Your Social Security number was leaked in a breach three years ago. You changed your passwords and moved on, but right now, that SSN is sitting in an enriched identity dossier on the dark web, bundled with your home address from a second breach and your phone number from a third, and someone is shopping for it.
The FBI's 2025 Internet Crime Report logged over $20.9 billion in cybercrime losses, a 26% jump from the year before. Much of that damage traces back to stolen data that stays in circulation long after the original dark web data breach. Data moves through distinct phases on the dark web, and each phase carries different risks. Knowing the dark web data lifecycle helps you figure out where you're exposed and what to do about it.
Key takeaways
- Stolen data moves through four phases: triage (24-72 hours), general sale (weeks 2-8), commodity pricing (months 3-12), and archive/enrichment (2-plus years)
- The first 24 to 72 hours after a breach are the highest-value window for dark web monitoring
- Credit cards lose value fast once canceled, but SSNs and medical records stay exploitable for years
- SSN data actually gains value over time as criminals enrich it with data from newer breaches
What Happens to Stolen Data on the Dark Web
Most people imagine a single moment where a hacker steals your data, sells it, and moves on. The real picture looks more like a supply chain. After a breach, your data enters an underground economy with its own buyers, sellers, pricing tiers, and timelines, and a single dark web data breach can generate criminal activity for years.
Phase 1: The triage window (first 24 to 72 hours)
The triage window is the first 24 to 72 hours after a breach, when stolen data is tested and sorted before reaching any public marketplace. Premium buyers get first access during this phase, and credentials are verified against live services to confirm which logins still work. Verified pairs sell for far more than untested ones, which is why this testing step sets the price for everything that follows.
Attackers sort the stolen data into tiers during this window. Bank logins, crypto exchange credentials, and corporate VPN access get flagged as premium, while credit cards get tested for active balances. Complete identity packages, known as "fullz" (name, address, SSN, date of birth), get assembled for buyers looking to commit identity fraud.
The first 24 to 72 hours after a breach are the highest-value window for dark web monitoring. If a monitoring service catches your credentials during this triage phase, you can change passwords and freeze accounts before criminals finish testing and pricing your data. Once the data goes to general sale, the damage is already spreading.
Phase 2: General sale (weeks 2 through 8)
The general sale phase is when stolen data hits dark web marketplaces for bulk purchase. Underground markets work like regular online stores, with product descriptions, seller reviews, and customer support. Buyers pay with cryptocurrency to stay anonymous.
Prices start at their peak and decline over time. A U.S. credit card with CVV may sell for $10 to $40 in the first days of listing, while bank account logins can cost $200 to $1,000 or more depending on the balance. A "fullz" identity package typically goes for $20 to $100. As weeks pass and more victims rotate their passwords or cancel cards, the percentage of working credentials drops, and prices fall with it.
That price decay is why speed matters on both sides. Criminals rush to exploit data before victims react, and victims who act fast, change passwords, enable two-factor authentication, and use unique email aliases for each account, can make stolen credentials useless before anyone gets to use them.
Phase 3: Commodity pricing (months 3 through 12)
The commodity phase kicks in around three months after a breach. Most high-value individual credentials have either been used or rotated by their owners by now, and what remains gets folded into massive combo lists. A combo list is a collection of millions of usernames and passwords pulled from multiple breaches and sold at pennies per record.
Say your email and password leaked from a shopping site in January. You never changed that password. In April, that credential is sitting in a combo list alongside millions of others, and criminals are buying these lists for credential stuffing attacks. Even if only 1% of the passwords still work, a list of 10 million credentials yields 100,000 live logins.
During this phase, a stolen SSN goes for as little as $1 to $6 because so many have already been leaked. KELA's State of Cybercrime 2026 report found 2.86 billion compromised credentials circulating across criminal markets in 2025 alone. Individual records are cheap at that volume, but credential stuffing at scale still causes serious financial damage.
Phase 4: Archive and enrichment (2-plus years)
The archive phase is when old breach data gets combined with records from newer breaches to build enriched identity dossiers. A leaked email from one breach gets paired with a stolen password from another, a phone number from a third, and a home address from a fourth, so each new breach adds another layer to the profile.
Your SSN is the most dangerous piece in this chain. Unlike a password or credit card, you can't cancel and replace it. A leaked SSN actually becomes more valuable over time as criminals layer additional data on top of it. Five years after a breach, your SSN may be sitting in a dossier that includes your employer, your bank, and your home address, all pulled from separate incidents. That enriched profile is far more useful for identity theft or tax fraud than a standalone SSN.
