HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Dark Web Marketplace Sells Fullz for Under $1, Exposing 8.4 B Records Across 7,500 Data Sets

Malwarebytes identified over 7,500 compromised data sets—more than 8.4 billion records—being sold as “fullz” for less than a coffee on the dark web. The scale highlights gaps in PII protection and underscores the need for SOC 2‑aligned privacy controls and continuous audit evidence.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Dark Web Marketplace Sells Full z for Under $1, Exposing 8.4 B Records Across 7,500 Data Sets

What Happened — Malwarebytes researchers spent 48 hours on dark‑web forums and discovered subscription‑style malware kits, social‑engineering guides, and “fullz” packages (full name, SSN, DOB, address, etc.). In the first half of 2026 they identified more than 7,500 compromised data sets, representing over 8.4 billion individual records being traded for as little as $0.95 each.

Why It Matters for Compliance & Audit Readiness

  • The volume of “fullz” sales demonstrates a systemic failure of data‑handling controls that SOC 2 CC6 (Confidentiality) and privacy‑specific criteria (e.g., GDPR Art. 5, CCPA § 1798.100) are designed to mitigate.
  • Continuous monitoring of data‑access logs and automated classification of PII can provide the audit evidence needed to prove “need‑to‑know” restrictions and timely breach‑notification readiness.
  • Verisq’s CookiePLUS Privacy capability supplies a single source of truth for consent, DSAR handling, and cross‑border data‑transfer documentation—critical artifacts for a defensible SOC 2 privacy audit.

Who Is Affected – Financial services, healthcare, retail, and any organization that stores personally identifiable information (PII) on‑premise or in the cloud.

Recommended Actions

  • Map all PII repositories to SOC 2 CC6 and privacy‑law controls; tag data with sensitivity levels.
  • Deploy continuous data‑discovery tools to detect unsanctioned storage and generate real‑time evidence for audit trails.
  • Review and update consent‑management and DSAR processes; ensure they are documented in a verifiable, searchable repository.

Technical Notes – The dark‑web listings include malware‑as‑a‑service kits (e.g., info‑stealers) and social‑engineering playbooks. No single CVE is cited; the threat vector is primarily credential harvesting via phishing and malicious payloads. Source: Malwarebytes Labs – Lock and Code S07E15

📰 Original Source
https://www.malwarebytes.com/blog/podcast/2026/07/whats-your-data-worth-on-the-dark-web-lock-and-code-s07e15

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →