Security1 distinct publisher3 min readPublished
C-suite officers and presidents make up more than 73% of the 395 people in Rapid7's telemetry, and a Social Security number cannot be cancelled, so the fix has to happen wherever an SSN still counts as proof.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
An SSN on its own is a nine-digit string with no directory attached. What the markets sell is the assembled record: the number plus name, date of birth, address, phone and employment history, which Rapid7 calls the foundation of a full identity profile [9]. Rapid7 describes those records as searchable, reusable inventory rather than one-time goods, monetised repeatedly by different buyers [10]. The abuse paths it lists are fraudulent account opening, synthetic identities, identity verification bypass, false tax and benefit claims, and support for targeted social engineering [11].
For an executive, the public half of that profile is already filed. Regulatory documents, corporate biographies and social media supply the narrative detail, and the purchased half supplies the attributes a verification script treats as proof [12]. Rapid7's argument is that the combination raises the credibility of phishing, business email compromise and executive impersonation against the employer as well as the individual [13]. That is where the cost lands. A damaged personal credit file is the executive's problem; a wire approved on a convincing impersonation is the company's.
The percentages hide two figures worth doing by hand. 476 records across 395 people works out to 1.21 records per person, so at least 81 of those records duplicate someone already counted [14]. And 44.6% C-suite against 28.6% presidents, applied to 395 profiles, is roughly 176 and 113 people [20], a targeted slice rather than a volume crime, set against the more than one million identity theft reports the FTC logs annually [7].
The denominator is missing. These are alerts from Rapid7's own monitoring telemetry [1], so 476 is a count of what one vendor saw across the organisations it watches, with no population figure to divide it by. The naming wobbles as well: the second marketplace appears as Bankom in the share breakdown and as Bankomat further down the same post [17]. Minor, except that the name is the identifier a buyer or an investigator searches on.
Rapid7's proposed control is proactive dark web monitoring, catching exposure before it is weaponised [18]. That shortens time to know, but it does not shorten the life of the record, because an SSN cannot be deactivated the way a payment card or a session token can [6]. The durable control sits with whoever accepts an SSN, a date of birth and an address as evidence of who is calling: the helpdesk resetting MFA for a president, the finance team taking instructions from a CFO whose personal details all check out. Rapid7 also notes actors go after these people for their credit profiles and for corporate espionage and downstream extortion [8]. The credit profile is the part that gets monitored. The other two are the part that gets budgeted last.
Ranked by verification strength, evidence, and original report placement.
Rapid7 alert telemetry identified 476 instances of compromised SSN records across 395 unique corporate personnel since early 2026.
Over 73% of the exposures directly targeted top-level leadership, with C-suite executives comprising 44.6% of affected profiles and Presidents another 28.6%.
Three marketplaces tracked by Rapid7 - Xilo, Bankom and PeopleFinder - together account for 81.5% of all executive SSN leaks in the dataset, led by Xilo at 40.8%, Bankom at 21.8% and PeopleFinder at 18.9%.
U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year.
Rapid7 positions proactive dark web monitoring as a way to mitigate upstream identity exposure before it is weaponised.
95.6% of the leaks stemmed from U.S.-headquartered organisations.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Three infostealer families in one two-month window, and the revived one had the volume1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
build
AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild1 distinct publisher
security
SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's unaudited telemetry, internally inconsistent
Every quantitative claim comes from a single Rapid7 blog post drawing on its own alert telemetry, with no disclosed methodology, monitoring denominator, sample frame or third-party corroboration. The figures are specific and internally coherent in arithmetic (44.6% + 28.6% = 73.2%; 476/395 = 1.21; 81.5% leaves an 18.5% residual), which supports the counting, but the post states two different observation windows for the same dataset and two names for the same marketplace, and the mechanism claims about attacker motives and profile enrichment are asserted without cases or measurement.
No adoption signal in supplied sources
The cluster contains no release, deployment, benchmark, pricing, licensing or usage-disclosure event. The post reports observed criminal marketplace listings and recommends a monitoring practice, but supplies nothing about who has adopted any product, control or standard in response, so adoption cannot be scored without inference.
Escalating framing ahead of disclosed method
The framing — an 'Identity-as-a-Service' underground economy, executive impersonation, corporate espionage and downstream extortion — runs ahead of what is actually shown: a count of 476 listings across 395 people from one vendor's unaudited telemetry, with no observed fraud, impersonation or extortion outcome tied to those records, and an unresolved discrepancy about the period the count covers. The underlying facts about SSN permanence are real and understated by most coverage, which keeps the gap moderate rather than large.
Vendor research recommending the vendor's own product category
The publisher is a commercial security vendor and the sole source. The post's stated purpose is to highlight how proactive dark web monitoring mitigates upstream identity exposure — the exact service category Rapid7 sells — and the supporting data is Rapid7's own non-reproducible telemetry. No commercial-interest disclosure appears in the supplied text, and cheaper non-product mitigations (credit freezes, identity PINs, removing SSN as a verification factor) are absent.
Directionally credible, quantitatively soft
Confidence is limited by the single-source, single-publisher structure, the vendor's commercial interest in the recommended remedy, and the post's own internal inconsistencies. The qualitative core — SSNs cannot be revoked, executive records are traded as reusable inventory, and enriched profiles strengthen BEC — is credible and consistent with the cited FTC baseline; the precise percentages and counts should be treated as vendor-reported and unverified.