Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email compromise (BEC), and identity theft.
Recent threat research from Rapid7 reveals an increasingly sophisticated “identity-as-a-service” ecosystem. In this environment, criminal platforms package stolen SSNs with names, addresses, dates of birth, phone numbers, and other personally identifiable information (PII).
Unlike passwords or payment cards, SSNs cannot be reset once exposed, making them a lasting asset for cybercriminals.
Rapid7’s analysis identified 476 compromised SSN listings tied to 395 unique corporate personnel since the beginning of 2026.
Senior leaders made up the largest share of affected individuals: C-suite executives accounted for 44.6% of profiles. In comparison, presidents and vice presidents accounted for 28.6%.
The exposure risks extend beyond personal financial fraud. Attackers can combine leaked SSNs with public corporate biographies, securities filings, social media profiles, and compromised data to create highly convincing executive profiles.
These records can facilitate spear-phishing attempts, fraudulent account creation, tax scams, synthetic identity fraud, and impersonation efforts targeting employees, suppliers, and financial institutions.
Financial organizations represented over a quarter of the affected entities in Rapid7’s dataset, with industrial companies following at 17%. Nearly 95.6% of the exposed records were associated with U.S.-headquartered organizations.
Three Major SSN Marketplaces
Rapid7 identified three marketplaces, Xilo, Bankomat, and PeopleFinder, that together accounted for 81.5% of executive SSN exposures in its study.
| Marketplace | SSN price | Notable capabilities |
|---|---|---|
| Xilo | $0.25 | Searches by name, location, and birth year; optional reverse lookups |
| PeopleFinder | $1.50 | Searches by name, date of birth, or address |
| Bankomat | $4 | SSN records alongside stolen card data and card-validation services |
Xilo was responsible for 40.8% of leaked executive SSNs observed by Rapid7, making it the largest source in the research sample.
The service displays identifying details, such as a victim’s name, home address, and date of birth, before the purchase, allowing criminals to verify a target before paying for the SSN.
It also provides reverse lookups for $0.50, enabling buyers to submit an SSN or phone number and access additional identifying data. Such enrichment functions can transform a single stolen identifier into a broader, fraud-ready profile.
Bankomat has been active since at least 2022 and combines identity-data sales with carding operations. Meanwhile, PeopleFinder appears to be linked to the infrastructure and legacy data from the previously seized SSNDOB Marketplace, reportedly granting access to over 24 million compromised U.S. PII records.
These platforms typically do not steal data themselves; instead, they function as downstream clearinghouses, acquiring databases sourced from large-scale breaches, data aggregators, healthcare organizations, financial providers, phishing operations, and infostealer malware infections.
Infostealers can be particularly valuable, as they may collect locally stored documents, saved browser data, tax files, and corporate onboarding materials from unmonitored or personal devices. Criminal operators can then parse and index that data for resale.
Organizations should regard exposure of executive PII as an enterprise security issue, not just a private matter. Security teams should monitor dark web sources for VIP identity data, strengthen out-of-band verification for executive payment and account-change requests, and train employees to recognize impersonation attempts.
Companies should also develop executive-focused incident-response procedures, including credit monitoring, fraud alerts, identity-verification reviews, and proactive communication with finance, HR, and legal teams. The low price of an SSN does not indicate a low risk; a 25-cent record can serve as the starting point for a costly, highly targeted corporate breach.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…
A cyber incident reportedly forced a small UK power generation facility offline for about four…
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages…
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government,…
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be…