Skip to main content
  1. Home
  2. Computing
  3. News

This hacker site sold 24 million people’s data — until now

Add as a preferred source on Google

An underground illegal online marketplace that contained and sold sensitive information pertaining to individuals based out of the U.S. has been shut down.

SSNDOB, which saw people’s names, Social Security numbers, and dates of birth being collected and sold, has been successfully taken offline due to a joint operation from U.S. authorities and their counterparts in Cyprus.

A social security card in shrink-wrap paper.
Mike Kemp/Getty Images

As reported by Bleeping Computer, the marketplace itself wasn’t your run-of-the-mill operation — around 24 million individuals from the U.S. alone were affected by its illicit activity.

Recommended Videos

Due to the large scope of the operation, ​​three governmental departments collaborated in shutting down SSNDOB. The FBI, the Internal Revenue Service, and the Department of Justice were all involved.

Additional assistance from Cyprus police was also a factor in the marketplace ceasing its operations.

The Department of Justice’s press release stated that more than $19 million in “sales revenue” was accumulated by the website’s owners.

A total of four domains that provided hosting services for the entire SSNDOB marketplace were seized, including “ssndob.ws,” “ssndob.vip,” “ssndob.club,” and “blackjob.biz.”

As for how the activities of the SSNDOB marketplace managed to go unchecked since 2015, Bleeping Computer highlights how the websites effectively evaded DDoS attacks and actions from law enforcement by supplying various mirror sites.

This practice is common amongst illegal websites such as torrent services and the like. The method makes it nearly impossible to target the core operation behind the websites as there’s always a new domain that can be accessed.

$0.50 to buy and use someone’s identity

The SSNDOB website landing page.
Image used with permission by copyright holder

As a result, SSNDOB saw threat actors being able to buy “social security numbers, dates of birth, and full info of people” predominantly through Bitcoin, which is largely an unregulated currency that has become commonplace amongst cybercriminals.

Personal information of U.S.-based residents was up for grabs for $0.50 in some cases. Dates of birth for individuals residing in the United Kingdom were also sold on the website.

According to cybersecurity firm Advanced Intel, which spoke with Bleeping Computer on the matter, a large portion of the stolen data was acquired via infiltrating healthcare and hospital systems and was subsequently utilized by cybercriminals to carry out financial fraud.

“SSNDOB was one of the largest crime shops offering a collection of personally identifiable information for fraudsters and played an integral part in fraud schemes The majority of the customers used the shop data for various types of scams from tax to bank fraud,” AdvIntel CEO Vitali Kremez told BleepingComputer.

“According to the few AdvIntel breach investigations, the criminals behind the shop specifically leveraged healthcare and hospital breach databases to source the supply of personal information for the fraudsters.”

Elsewhere, since April 2015, blockchain analysis company Chainalysis detailed how they discovered $22 million in Bitcoin transactions going directly to SSNDOB. Certain transfers equalled $100,000 in Bitcoin; Bleeping Computer aptly points out that this tidbit indicates how cybercriminals bought data in bulk.

Zak Islam
Former Contributor
Zak covers the latest news in the technology world, particularly the computing field. A fan of anything pertaining to tech…
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more
OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery
OpenAI

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet. This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking.

The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident.

Read more