Skip to main content

What Are Fullz? Complete Guide to Stolen Identity Data

author image
Arvinder SinglaCo-founder & CEO15 min read
What Are Fullz? Complete Guide to Stolen Identity Data article image

Fullz, also known as full information, is a cybercriminal slang term used by fraudsters. It is a package containing stolen identity information like full name, date of birth, address, government ID number, and financial account information, gathered and sold as a single entity in the cybercrime marketplace. Fullz info gives a fraudster everything they need to impersonate a person, from opening up lines of credit to applying for loans to passing identity checks at a bank or lender. That's a lot more than just a single stolen card number.

In July 2026, the Ministry of Home Affairs shared data that showed that there were more than 53.8 lakh cyber fraud complaints and reported losses of over ₹56,087 crore in FY 2023-24 to FY 2025-26. The scale of these losses underscores how stolen personal and financial information continues to fuel ever-more sophisticated fraud schemes across India.

This guide explains how fullz work, the differences between live, dead, and fake fullz, and why those distinctions matter in identity fraud.

Key Takeaways

  • Fullz is basically a package where a victim's complete identity profile, such as name, date of birth, address, ID number, and financial details, is sold as one unit on dark web marketplaces.

  • Live fullz are verified and still usable for fraud; dead fullz have expired, been closed, or already been blacklisted.

  • Fake fullz are fabricated, recycled, or falsely advertised data sets, often sold to scam other buyers rather than to defraud a real victim.

  • Most “free fullz” offers are fraudulent, typically serving as malware delivery methods or advance-fee scams rather than sources of genuine data.

What Does “Fullz” Mean?

Fullz means “full information,” which is a complete identity record compiled and sold as a single package to enable fraudulent activities. The term originated on cybercrime forums, where sellers posted verified collections of stolen personal information rather than individual pieces like a single password or card number.

A typical fullz data set contains a person's full legal name, date of birth, national ID or equivalent Social Security Number, home address, phone number, and email address, often bundled with bank account or credit card information and answers to security questions.

Fake Fullz, Dead Fullz, Live Fullz, and Free Fullz: What These Terms Actually Mean

The fullz economy has its own internal language, and buyers on cybercrime forums use these terms constantly to grade what they are purchasing.

  • Live fullz: a data package that has been tested and confirmed to work; the linked account is active, the ID passes validation, and the credentials still log in. This is the highest-value listing on any fullz marketplace.

  • Fake fullz: data that is fabricated, duplicated from an older breach and relisted as new, or deliberately mismatched (a real name paired with an unrelated ID number) to pad out a bundle. Fake fullz are often sold by scammers targeting other criminals, since dark web transactions carry no buyer protection.

  • Free fullz: listings or forum posts advertising fullz info at no cost are almost never genuine. In most cases, the links or listings offering “free fullz” are scams meant to distribute malware, steal credentials via phishing pages, or trick users into paying upfront fees without providing any data.

  • Dead fullz: an identity data package that no longer works for fraud, either because the information is outdated, the linked account has been closed, or the data was already flagged and blacklisted after prior misuse.

For anyone gathering insights on Fullz from the perspective of fraud prevention or cybersecurity, the main takeaway is simple: claims of free fullz or unverified fullz data should be viewed as red flags, not shortcuts. Interaction with these listings often exposes users to the same malware, phishing, and credential theft techniques used to steal identity data in the first place.

What Is the Difference Between “Fullz” and “Dumps”?

Fullz and dumps are both stolen data products sold on cybercrime marketplaces, but they serve different purposes and carry different risk profiles.

Key AspectFullzDumps
ContentsComplete identity profile: name, DOB, address, ID number, bank/card detailsRaw card track data: card number, expiry date, CVV
Primary SourceData breaches, phishing, malware, and insider leaksCard skimmers, ATM/POS malware, and compromised payment terminals
Common UseLoan fraud, account takeover, synthetic identity creation, and KYC bypassCard cloning and unauthorised card-present or online transactions
Market PriceHigher, due to the completeness of the identity dataLower per unit, since a single card has limited use before it is blocked
Detection WindowLonger, as identity misuse can go unnoticed for weeks or monthsShorter, as unusual card transactions are typically flagged faster

Dumps are transactional and card-specific, whereas fullz are identity-specific and can be used multiple times in fraud attempts. A single live fullz can be used to defraud banking, lending, and e-commerce sites years after the original breach that exposed it.

How Do Fullz Work?

The journey of a fullz follows a surprisingly structured process, resembling a legitimate supply chain where stolen identity data moves through collection, verification, packaging, and sale before being used for fraud.

How Do Fullz Work

  • Obtain: first, data is collected through a breach, phishing campaign, malware infection, or skimming device.

  • Verify: sellers start by testing the data, such as login attempts, ID validation, and balance checks, to confirm it is live fullz and not dead on arrival.

  • Package and price: the verified records are bundled into a fullz listing and priced by completeness, country, and account balance where applicable.

  • Sell: listings go up on dark web marketplaces, private cybercrime forums, or encrypted messaging channels.

  • Exploit: a buyer uses the identity to open multiple bank accounts, apply for loans or credit cards, file fraudulent tax returns, or pass identity checks that rely on static personal data rather than behavioural or device signals.

