Isometric diagram of breached databases feeding dark web identity marketplaces selling executive SSN records

Three dark web marketplaces, Xilo, Bankomat (tracked as Bankom in alert data), and PeopleFinder, account for 81.5% of the executive Social Security number exposures Rapid7 identified in its 2026 telemetry. These are storefronts, not data dumps. They sell searchable identity records on named individuals, and a Social Security number costs less than a cup of coffee. Original reporting for this article comes from Rapid7.

What separates this from a traditional credential leak matters for how you assess the risk. A stolen password database is raw material that a buyer has to parse, sort, and correlate. On Xilo, a buyer types in a name, a state, and a year of birth, and gets back results showing the person's full name, physical address, and date of birth before paying anything. The SSN is unlocked after purchase, at a fixed $0.25 per record.

Bankomat charges $4 per SSN record and also sells stolen payment card details at roughly $10, with card validation services (Viper and 4chk) built in so buyers can check whether a card is still live. PeopleFinder sits between the two at $1.50 per lookup, running on the legacy database of more than 24 million compromised U.S. PII records inherited from the SSNDOB Marketplace that law enforcement seized in June 2022.

Since the beginning of 2026, Rapid7 telemetry identified 476 instances of compromised SSN records across 395 unique corporate personnel, with over 73% belonging to top-level leadership.

Executives are priced the same as anyone else, which is the point. The value is not in the record itself but in who it belongs to. When an attacker combines a CFO's SSN and date of birth with the biography on your corporate website and the details in your regulatory filings, the resulting profile makes impersonation attempts against your finance team considerably harder to dismiss.

Free search on Bankomat and PeopleFinder means a threat actor can confirm they have the right executive before spending a single dollar.

How Data Broker Aggregation Feeds the Identity Markets

The marketplaces sit at the end of a supply chain, not the start of one. The bulk of their inventory comes from large-scale institutional breaches, where operators compromise data aggregators, healthcare systems, and financial providers, then sell the resulting SQL databases in bulk on deep-web forums. Marketplace administrators buy those dumps, parse them into normalized fields, and load them into a searchable storefront.

The Identity Theft Resource Center reports that billions of individual records are exposed annually through mega-breaches, which accounts for the vast majority of what ends up online. For your organization, that means an executive's Social Security number usually enters this economy through a third party they never transacted with directly, and no control you own would have prevented it.

The second supply tier produces fresher, more targeted material. Infostealer malware and targeted phishing scrape highly contextual local data: saved browser form entries and PDF documents such as tax returns or corporate onboarding paperwork sitting on unmanaged personal devices. This maps to ATT&CK T1555.003 (credentials from web browsers) and T1005 (data from local system). Once administrators parse those logs, the output is a current identity profile on a specific named leader, which is what makes executive-level targeting practical.

Correlation is where the raw data becomes a usable product. Bankomat requires a first and last name plus a second identifier such as state, city, ZIP code, or date of birth, and the search itself is free. PeopleFinder allows free lookups by name, date of birth, or physical address. Buyers confirm they have the right person, including matching a physical address to a known residence, before spending anything.

Xilo goes further with a reverse lookup that accepts an SSN or a phone number and returns additional PII including full name and phone number, priced at $0.50 per lookup. Enrichment therefore costs twice what a base record costs, which tells you the operators consider a completed profile more valuable than a bare number. The pivot direction matters: a buyer holding only a phone number from an unrelated leak can resolve it back to a named individual.

Payment mechanics favor pre-funded balances over escrow. Xilo accepts Bitcoin, Litecoin, Monero, Ether, and Tether, with a minimum deposit of $1 and bonuses on deposits above $100 to push users toward larger balances. Bankomat and PeopleFinder transact exclusively in Bitcoin. Distribution runs through cybercrime and carding forums including XSS, WWH-Club, Altenens, and Exploit, plus a Telegram channel with more than 500 subscribers used to announce new domains after disruptions.

