CyberSecurityNews

Cybercriminals Are Selling Corporate Executives’ Social Security Numbers for Just 25 Cents


Corporate executives’ most sensitive identity data is being sold on dark web marketplaces for as little as a quarter, according to new threat intelligence from Rapid7.

Unlike stolen credit cards, which can be canceled within minutes, a compromised Social Security number remains a permanent liability, and cybercriminals are exploiting that durability to build a thriving underground economy around executive identity theft.

Since early 2026, Rapid7 has tracked 476 instances of compromised SSN records tied to 395 unique corporate personnel. The exposure skews heavily toward senior leadership: C-suite executives account for 44.6% of affected profiles, while presidents make up another 28.6%.

Cybercriminals Selling Executive Social Security Numbers

Because SSNs are a U.S.-specific identifier, 95.6% of leaks originated from U.S.-headquartered companies, with the financial sector hit hardest at over 25%, followed by industrials at 17%.

sample distribution of leaked SSNs by sector (Image Source: Rapid7.com)

Rapid7’s research focuses on three platforms that account for 81.5% of all executive SSN leaks identified: Xilo, Bankomat, and PeopleFinder.

Xilo, active since March 2025, operates as a Tor hidden service with clear-web mirrors and sells SSN records for a flat 25 cents each, with an optional $0.50 reverse-lookup feature that enriches profiles with additional phone and contact details.

Bankomat, running since 2022, charges $4 per record but doubles as a full carding marketplace, bundling stolen payment card data and validation tools alongside identity records.

PeopleFinder, a rebranded successor to the law-enforcement-seized SSNDOB Marketplace, still runs on a legacy database of more than 24 million U.S. PII records and charges $1.50 per lookup.

These storefronts don’t generate the data themselves.

They function as downstream clearinghouses, purchasing bulk records from large-scale breaches of data aggregators, healthcare systems, and financial institutions, while infostealer malware and phishing campaigns supply fresher, more targeted profiles pulled from personal devices and documents like tax returns.

Rapid7 Platform alert about the leaked details of a company executive
Rapid7 Platform alert about the leaked details of a company executive (Image Source: Rapid7.com)
Marketplace / PlatformOperating Model & Price PointDatabase Profile & Capabilities
XiloTor hidden service / $0.25 flat per recordOptional $0.50 reverse lookup for contact and phone enrichment
BankomatActive since 2022 / $4.00 per recordFull carding hub bundling stolen credit cards, CVVs, and SSNs
PeopleFinderSSNDOB successor / $1.50 per lookupLegacy repository containing 24M+ U.S. personal identity records
Data SourcingAggregator breaches, infostealers, phishingHigh concentration of C-suite (44.6%) and Presidents (28.6%)

Passwords can be reset, and cards can be frozen, but an SSN is a fixed identity attribute that retains criminal value indefinitely.

Combined with other personally identifiable information, it becomes the foundation for synthetic identity fraud, fraudulent credit lines, tax scams, and, for high-profile targets, highly convincing executive impersonation and business email compromise schemes.

Enriched with publicly available biographical details from corporate filings or social media, a stolen SSN can dramatically increase the credibility of a phishing or social engineering attack aimed at an entire organization.

Rapid7 recommends organizations treat executive identity exposure as an ongoing risk rather than a one-time incident.

Continuous dark web monitoring tied to executives’ names and known identifiers can flag leaked records early, while takedown or purchase options can remove listings before other buyers acquire them.

Limiting executives’ public digital footprint, enforcing out-of-band verification for sensitive financial or administrative requests, and training C-suite members and executive assistants on impersonation tactics round out a layered defense.

As underground marketplaces grow more efficient and accessible, the message for security teams is clear: once an executive’s SSN is exposed, the clock doesn’t reset, so detection speed and response now matter more than ever.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link