Introduction
“Fullz” is underground cybercrime slang for a relatively complete package of stolen personally identifiable information about a real person. The exact contents vary, but the term generally signals that the record contains substantially more than a single payment-card number or isolated password.
U.S. Department of Justice cases have used the term when describing stolen identity packages containing information such as a person’s name, date of birth, Social Security number, bank account number, and bank routing number. In another federal investigation, agents described a “fullz” as a complete set of identifiers including name, date of birth, Social Security number, address, and credit-card number.
This broader collection of information can create more serious risks than card-only theft because it may support account takeover, new-account fraud, tax identity theft, fraudulent applications, social engineering, and other forms of impersonation.
Europol says stolen data is increasingly treated as a commodity in the criminal economy and can be sold, resold, and repackaged for identity theft, extortion, fraud, and other abuse.
This article explains the term from a defensive perspective. It does not provide sources, prices, marketplace names, search methods, purchasing instructions, validation procedures, or guidance for using stolen identity data.
Quick Answer: What Are Fullz?
“Fullz” is criminal slang for a bundle of stolen personal information that is detailed enough to represent a fuller identity profile rather than one isolated credential.
The specific fields vary. Public U.S. law-enforcement cases have described fullz packages containing combinations of names, dates of birth, Social Security numbers, addresses, bank-account information, routing numbers, and payment-card information.
The term is not a formal legal or data-protection category. It is underground terminology, so there is no universal definition requiring the same fields in every record.
The security significance is that combining multiple identity attributes can make impersonation more convincing and can create risks beyond ordinary unauthorized card purchases.
Why the Term Is Written as “Fullz”
The spelling is underground slang derived from the idea of a “full” or comparatively complete identity record.
It should not be interpreted as meaning that every possible piece of information about a person is present.
A criminal seller may use the label loosely, and different marketplaces or groups may mean slightly different things.
For fraud prevention, the important distinction is not the spelling but the increased risk created when several pieces of personal and financial information are bundled together.
Fullz Is Not a Formal Legal Category
Law-enforcement agencies may use the term descriptively when discussing criminal evidence, but consumer-protection law generally focuses on the actual information stolen and the fraudulent conduct that follows.
Identity theft and identity fraud broadly involve wrongfully obtaining and using another person's personal data for fraud or deception.
The U.S. Department of Justice describes identity theft and identity fraud as crimes involving the wrongful obtaining and use of another person's personal data, typically for economic gain.
A victim's response should therefore be based on the data exposed and the misuse observed rather than on whether criminals labeled the record “fullz.”
What Information Can a Fullz Record Contain?
There is no universal checklist.
Public federal cases have described packages containing combinations of a victim's full name, date of birth, Social Security number, address, bank-account number, routing number, and credit-card information.
Other stolen datasets may also include email addresses, phone numbers, usernames, passwords, employment information, or other identity attributes, depending on the original breach.
Not every record contains all of these fields.
From a defensive perspective, the more categories of information that are exposed together, the more varied the potential fraud risks can become.
Fullz vs Stolen Credit Card Data
Stolen credit-card data is primarily a payment-security problem.
A fuller identity record can create both payment risk and identity risk.
A card-only compromise might be addressed largely through issuer monitoring and card replacement.
A record containing a Social Security number, date of birth, address, and account information may require broader measures such as credit freezes, fraud alerts, account security reviews, and identity-theft recovery steps.
This is why consumers should read breach notices carefully and determine exactly which fields were affected.
Fullz vs “Dumps”
The terms refer to different kinds of stolen information.
“Dumps” is historically associated with payment-card magnetic-stripe data or data derived from card-present compromise.
“Fullz” refers more broadly to identity information about an individual.
The two categories can overlap in criminal ecosystems, but they are not interchangeable.
Understanding the distinction helps defenders separate physical-payment compromise from broader identity theft.
Fullz vs Login Credentials
A username and password can enable account takeover without revealing a person's complete identity profile.