Rapid7's research does not publish onion addresses, mirror domains, or seller handles, so there are no network IOCs to feed a blocklist from this reporting. The observable artifacts it does name are code-level and operational:

  • PeopleFinder mirror login pages retain the original ssndob title text and logo in the front-end source
  • Bankomat integrates the Viper and 4chk card validation services, also seen at Findsome and UltimateShop
  • Clear-web-sounding domain naming is used deliberately to reduce buyer friction

The field set on sale (name, date of birth, current and prior addresses, phone number, SSN) is the same set that help desks, carriers, and account-recovery workflows use to verify a caller. Combined with regulatory filings and corporate biographies, it supports identity verification bypass, synthetic identity creation, fraudulent tax and benefit claims, executive impersonation (T1656), and BEC pretexting built on details the target assumes are private.

Business Consequences of Executive Identity Exposure

Rapid7's 2026 telemetry counted 476 compromised Social Security number records tied to 395 unique individuals, and 176 of those people sat in C-suite roles such as CEO, CFO, COO, CTO and CIO. Another 113 held President, SVP, EVP or regional vice president titles. The people named in these listings are the same people who approve payments, sign filings, and authorize account changes at your company.

The first-order harm lands on the individual. An SSN paired with a date of birth and a current home address supports opening lines of credit, filing fraudulent tax returns, and building synthetic identities that blend real and invented details. Your executive spends months disputing accounts they never opened, and that work happens during business hours.

The second-order harm lands on you. A record that already contains a verified full name, birth date, and address history removes the guesswork from impersonation. Fraud attempts against your finance and HR teams stop looking like generic phishing and start looking like a message from someone who knows their own details better than your staff does.

That accuracy shows up in a few predictable places:

  • Wire fraud and business email compromise, where a request to move funds carries enough personal corroboration to survive a callback that only checks identity questions.
  • Payroll diversion, where an attacker contacts HR posing as an executive and changes direct deposit details ahead of a pay run.
  • Account recovery bypass on corporate SaaS, where help desks and self-service reset flows use date of birth, home address, or the last four digits of an SSN as identity proof.
  • Targeted spear-phishing of assistants and controllers, since executive assistants and departmental managers appear in the same dataset at 13.9% of unique targets.

Sector concentration matters for how you weigh this. Financials accounted for more than a quarter of affected organizations and Industrials for 17%. If you operate in either, your exposure includes partner and supply chain relationships where a convincing impersonation of your leadership can be used against a customer or vendor rather than against you directly.

There is a duty-of-care dimension that boards tend to underestimate. The exposed data is personal data belonging to your employees, and where it originated from payroll, benefits, or onboarding paperwork held by your organization or a third-party processor, privacy obligations and breach notification questions follow. Legal, partner and advisory roles made up 8.4% of unique targets, and board members and governance officials another 4.6%, which pulls the issue into fiduciary territory.

If an impersonation succeeds against a client or counterparty, you carry the reputational and litigation consequences alongside the loss. Counterparties who wired funds on the strength of a fake instruction from your CFO will ask what you knew about the exposure and when. That question is easier to answer when someone at your firm has been tracking it.

Physical safety deserves separate attention. These listings display current and historical home addresses before any purchase is made, and 95.6% of the affected organizations were headquartered in the United States. For an executive facing activist attention, litigation, or a contentious labor dispute, a searchable home address in a criminal marketplace is a personal security concern for their household, not only a fraud concern for the company.

How exposed executive identity records are abused
1
Executive records exposed
Compromised listings pair Social Security numbers with named individuals holding CEO, CFO, COO, CTO, CIO, President, SVP and EVP titles. SSN + DOB + home address
2
First-order identity fraud
The record supports opening lines of credit, filing fraudulent tax returns, and building synthetic identities that blend real and invented details. Medium
3
Corroborated impersonation
Verified full name, birth date and address history remove the guesswork from posing as the executive, so contact attempts no longer read as generic phishing. High
4
Finance and HR targeting
Business email compromise requests survive callbacks that only ask identity questions, and payroll diversion changes direct deposit details ahead of a pay run. Assistants and controllers receive matching spear-phishing. High
5
Account recovery bypass
Help desks and self-service reset flows on corporate SaaS accept date of birth, home address or trailing SSN digits as identity proof, extending reach into partner and supply chain relationships. High

Detection and Response Actions for Executive Identity Fraud

Start with credit freezes. If dark web monitoring names one of your executives in an SSN listing, place freezes at Equifax, Experian, and TransUnion for that individual and for their spouse and adult children, since synthetic identity fraud frequently pivots to family members who share an address. A freeze blocks new account opening outright, and it is the only control that directly reduces the value of a number nobody can reset. Assign this to your executive protection lead or, in smaller firms, the CFO's office, with the alert itself as the trigger.

