 44.6% of observed profiles and company presidents representing another 28.6%.
The activity was also heavily concentrated in the United States, with 95.6% of observed leaks associated with U.S.-headquartered companies. Financial services organizations represented more than one-quarter of affected companies, followed by industrial organizations at 17%.
Rapid7 identified three marketplaces, Xilo, Bankomat, and PeopleFinder, as responsible for 81.5% of the executive SSN leaks observed during its research.
Xilo, which has operated since March 2025, reportedly provides SSN records for a flat $0.25 fee and offers reverse-lookups for approximately $0.50 to enrich profiles with telephone numbers and other contact information.
Bankomat, active since 2022, reportedly charges around $4 per record while operating as a broader carding marketplace that combines identity information with stolen payment-card data and validation services.
PeopleFinder is described as a rebranded successor to the previously seized SSNDOB marketplace. The service reportedly charges approximately $1.50 per lookup and draws from a legacy database containing more than 24 million U.S. personally identifiable information records.
These marketplaces generally function as downstream distributors rather than the original source of the information. Data can originate from major breaches involving data brokers, healthcare organizations, financial institutions, and other organizations holding large volumes of personal information.
The ecosystem is also being strengthened by infostealer malware and phishing campaigns, which can provide fresher and more targeted information.
Stolen data may include identity documents, browser credentials, tax records, contact information, and other sensitive files stored on compromised devices. Combining this information with previously leaked SSNs enables criminals to build significantly more convincing victim profiles.
The business impact extends well beyond conventional identity theft. Executive identity information can support synthetic identity fraud, fraudulent credit applications, tax-related scams, account takeovers, and highly targeted social engineering.
When attackers combine personal information with corporate filings, organizational charts, social-media activity, and executive responsibilities, they can create credible impersonation scenarios.
Finance departments, executive assistants, payroll teams, and external partners may subsequently receive fraudulent requests that appear to originate from legitimate leadership.
Rapid7 recommends treating executive identity exposure as an ongoing security concern rather than a single breach-response event.
Organizations should continuously monitor relevant threat-intelligence sources for exposed executive information, minimize unnecessary public disclosure of leadership data, and establish out-of-band verification for financial transfers, payroll changes, sensitive document requests, and other high-risk actions.
Executives and their support teams should also receive targeted training on identity-based impersonation and social-engineering techniques.
The low cost of an SSN on underground marketplaces illustrates the scale of the problem: the information itself may be cheap, but its downstream value can be substantial.
Because compromised identity attributes remain useful long after their original exposure, organizations need continuous monitoring, stronger verification procedures, and layered fraud controls to prevent inexpensive leaked data from becoming the foundation for expensive corporate attacks.
No Comment! Be the first one.