A fullz-style identity bundle may contain personal identifiers that can support attempts to impersonate the victim across several organizations.
If a breach exposes both identity data and account credentials, the risks can compound.
Consumers may need to secure existing accounts while also monitoring for new accounts or fraudulent applications opened in their name.
Fullz vs a Complete Identity
The word “fullz” can sound as though criminals possess every detail of a person's identity.
That is not necessarily true.
The package may still be incomplete, outdated, incorrect, duplicated, or mixed with information from another source.
However, incomplete information can still be dangerous if it is sufficient to support convincing impersonation or fraud attempts.
Defensive action should not wait for proof that criminals possess a perfectly complete identity profile.
Where Does Fullz Data Come From?
Stolen identity packages can be assembled from several sources.
Potential origins include major data breaches, phishing, compromised consumer or employee accounts, malware, stolen documents, compromised businesses, or data obtained from multiple breaches and later combined.
Europol says personal and financial data stolen online is sold in the underground economy and can be misused by criminal organizations.
Its 2025 threat reporting says stolen data is now treated as a commodity and is sold, resold, and repackaged.
The person assembling a full identity record may therefore not be the person who originally stole every individual field.
How Separate Breaches Can Be Combined
One breach might expose an email address and password.
Another may expose a date of birth and address.
A third may expose financial information.
Criminal data brokers can combine information from different sources into a more detailed profile.
This is one reason old breaches can remain relevant: information that looks harmless in isolation may become more useful when combined with other stolen datasets.
For businesses, minimizing the amount of identity data retained reduces the material available for future aggregation.
Why Full Identity Packages Are More Dangerous
Fraud risk increases when criminals possess several matching identity attributes.
A single card number can often be invalidated quickly.
A Social Security number, date of birth, historical address, or other identity attribute cannot be replaced as easily.
Combined information can also make social engineering more persuasive because the criminal may already know details that appear to prove legitimacy.
This makes full identity exposure a longer-term security concern than many isolated payment-card compromises.
Identity Fraud vs Identity Theft
The terms are often used together.
DOJ explains identity theft and identity fraud as crimes involving the wrongful obtaining and use of another person's personal data in a fraudulent or deceptive way.
The theft is the acquisition of identity information; fraud refers to the misuse of that information.
A breach can expose identity data without immediate evidence that fraud has occurred.
Consumers should therefore distinguish between exposure and confirmed misuse while still taking preventive steps appropriate to the information involved.
Risk 1: New Credit Accounts
A detailed identity profile can increase the risk of attempts to open new credit accounts in the victim's name.
This is why credit freezes are particularly relevant after exposure of strong identity information such as a Social Security number.
The FTC says a credit freeze restricts access to a consumer's credit file and can make it harder for an identity thief to open new accounts.
Credit freezes are free to place and lift in the United States.
A freeze protects against new-account risk; it does not stop fraud on an existing card or bank account.
Risk 2: Bank and Financial Account Fraud
Identity information may be used in attempts to impersonate a customer or manipulate account-recovery processes.
Banks increasingly use multi-factor authentication, device signals, transaction monitoring, and other controls to reduce this risk.
Consumers should protect email and phone accounts because those channels are often involved in financial-account recovery.
Unexpected password-reset messages, new-device alerts, or account changes should be investigated promptly.
Never assume that a criminal who knows your date of birth or address is actually calling from your bank.
Risk 3: Tax Identity Theft
Stolen identity information can be misused in tax fraud.
In the DOJ case involving stolen “fullz” packages sold by Hieu Minh Ngo, the IRS confirmed that thousands of U.S. citizens whose information had been sold were victimized through fraudulent individual income-tax returns.
That case demonstrates that full identity records can be used for crimes far beyond unauthorized card purchases.
Consumers who encounter signs of tax identity theft should follow IRS and IdentityTheft.gov guidance appropriate to their situation.
