< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

Executive Social Security numbers targeted on dark web marketplaces

Cybercriminals are increasingly targeting high-profile corporate executives on dark web marketplaces to trade stolen Social Security numbers (SSNs). Unlike credit cards, SSNs cannot be easily deactivated, making them highly valuable for synthetic identity fraud, tax scams, and corporate espionage.

Telemetry from Rapid7 indicates that since early 2026, 476 instances of compromised SSN records were identified across 395 unique corporate personnel. Over 73% of these exposures targeted top-level leadership, including C-suite executives and company presidents. The vast majority of these leaks, 95.6%, originated from U.S.-headquartered organizations, particularly within the financial and industrial sectors.

Three primary dark web marketplaces—Xilo, Bankom, and PeopleFinder—account for approximately 81.5% of these executive SSN leaks.

On a broader scale, identity theft remains a significant economic threat. In the United States, fraud losses exceeded $12.7 billion in 2024. Common methods include SIM-swapping attacks and the theft of personal details to commit fraud, which can lead to significant financial loss and long-term credit damage.

Entities

Bankom · Federal Trade Commission · PeopleFinder · Rapid7 · Xilo