SSNs of Corporate Execs Selling for 25¢ Each on Dark Web

New intelligence reveals U.S. corporate executives’ Social Security Numbers (SSNs) are being sold on the dark web for as little as 25¢ each. The information comes from Rapid7 and highlights a troubling trend in executive identity theft that exposes SSNs tied to high-ranking individuals to long-term criminal abuses.

Scope of the Exposure

Between January and mid-2026, analysts documented 476 different SSN leaks connected to 395 corporate personnel. Nearly three-quarters of those exposed belong to senior leadership: 44.6% are C-suite executives, and another 28.6% are presidents of companies. These leaks almost wholly involve U.S. companies—with 95.6% of incidents coming from organizations headquartered in the United States. The financial sector is the hardest hit (just over 25% of breaches), followed by industrials at roughly 17%.

How These Numbers are Traded

Rapid7’s investigation identified three dark-web marketplaces as primary hubs where compromised SSNs are sold: Xilo, Bankomat, and PeopleFinder. Xilo, active since March 2025, lists records at 25¢ each. For an extra 50¢, it offers a reverse‐lookup tool that provides phone numbers and contact data. Bankomat, operational since 2022, charges about $4 per record but packages SSNs alongside credit card data, CVVs, and other payment credentials. PeopleFinder, evolving from the previously law-enforcement-shut SSNDOB, sells lookups at $1.50 each and draws on a legacy database of more than 24 million U.S. personal identity records.

None of these sites tend to create the data themselves. Most data comes from bulk breaches of data aggregators, healthcare providers, and financial institutions. Recently compromised profiles are often gathered via phishing or infostealer malware, which target executive-level individuals directly and steal documents like personal tax returns.

Why SSNs Are So Valuable—and Dangerous

Unlike credit cards or passwords, which can be changed or revoked, a Social Security Number is fixed for life. That makes it especially attractive to criminals, who can use SSNs—and associated personal identifiers—to facilitate synthetic identity fraud, financial scams, tax deception, or executive impersonation. In cases of business email compromise, enriched profile data makes fraudulent requests more convincing.

Preventative Measures Companies Should Take

Rapid7 urges organizations to treat executive SSN exposure not as isolated events, but as persistent threats requiring continuous monitoring. This involves:

  • Watching the dark web for executive names and unique identifiers to detect leaks promptly.
  • Deploying takedown or purchase strategies to remove stolen records before they spread.
  • Minimizing executives’ public digital footprint and using out-of-band verification for sensitive communications.
  • Training C-suite execs and their assistants to recognize impersonation and phishing tactics.

Once an executive’s SSN is leaked, the damage is permanent. The only way to limit risk is fast detection and an organized, layered defense strategy.

Why This Matters Now

The accessibility of executive SSNs at such low prices signals a dangerous normalization of identity theft, especially at the top levels of business. SSNs are being traded like commodities: low entry cost, high potential harm. As dark-web marketplaces become more sophisticated, executives—and the organizations they lead—are increasingly vulnerable to attacks that go beyond financial fraud and into operational and reputational risk.