Risk 4: Account Takeover
A detailed identity profile can help criminals make account-takeover attempts more convincing.
Security questions based on personal history are weaker when personal information has been widely exposed.
Organizations should avoid relying solely on static biographical facts for authentication.
Consumers should use strong unique passwords and multi-factor authentication on email, financial, cloud, and shopping accounts.
Email accounts deserve special protection because they often control password resets for other services.
Risk 5: Social Engineering
Stolen personal information can make scams more credible.
A criminal who already knows the victim's name, address, date of birth, or account provider can craft a message or call that appears unusually informed.
The fact that a caller knows personal information is not proof that the caller is legitimate.
Verify sensitive requests through an independent official channel.
Do not disclose passwords or one-time authentication codes simply because the caller can recite information about you.
Risk 6: Synthetic Identity Fraud
Stolen real identity elements can sometimes be mixed with invented or altered information to create synthetic identities.
Synthetic identity fraud differs from direct impersonation of one victim because the criminal identity may combine real and fabricated attributes.
Financial institutions use identity verification, consortium intelligence, device analysis, and behavioral monitoring to identify suspicious identity patterns.
Consumers may not immediately see synthetic misuse if only one element of their identity was incorporated.
This reinforces the value of regular credit-report monitoring after serious identity-data exposure.
Risk 7: Government Benefits or Employment Fraud
A stolen Social Security number can create risks beyond banking.
IdentityTheft.gov notes that an identity thief may attempt to use an SSN to open accounts, obtain loans, file taxes, or get a job.
The exact risks depend on the data exposed and the jurisdiction.
Consumers whose SSNs are compromised should follow official identity-theft guidance rather than focusing only on payment-card monitoring.
Long-lived identifiers deserve long-term vigilance.
Why Fullz Records Can Remain Useful Longer Than Card Numbers
Credit cards can be cancelled and reissued.
Many identity attributes cannot be easily changed.
A victim's date of birth remains the same, and Social Security numbers are not routinely replaced merely because of exposure.
Addresses and telephone numbers may also remain useful for social engineering after they become outdated.
This is why identity-data breaches often justify longer-term credit and account monitoring than ordinary card replacement alone.
Why Underground Fullz Listings Can Still Be Wrong
Criminal listings should never be treated as authoritative records.
Data can be stale, incomplete, fabricated, duplicated, or incorrectly merged.
One person may have moved, changed banks, closed an account, or updated contact information.
The underground label “fullz” is a marketing term, not an accuracy certification.
This uncertainty does not make the underlying theft harmless; it simply illustrates the unreliability of criminal markets.
Why Consumers Should Not Search for Their Own Fullz
Searching criminal marketplaces for your identity data is not a useful recovery strategy.
Not finding your information in one place does not prove it has not been copied elsewhere.
Criminal websites can expose visitors to malware, scams, illegal content, or fraudulent 'dark web removal' services.
The safer approach is to use official monitoring and recovery tools.
In the United States, IdentityTheft.gov provides guidance based on the specific type of information lost or exposed.
Dark-Web Monitoring: Useful but Incomplete
Legitimate identity-protection providers may monitor known underground sources.
Such alerts can provide useful evidence that information has circulated.
But no service can guarantee visibility into every private forum, encrypted group, direct transaction, or copied database.
The FTC has warned consumers not to overreact to messages claiming their information is 'for sale on the dark web' and recommends checking financial accounts and using IdentityTheft.gov when misuse is detected.
Monitoring is a detection signal, not a guarantee that a person's data is safe or unsafe.
What to Do If Your Social Security Number Was Exposed
Consider placing a credit freeze with the major credit bureaus.
The FTC says freezes are free and can help stop new-account identity theft.
Review your credit reports and watch for unfamiliar accounts or inquiries.
If someone has actually misused your identity, report it at IdentityTheft.gov and follow the personalized recovery plan.
