From data breaches to account takeovers: The business risk of fullz
How Stolen Identity Packages Fuel Modern Cyberattacks in 2026
Key Takeaways
- Fullz are complete stolen identity packages that help attackers conduct fraud, account takeover, and social engineering attacks.
- Infostealer malware has transformed the fullz economy by supplying fresh credentials, browser cookies, and authentication data at scale.
- Organizations should adopt zero trust principles, phishing-resistant MFA, and strong identity security controls to reduce the risk posed by stolen identities and credentials.
“Fullz” is a slang term used by cybercriminals trading in stolen data. Short for "full information," fullz are bundled packages of personally identifiable information (PII) that can include names, addresses, dates of birth, Social Security numbers, driver's license details, financial account information, phone numbers, and email addresses. Brokers piece together victim information from multiple sources and offer attackers a complete identity profile ready for fraud and abuse.
These packages are not new; fullz datasets have been a staple of underground cybercrime marketplaces for years. What’s new and notable is how infostealer malware logs have increased the value and usefulness of fullz. The PII that we have always seen in these datasets is now complemented with stolen credentials, browser cookies, device information, and other types of data. Fullz now enables everything from identity theft and financial fraud to business email compromise (BEC), account takeover, and ransomware attacks.
Partial screenshot of forum post advertising fullz dataset, via DarkWebInformer
The offer shown in the screenshot above lists several types of information and even provides an API for automated access to the data. Companies are no longer defending against isolated data breaches. They are defending against an industrialized ecosystem that continuously harvests, aggregates, and sells identity data.
Multi-factor authentication alone isn't enough
Multi-factor authentication (MFA) is one of the most important security controls an organization can deploy. Unfortunately, threat actors are finding ways to bypass MFA through social engineering, adversary-in-the-middle phishing, browser credential theft, OAuth abuse and more. In many cases, attackers do not need a password if they can obtain a valid authenticated session from an infected endpoint. This reality has pushed many organizations toward more comprehensive identity-centric security strategies.
Zero trust for the post-breach era
The assumption that user credentials will eventually be compromised has become a core principle of modern cybersecurity. A zero-trust approach helps reduce risk by continuously validating:
- User identity
- Device security posture
- Location
- Application access
- Behavioral patterns
Instead of automatically trusting a user after login, zero trust requires ongoing verification before granting access to corporate resources. This significantly limits the damage attackers can cause with stolen credentials or fullz data because access decisions are based on multiple factors, not just a username and password.
The dark-web market for stolen data is thriving, creating a new reality for cybersecurity professionals. The key to success is to remain adaptable, and to respond strategically to an ever-changing threat landscape.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit