Dark Web Marketplace Sells Full z for Under $1, Exposing 8.4 B Records Across 7,500 Data Sets
What Happened — Malwarebytes researchers spent 48 hours on dark‑web forums and discovered subscription‑style malware kits, social‑engineering guides, and “fullz” packages (full name, SSN, DOB, address, etc.). In the first half of 2026 they identified more than 7,500 compromised data sets, representing over 8.4 billion individual records being traded for as little as $0.95 each.
Why It Matters for Compliance & Audit Readiness
- The volume of “fullz” sales demonstrates a systemic failure of data‑handling controls that SOC 2 CC6 (Confidentiality) and privacy‑specific criteria (e.g., GDPR Art. 5, CCPA § 1798.100) are designed to mitigate.
- Continuous monitoring of data‑access logs and automated classification of PII can provide the audit evidence needed to prove “need‑to‑know” restrictions and timely breach‑notification readiness.
- Verisq’s CookiePLUS Privacy capability supplies a single source of truth for consent, DSAR handling, and cross‑border data‑transfer documentation—critical artifacts for a defensible SOC 2 privacy audit.
Who Is Affected – Financial services, healthcare, retail, and any organization that stores personally identifiable information (PII) on‑premise or in the cloud.
Recommended Actions
- Map all PII repositories to SOC 2 CC6 and privacy‑law controls; tag data with sensitivity levels.
- Deploy continuous data‑discovery tools to detect unsanctioned storage and generate real‑time evidence for audit trails.
- Review and update consent‑management and DSAR processes; ensure they are documented in a verifiable, searchable repository.
Technical Notes – The dark‑web listings include malware‑as‑a‑service kits (e.g., info‑stealers) and social‑engineering playbooks. No single CVE is cited; the threat vector is primarily credential harvesting via phishing and malicious payloads. Source: Malwarebytes Labs – Lock and Code S07E15