Continue to secure existing financial accounts separately because a credit freeze does not block transactions on accounts you already have.
What to Do If Bank Account Information Was Exposed
Contact the bank through an official channel.
Ask what monitoring, account-number changes, transfer restrictions, or other protective measures are appropriate.
Review recent transactions and report anything unfamiliar.
Protect online-banking credentials with unique passwords and MFA.
If credentials were exposed as well as account numbers, the bank may need to revoke active sessions or reset authentication information.
What to Do If Credit Card Information Was Exposed
Contact the card issuer and monitor the account.
Enable transaction alerts.
If the issuer recommends replacement, accept the new card and update legitimate recurring payments.
A credit-card replacement addresses the payment credential but does not resolve exposure of an SSN, password, or other identity data that may have appeared in the same stolen package.
Treat each exposed data category separately.
What to Do If Passwords Were Exposed
Change affected passwords immediately.
Change the password anywhere else it was reused.
Prioritize email, financial, cloud, social-media, and major shopping accounts.
Enable MFA.
Review active sessions and recovery details.
A password included with identity data can make account takeover much easier if it remains active.
Credit Freeze vs Fraud Alert
These protections work differently.
A credit freeze restricts access to the credit file and is generally the stronger preventive control against new-account credit fraud.
A fraud alert tells businesses to take extra steps to verify identity before opening new credit.
The FTC says both are free, but their duration and effect differ.
Consumers should choose based on their situation and official FTC guidance.
Credit Monitoring vs Identity-Theft Recovery
Credit monitoring can alert consumers to certain changes on their credit reports.
It does not prevent every type of identity theft and cannot detect all fraudulent use of personal information.
IdentityTheft.gov provides recovery steps after actual misuse.
Consumers should understand monitoring as an early-warning tool, not a complete recovery system.
Existing bank and card accounts should also have direct transaction alerts.
Why Businesses Should Minimize Stored PII
Every piece of personal information a business stores can become part of the impact if the organization is breached.
Data minimization reduces the quantity of information available to criminals.
Businesses should collect only what they genuinely need, retain it only as long as necessary, restrict access, and secure it appropriately.
Strong identity protection is not only an individual responsibility; organizations create systemic risk when they retain excessive personal information.
Data governance should therefore be part of fraud prevention.
Businesses Should Protect Identity Data and Payment Data Together
Payment security and identity security are closely connected.
A business may protect card information well while leaving customer profiles, addresses, dates of birth, or account credentials exposed.
Criminals can combine those fields with data stolen elsewhere.
Organizations should use strong access controls, MFA, encryption where appropriate, logging, patching, secure development, third-party risk management, and incident response across the broader customer-data environment.
Security scope should reflect how criminals actually aggregate information across systems.
Why Authentication Should Not Depend on Static Personal Facts
Questions such as date of birth, address, or mother's maiden name are weak when personal data has been breached.
Organizations should use stronger authentication methods and risk-based verification rather than relying only on biographical facts.
Phishing-resistant MFA provides stronger protection for high-risk accounts where supported.
Recovery processes deserve particular attention because criminals may use stolen identity facts to bypass normal login protections.
A secure login system can still fail if account recovery is easy to socially engineer.
How Financial Institutions Detect Identity Fraud
Banks and lenders can evaluate identity applications and account activity using multiple signals.
These can include credit history, identity consistency, device information, document verification, behavioral patterns, transaction activity, consortium intelligence, and other risk indicators.
The exact fraud models are security-sensitive and continually changing.
The broader principle is that possession of static identity details should not automatically establish that the applicant is the real person.
Layered verification reduces the value of stolen identity packages.
Case Study: The Hieu Minh Ngo Identity-Theft Scheme
A DOJ case provides one of the clearest official descriptions of the term “fullz.”
According to the Justice Department, Hieu Minh Ngo operated online marketplaces selling stolen personally identifiable information from 2007 through 2013.