Health records work the same way. Medical histories, insurance details, and diagnoses can't be changed or canceled, so the dark web stolen credentials shelf life for medical data is essentially permanent. A Flare analysis of 348 breach listings found health records may command around $300 per record.
Why the First 72 Hours Matter Most
Every phase carries risk, but acting in the first 24 to 72 hours gives you the best chance of preventing real damage. Your credentials haven't been widely distributed yet, passwords are still active, and credit cards haven't been maxed out.
After that window closes, the damage compounds quickly. Credentials spread to more buyers, prices drop, and your data gets bundled into combo lists and enriched dossiers that circulate for years.
Removing your personal data from data broker sites reduces what attackers can find during the enrichment phase. Fewer public records about you means less material for criminals to cross-reference with stolen credentials.
What You Can Do Right Now
Knowing how long stolen data remains active only matters if you act on it. Here are six steps to reduce your exposure across all four phases:
- Set up dark web monitoring now, not after a breach. A monitoring service that alerts you during the triage window gives you the best shot at beating criminals to your own accounts.
- Freeze your credit with all three major bureaus (Equifax, Experian, TransUnion). A freeze blocks anyone from opening new accounts in your name, even if they have your SSN.
- Use unique passwords for every account. A password manager makes this practical. When one account gets breached, the damage stays contained and the credential becomes useless for stuffing attacks.
- Turn on two-factor authentication everywhere. App-based authenticators (not SMS) are the stronger option.
- Use unique email aliases for different accounts. When every account has a different email alias, a breach at one service can't be linked to your bank or your workplace. An attacker building an enriched dossier hits a dead end.
- Reduce your public footprint. Delete old accounts you no longer use. Tighten privacy settings on active ones. Cloaked's opt-out guides walk you through removing your data from the biggest broker sites.
How Cloaked Helps You Stay Ahead of Breach Fallout
Stolen data circulates for years, and you can't delete what's already on the dark web. What you can do is make that data useless. Cloaked is useful here in a straightforward way. You generate unique email aliases and masked phone numbers for every account, so a breach at one service cannot be linked back to you. Cloaked also removes your personal information from 1000+ public websites, cutting off the pipeline that feeds the dark web data lifecycle. Your data is protected with end-to-end encryption and SOC 2 compliance, and you get Dark Web & SSN Monitoring plus identity theft insurance up to $1M.
Take a free safety scan and see how exposed your information is right now. Have questions? Get in touch.
FAQs
How long does stolen data stay on the dark web?
Stolen data can remain on the dark web indefinitely. Credit card numbers may lose value within days once canceled, but Social Security numbers, dates of birth, and medical records stay useful to criminals for years. Old breach data regularly gets repackaged with newer leaks and resold in enriched identity dossiers.
What are the four phases of the breach data lifecycle?
Stolen data typically moves through four phases: the triage window (24 to 72 hours, where premium buyers test credentials), general sale (weeks 2 through 8, with declining prices), commodity pricing (months 3 through 12, where data enters bulk combo lists), and the archive phase (2-plus years, where records get enriched with data from other breaches).
Can you remove your data from the dark web?
No. Once stolen data is posted, copied, and distributed across multiple dark web forums and marketplaces, full removal is not possible. The practical response is to make that data less useful by changing passwords, freezing credit, using unique aliases, and monitoring for new exposures.
Why are Social Security numbers more dangerous than stolen credit cards?
Credit cards can be canceled and replaced within minutes, which makes stolen card data lose value fast. SSNs can't be changed. A leaked SSN actually becomes more valuable over time as criminals combine it with data from other breaches to build enriched identity profiles used for loan fraud, tax fraud, and account takeovers.
How quickly does stolen data appear on the dark web after a breach?
Stolen data can appear on dark web marketplaces within hours of a breach. Premium buyers may test and purchase credentials within the first 24 to 72 hours, before the data reaches public listings. Acting during this triage window gives you the best chance of preventing damage.
How do you know if your stolen data is being sold on the dark web?
Dark web monitoring services scan underground forums, marketplaces, and data dumps for your personal information, including email addresses, SSNs, and phone numbers. When a match appears, you get an alert so you can change passwords, freeze accounts, and take protective steps before criminals use the data.



