Dark Web Marketplaces Thrive on Stolen Executive SSNs, Rapid7 Reports
Rapid7 research reveals 476 compromised SSN records for corporate personnel since early 2026, with over 73% targeting top leadership, traded on three major dark web marketplaces.

Identity theft continues to be a pervasive threat, with millions of reports annually and billions in financial losses. While stolen credit cards offer quick monetization, Social Security numbers (SSNs) represent a more dangerous, long-term asset for cybercriminals. Unlike payment cards, SSNs cannot be deactivated once exposed, enabling persistent fraud schemes such as unauthorized credit lines, synthetic identity fraud, and sophisticated tax scams.
When the compromised identities belong to corporate executives and high-profile employees, the risks extend beyond the individual to the organization. Threat actors target these individuals not only for their premium credit profiles but also to leverage their stolen identities for executive impersonation, corporate espionage, and downstream extortion. Rapid7's telemetry highlights this trend, identifying 476 compromised SSN records for corporate personnel since early 2026, with over 73% targeting top leadership, including C-suite executives and presidents.
These exposures are heavily concentrated among U.S.-headquartered organizations, particularly in high-value sectors like Financials and Industrials. The research delves into the operational mechanics of the underground identity economy, focusing on three dominant SSN marketplaces tracked by Rapid7: Xilo, Bankom, and PeopleFinder. These platforms collectively account for 81.5% of all executive SSN leaks in Rapid7's dataset, with Xilo leading at 40.8%.
Stolen SSNs retain their value due to their permanence. While credentials and payment cards can be invalidated, SSNs serve as a core identity attribute that can be abused for years. When combined with other personally identifiable information (PII), an SSN forms a comprehensive identity profile that can be repeatedly monetized across the criminal ecosystem for various fraudulent activities, including opening fake accounts, bypassing verification processes, and enabling targeted social engineering attacks.
For corporate leaders, exposed identity data, when combined with publicly available information, can significantly enhance the credibility of phishing, business email compromise (BEC), and executive impersonation attacks. This enriched data allows threat actors to target both the individual and the organization they represent, turning personal data into a corporate security risk.
The underground economy treats identity records as searchable, reusable inventory, demonstrating a mature and accessible ecosystem. Marketplaces like Xilo, Bankom, and PeopleFinder act as downstream clearinghouses, sourcing their data from a multi-tiered supply chain. This supply chain includes massive institutional network breaches of data aggregators, healthcare systems, and financial providers, where wholesale databases are sold and then parsed into searchable storefronts.
In addition to large-scale breaches, infostealer malware and targeted phishing campaigns contribute to the data pool. Infostealers scrape highly contextual local data from unmanaged personal devices, such as saved browser forms and sensitive documents like tax returns. Marketplace administrators parse these logs to create fresh, high-value identity profiles that enable buyers to target specific corporate leaders with greater precision.
Rapid7's analysis of these marketplaces underscores the critical need for proactive dark web monitoring. By identifying and mitigating upstream identity exposure before it can be weaponized, organizations can better protect their executives and their own sensitive data from these persistent and evolving threats.