Cyber Security News

Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents

Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email compromise (BEC), and identity theft.

Recent threat research from Rapid7 reveals an increasingly sophisticated “identity-as-a-service” ecosystem. In this environment, criminal platforms package stolen SSNs with names, addresses, dates of birth, phone numbers, and other personally identifiable information (PII).

Unlike passwords or payment cards, SSNs cannot be reset once exposed, making them a lasting asset for cybercriminals.

Executive PII Becomes a Corporate Risk

Rapid7’s analysis identified 476 compromised SSN listings tied to 395 unique corporate personnel since the beginning of 2026.

Senior leaders made up the largest share of affected individuals: C-suite executives accounted for 44.6% of profiles. In comparison, presidents and vice presidents accounted for 28.6%.

The exposure risks extend beyond personal financial fraud. Attackers can combine leaked SSNs with public corporate biographies, securities filings, social media profiles, and compromised data to create highly convincing executive profiles.

These records can facilitate spear-phishing attempts, fraudulent account creation, tax scams, synthetic identity fraud, and impersonation efforts targeting employees, suppliers, and financial institutions.

PeopleFinder SSN listings (Source: Rapid7)

Financial organizations represented over a quarter of the affected entities in Rapid7’s dataset, with industrial companies following at 17%. Nearly 95.6% of the exposed records were associated with U.S.-headquartered organizations.

Three Major SSN Marketplaces

Rapid7 identified three marketplaces, Xilo, Bankomat, and PeopleFinder, that together accounted for 81.5% of executive SSN exposures in its study.

MarketplaceSSN priceNotable capabilities
Xilo$0.25Searches by name, location, and birth year; optional reverse lookups
PeopleFinder$1.50Searches by name, date of birth, or address
Bankomat$4SSN records alongside stolen card data and card-validation services

Xilo was responsible for 40.8% of leaked executive SSNs observed by Rapid7, making it the largest source in the research sample.

The service displays identifying details, such as a victim’s name, home address, and date of birth, before the purchase, allowing criminals to verify a target before paying for the SSN.

It also provides reverse lookups for $0.50, enabling buyers to submit an SSN or phone number and access additional identifying data. Such enrichment functions can transform a single stolen identifier into a broader, fraud-ready profile.

Bankomat has been active since at least 2022 and combines identity-data sales with carding operations. Meanwhile, PeopleFinder appears to be linked to the infrastructure and legacy data from the previously seized SSNDOB Marketplace, reportedly granting access to over 24 million compromised U.S. PII records.

Rapid7 Platform alert about the leaked details of a company executive

These platforms typically do not steal data themselves; instead, they function as downstream clearinghouses, acquiring databases sourced from large-scale breaches, data aggregators, healthcare organizations, financial providers, phishing operations, and infostealer malware infections.

Infostealers can be particularly valuable, as they may collect locally stored documents, saved browser data, tax files, and corporate onboarding materials from unmonitored or personal devices. Criminal operators can then parse and index that data for resale.

Organizations should regard exposure of executive PII as an enterprise security issue, not just a private matter. Security teams should monitor dark web sources for VIP identity data, strengthen out-of-band verification for executive payment and account-change requests, and train employees to recognize impersonation attempts.

Companies should also develop executive-focused incident-response procedures, including credit monitoring, fraud alerts, identity-verification reviews, and proactive communication with finance, HR, and legal teams. The low price of an SSN does not indicate a low risk; a 25-cent record can serve as the starting point for a costly, highly targeted corporate breach.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…

3 minutes ago

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…

14 minutes ago

Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days

A cyber incident reportedly forced a small UK power generation facility offline for about four…

23 minutes ago

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages…

25 minutes ago

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government,…

59 minutes ago

Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth

Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be…

3 hours ago