Dark web shops sell executives' SSNs for 25 cents

On a marketplace called Xilo, a US Social Security number costs 25 cents. You can search by name, by state, by country and by year of birth. The results show you the person's full name, home address and date of birth before you pay anything at all. The nine digits themselves are what you are buying, and they arrive after checkout.

Rapid7 has been counting whose numbers turn up there, and the answer is not the general public. Since the start of 2026, the firm's alert telemetry has recorded 476 instances of compromised SSN records covering 395 unique corporate personnel, and more than 73% of those exposures involved top-level leadership. C-suite executives made up 44.6% of the affected profiles and presidents another 28.6%. Almost all of it, 95.6%, came from organizations headquartered in the United States, concentrated in financial services (over 25%) and industrials (17%).

Alexandra Blia of Rapid7 set out the findings in the original research, which tracks three marketplaces, Xilo, Bankom and PeopleFinder, that between them account for 81.5% of the executive SSN exposures in the dataset. Xilo alone accounts for 40.8%.

Why a stolen SSN never expires

Most stolen data has a shelf life. Passwords get reset, cards get cancelled, session tokens time out, and the criminal's whole problem is moving faster than the victim's bank. A Social Security number has no equivalent kill switch. It is a permanent identity attribute, and once it is out it stays useful for years after the breach that leaked it is forgotten.

Combined with a name, date of birth, address, phone number and employment history, it becomes what Rapid7 calls a comprehensive identity profile: a reusable asset sold repeatedly to different buyers. Rapid7 lists the uses as opening fraudulent accounts, building synthetic identities, defeating verification checks, filing bogus tax claims, and running targeted social engineering.

That last one is why this is a corporate problem and not only a personal one. Executive biographies, regulatory filings and social media are all public. Bolt a verified date of birth and home address onto them and a phishing or business email compromise attempt stops looking like a guess. The individual is the doorway; the company is the target.

The storefront looks like a search engine

Xilo has been running since at least March 2025 as a Tor hidden service with clear web mirrors for accessibility and resilience. Pricing is flat at $0.25 per record. Records advertised as including phone numbers cost the same as plain ones.

The more telling feature is reverse lookup. For $0.50, twice the price of a record, you can submit an SSN or a phone number and get back additional personal information including the name and phone number attached to it. Enrichment is worth more than raw supply, which tells you the buyers already hold partial data and are assembling profiles rather than shopping blind. A Telegram channel with more than 500 subscribers announces new domains when the old ones go down, the same continuity practice a legitimate service would run.

Nobody on these sites stole anything

The marketplaces are clearinghouses, not sources. Rapid7 traces the inventory upstream to two supplies. Most of it comes from large institutional breaches, where data aggregators, healthcare systems and financial providers are compromised wholesale, the databases are sold on deep-web forums, and a marketplace operator parses them into a searchable storefront. Rapid7 cites Identity Theft Resource Center telemetry showing billions of records exposed annually through such mega-breaches. Corporate breaches that spill SSNs and bank details together feed straight into this pipeline.

The second supply is smaller, fresher and better targeted. Infostealer malware scrapes highly contextual local data from saved browser forms and from documents sitting on unmanaged personal machines, tax returns and onboarding paperwork among them. The commodity stealers that arrive through fake fix prompts and cracked software are not usually thought of as executive-targeting tools, but a stealer log from a chief executive's home laptop is exactly what produces a premium listing.

You cannot reissue an executive

Rapid7's own recommendation is proactive dark web monitoring, on the logic that the only intervention available runs upstream: you find out an identity profile is on sale before somebody uses it, because you cannot invalidate the number afterwards. The United States profile carries more on the exposure picture there. The uncomfortable arithmetic is that a complete executive identity is being sold for a quarter, over and over, to whoever wants it next.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions