VYPR
breachPublished Aug 27, 2026· 1 source

Executive Social Security Numbers Sold for Pennies on Dark Web, Rapid7 Reports

Corporate executives' Social Security numbers are being sold on dark web marketplaces for as little as 25 cents, according to new threat intelligence from Rapid7.

Corporate executives' most sensitive identity data, including their Social Security numbers (SSNs), is being peddled on dark web marketplaces for a mere quarter, a recent report from Rapid7 reveals. Unlike credit card numbers, which can be quickly canceled, compromised SSNs represent a permanent liability for victims, a fact cybercriminals are actively exploiting to fuel a burgeoning underground economy centered on executive identity theft. Since the beginning of 2026, Rapid7 has documented 476 instances of compromised SSN records linked to 395 distinct corporate personnel, with a significant skew towards senior leadership. C-suite executives constitute 44.6% of affected profiles, and presidents represent an additional 28.6%.

The vast majority of these leaks, 95.6%, originate from U.S.-headquartered companies, with the financial sector being the most heavily impacted, accounting for over 25% of exposed SSNs, followed by the industrials sector at 17%. Rapid7's analysis identified three primary platforms facilitating these sales: Xilo, Bankomat, and PeopleFinder, which collectively account for 81.5% of all identified executive SSN leaks. Xilo, operating as a Tor hidden service with clear-web mirrors since March 2025, offers SSN records for a flat 25 cents, with an optional $0.50 reverse-lookup feature to enrich profiles with additional contact details. Bankomat, active since 2022, charges $4 per record and functions as a comprehensive carding marketplace, bundling stolen payment card data and validation tools alongside identity records. PeopleFinder, a successor to the law-enforcement-seized SSNDOB Marketplace, continues to operate with a legacy database of over 24 million U.S. Personally Identifiable Information (PII) records, charging $1.50 per lookup.

These marketplaces do not generate the compromised data themselves; instead, they act as downstream clearinghouses. They acquire bulk records from large-scale breaches affecting data aggregators, healthcare systems, and financial institutions. Additionally, infostealer malware and sophisticated phishing campaigns provide fresher, more targeted profiles harvested from personal devices and sensitive documents like tax returns. The data's value lies in its permanence; while passwords can be reset and credit cards frozen, an SSN is a fixed identity attribute that retains criminal value indefinitely.

When combined with other PII, a compromised SSN becomes the bedrock for various fraudulent activities. These include synthetic identity fraud, the establishment of fraudulent credit lines, tax scams, and, particularly for high-profile targets, highly convincing executive impersonation and business email compromise (BEC) schemes. When enriched with publicly available biographical details gleaned from corporate filings or social media, a stolen SSN can significantly enhance the credibility of phishing or social engineering attacks aimed at an entire organization.

Rapid7 recommends that organizations treat executive identity exposure as an ongoing risk rather than an isolated incident. Implementing continuous dark web monitoring that tracks executives' names and known identifiers can provide early alerts to leaked records, allowing for timely takedown requests or purchase of listings before they are acquired by other malicious actors. A layered defense strategy should also include minimizing executives' public digital footprints, enforcing out-of-band verification for sensitive financial or administrative requests, and providing targeted training to C-suite members and their executive assistants on recognizing and countering impersonation tactics.

The increasing efficiency and accessibility of underground marketplaces underscore a critical message for security teams: once an executive's SSN is compromised, the clock does not reset. Therefore, the speed of detection and the effectiveness of the response are paramount. Organizations must prioritize robust monitoring and rapid incident response to mitigate the escalating threat of executive identity theft.

Synthesized by Vypr AI