Rapid7 identified an active identity-as-a-service market in which cybercriminals sell compromised Social Security number (SSN) records tied to corporate executives for as little as $0.25. Since early 2026, researchers tracked 476 exposed SSN records associated with 395 unique corporate personnel, with C-suite leaders and company presidents accounting for most of the affected individuals.
Three services—Xilo, Bankomat, and PeopleFinder—accounted for 81.5% of identified executive SSN leaks, functioning as clearinghouses for data originating from aggregators, healthcare and financial-sector breaches, infostealer infections, and phishing. The records can enable synthetic-identity and tax fraud, executive impersonation, and business email compromise; organizations should continuously monitor executive identity exposure, prepare response processes, and apply stronger verification controls for high-risk financial and identity-related requests.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Since early 2026, Rapid7 tracked 476 compromised SSN records associated with 395 corporate personnel. C-suite executives and corporate presidents comprised most affected profiles, and Xilo, Bankomat, and PeopleFinder accounted for 81.5% of identified leaks.
Xilo began operating in March 2025 as a Tor hidden service with clear-web mirrors, offering SSN records at a flat price of $0.25 and reverse lookups for $0.50.
PeopleFinder began operating as a direct successor to SSNDOB Marketplace, which had been seized in June 2022. It reportedly reused SSNDOB's database of more than 24 million U.S. personally identifiable-information records and retained SSNDOB branding in its front-end source code.
Bankomat began operating as a marketplace for stolen payment-card data, CVVs, validation tools, and SSN records. It charges $4 per SSN record.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecybersecuritynews.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.