Within the same 48 hours, call the mobile carrier and set a port-out PIN plus an account change lock on every executive line. The free preview data these listings expose (full name, date of birth, current and prior addresses) is exactly what a carrier representative asks to verify a SIM transfer. Once an attacker controls the number, SMS-based resets on banking, brokerage, and corporate accounts follow.

Then strip phone-based and knowledge-based recovery from executive accounts entirely. Security questions about your first street or year of birth are answerable from a free search result, and SMS recovery is only as strong as the carrier's call center. Move recovery to an administrator-controlled process instead.

Brief your IT help desk the same week. Give the desk a written identity verification standard for password and MFA resets on executive accounts, requiring a video callback or manager confirmation rather than personal details a caller can recite. Help desk impersonation is the shortest path from a purchased identity record to a corporate account, and your desk staff are the control point. In environments Capstone manages, Adlumin ITDR monitors authentication behavior on those accounts, flagging new MFA enrollments, unusual logon locations, and reset activity that does not match the executive's established pattern.

Over the next quarter, work through the following:

  • File opt-out and deletion requests with people-search and data broker sites for each executive, owned by legal or HR, and re-run them quarterly because brokers repopulate from fresh sources.
  • Enroll executives in identity and credit monitoring that covers new inquiries, address changes, and benefit claims filed in their name.
  • Configure marketplace monitoring with executive names, known locations, titles, and prior employers so a new listing triggers an alert rather than being discovered after a fraudulent account opens.
  • Move the executive tier to hardware-key MFA (FIDO2 security keys), which removes the phone from the authentication path completely.
  • Require out-of-band callback verification for every payment instruction, banking detail change, and vendor bank update above a defined threshold, using a number from your own vendor master file.

Longer term, build an executive digital protection program with a named owner, a review cadence, and coverage that extends to board members and executive assistants, who appear in this exposure data alongside the C-suite. Run a tabletop that walks your finance team through a CEO impersonation and wire fraud scenario where the attacker already knows the CEO's date of birth and home address, and measure whether the callback rule actually holds under pressure from a senior name.

Finally, negotiate broker deletion at scale through a contracted service rather than filing individually, and route dark web alerts into your SOC intake queue with a defined triage playbook. That gives every future listing a documented owner and a response clock instead of an email that sits in someone's inbox.

What Security Leaders Should Prioritise

The takeaway from this research is that your executives' personal identity data is now inventory. It sits in a searchable storefront with a fixed price, a free preview of name, date of birth and address, and a payment page. That changes the question you should be asking. It is no longer whether an executive's data will be exposed, but what an attacker can do with a verified identity profile once they have paid for it.

The answer usually runs through your people, not your perimeter. A buyer who holds a CFO's date of birth, home address and Social Security number is not trying to breach your firewall. They are calling your service desk, resetting a password, requesting a device enrolment, or emailing accounts payable with enough personal detail to sound legitimate. Every control you have built around network access assumes the person on the phone is who they claim to be, and purchased identity data is designed to satisfy exactly that assumption.

So the priority for security leaders is the verification step, in two places: account recovery and help desk identity checks for the executive tier, and the approval path for payments and account changes. If knowledge of personal details is what unlocks a password reset or a wire authorisation in your organisation, then the data these marketplaces sell is functionally an access credential. Hardening that one pivot point does more to limit the damage than any amount of additional monitoring at the network edge, because it is where a purchased record stops being a personal fraud problem and becomes a corporate one.

In This Article

Top hits