DOJ said the packages known as “fullz” typically included a person's name, date of birth, Social Security number, bank-account number, and bank-routing number.
Ngo admitted offering access to stolen PII concerning a very large number of U.S. citizens. DOJ reported that thousands of victims whose information was sold were later victimized through fraudulent tax returns.
The case demonstrates why full identity packages should be viewed as identity-fraud infrastructure rather than simply a type of stolen credit-card record.
Case Study: SSNDOB Marketplace Seizure
In 2022, U.S. authorities announced seizure of the SSNDOB Marketplace, a series of websites that had sold personal information including names, dates of birth, and Social Security numbers.
DOJ said the marketplace had listed personal information belonging to approximately 24 million individuals in the United States and had generated more than $19 million in sales revenue.
The case illustrates the industrial scale at which identity information can be commoditized.
It also demonstrates that identity-data marketplaces create infrastructure, financial trails, and records that law enforcement can target.
Why Law Enforcement Targets Identity-Data Markets
Identity-data markets can enable many different crimes rather than one narrow payment-fraud technique.
Investigators may target marketplace operators, brokers, servers, domains, cryptocurrency, payment infrastructure, and customers.
International cooperation is often necessary because victims, operators, servers, and financial flows can exist in different countries.
Public enforcement cases show that underground identity markets are not beyond investigation simply because they operate online.
Seized data may also help identify victims and downstream fraud.
Legal Risks
Trafficking in or using stolen identity data can violate serious criminal laws.
Potential offenses may include identity theft, aggravated identity theft, wire fraud, access-device fraud, computer crimes, conspiracy, and money laundering depending on the facts and jurisdiction.
The 2015 Ngo case involved convictions and a 13-year federal prison sentence arising from a large international hacking and identity-theft scheme.
Marketplace buyers can also become investigative targets; operating the original breach is not required for downstream conduct to be criminal.
Legitimate education should use public cases, synthetic records, and authorized training data rather than real stolen identities.
Common Myths About Fullz
Myth: Fullz means every possible fact about a person. Reality: the term is informal criminal slang and the fields vary.
Myth: Fullz is just another name for a stolen credit card. Reality: it usually describes a broader identity-data package.
Myth: A fullz record guarantees successful identity fraud. Reality: data can be outdated, incomplete, inaccurate, or blocked by modern identity and fraud controls.
Myth: Replacing a credit card fixes every problem. Reality: long-lived identifiers such as SSNs or dates of birth may still create identity-theft risk.
Myth: If the information is on the dark web, nothing can be done. Reality: freezes, fraud alerts, issuer controls, MFA, account recovery protections, and IdentityTheft.gov recovery steps can substantially reduce harm.
Myth: A criminal seller's 'verified' label means the identity record is accurate. Reality: underground markets are unregulated and their claims are not trustworthy.
Myth: Consumers should buy or search leaked identity data to check themselves. Reality: official credit, banking, and identity-theft monitoring channels are safer and more useful.
Conclusion
“Fullz” is useful to understand because it highlights the difference between payment-card theft and broader identity-data theft.
A compromised card number can often be replaced. A stolen identity profile may contain long-lived information that criminals can continue attempting to misuse long after the original breach.
Public DOJ cases show that fullz packages have included combinations of names, dates of birth, Social Security numbers, addresses, bank-account details, routing numbers, and payment-card information.
The most important defensive response is therefore data-specific. Secure cards through the issuer, secure accounts with unique passwords and MFA, protect credit files when strong identity data is exposed, and use IdentityTheft.gov if actual identity theft occurs.
For businesses, prevention means reducing the amount of identity data available to steal, restricting who can access it, protecting authentication and recovery processes, and detecting fraud based on more than static personal facts.
Understanding fullz should not teach anyone how to trade stolen identities. It should make clear why combined identity records are dangerous, why underground claims are unreliable, and why both consumers and organizations need layered defenses against identity fraud.