Warning Signs of a Fullz-Based Application

No single signal proves an application is built on stolen identity data, but a cluster of these together is exactly the pattern fraud teams should be watching for.

  • A newly created email address attached to an identity that's supposedly years old.

  • A device location that doesn't match the applicant's declared residential address.

  • Multiple applications submitted from the same device within a short span of time.

  • Identity details that match public records but show almost no digital footprint anywhere else.

  • A SIM change recorded shortly before the account or application was opened.

  • Several accounts linked back to the same phone number or device fingerprint.

Fullz Used in Criminal Activity: Real-World Patterns

Nobody buys a fullz out of curiosity. It's bought to commit fraud, and the way that plays out tends to follow a handful of familiar patterns across cases worldwide.

  • Loan and credit card applications are the most common route. A fraudster walks a victim's full identity through a bank or lender's KYC process, one that's often built to match documents and details rather than confirm the person is actually there.

  • Synthetic identity works a little differently: genuine fullz data gets blended with invented details to create someone who doesn't fully map back to any single victim, which makes the fraud harder to trace.

  • Account takeover is more direct: login credentials inside a fullz are used to break into an existing bank, e-commerce, or telecom account, often followed by a quiet change to the registered phone number or email that locks the real owner out.

  • SIM swap fraud takes identity theft a step further. Fraudsters use a victim's personal details to convince a telecom provider to issue a duplicate SIM, which then lets them intercept the OTPs banks depend on.

  • Tax and benefit fraud is another common use case, with stolen identity data being used to file fraudulent tax returns or claim government benefits intended for the legitimate recipient.

Understanding how fraudsters obtain this identity data is the next step in understanding how fullz markets operate.

How Identity Data Actually Gets Stolen

Fullz data does not appear on dark web marketplaces by accident. It is typically obtained through a handful of well-established cybercrime techniques that individuals and businesses are exposed to every day, often without realising it.

  • Data breaches: A data breach at a bank, an e-commerce platform, or a healthcare provider can expose thousands of customers' records. Criminals often collect this data and combine this information into fullz packages.

  • Phishing: Phishing works the other way around, tricking someone into typing their own details into a fake email, text message, or website.

  • Card skimming: Card skimming captures payment card data during legitimate transactions, either through physical skimming devices or compromised payment systems.

  • Malware: Malware such as keyloggers and info-stealers can secretly collect passwords, payment details, and other sensitive information from a device by hacking it.

  • Unsecured public Wi-Fi: Using unsecured public Wi-Fi can expose sensitive information. This can happen because unencrypted data may be intercepted by attackers.

Why Traditional KYC Struggles Against Fullz

Most identity verification built into onboarding today checks a handful of fixed data points: Whether the name matches, whether the date of birth matches, whether the address matches, and whether the OTP arrives at the right number. That approach works well against a fraudster guessing at details or using a stolen card in isolation. It struggles badly against a fullz, because a fullz was built specifically to answer every one of those questions correctly.

Traditional CheckWhy It Fails Against Fullz
Name MatchThe fraudster already has the correct name from the fullz package
Date of Birth VerificationThe date of birth is included in the fullz data, so it can match on the first attempt
Address VerificationThe address is also part of the package and may be accurate down to the PIN code
OTP VerificationCan be bypassed through SIM swaps enabled by the same stolen identity details
Document UploadReal, stolen, or leaked documents may already accompany the fullz

The problem isn't that KYC systems are poorly designed. It's that a fullz supplies exactly the information those systems are built to check. The fraudster isn't inventing an identity; rather, they’re presenting a real one, verified by the last data point. This is why identity checks alone are no longer enough to stop this category of fraud.

How Do Fullz Attacks Affect Businesses?

Fullz-driven fraud directly increases financial losses, regulatory exposure, and customer churn for businesses that rely on static identity checks. When identity data used to open accounts or approve transactions is stolen and traded at scale, the effects ripple across lending, banking, e-commerce, and telecom sectors.

Impact AreaEffect on Business
Direct Financial LossLoan defaults and chargebacks from accounts opened using fullz-based synthetic or stolen identities
Regulatory PenaltiesNon-compliance with KYC and AML requirements when fraudulent onboarding goes undetected
Customer TrustAccount takeovers and unauthorised transactions damage brand reputation and customer retention
Operational CostManual fraud investigation, chargeback disputes, and remediation consume support and compliance resources
Onboarding FrictionBusinesses may tighten verification after fraud incidents, slowing down legitimate customer onboarding

The increasing scale and sophistication of cyber-enabled financial fraud have also drawn regulatory attention. Therefore, the Supreme Court of India has recently asked the Reserve Bank of India (RBI) to prepare a standard protocol for banks to deal with cyber fraud cases.

It emphasised early detection, coordinated response mechanisms, and providing better protection against new types of financial crime. The move reflects a broader recognition that traditional verification controls alone are no longer sufficient against identity-driven fraud, account takeovers, and other increasingly sophisticated cyber threats.

How to Detect Fullz-Based Fraud

Catching a fullz-based application means looking past the data itself, because the information will often appear legitimate. The real signals come from factors that are far harder for fraudsters to control or replicate, such as device history, behavioural patterns, and digital footprint consistency.

  • Device intelligence flags a phone or browser that has previously been associated with fraud attempts, even when it's now or later paired with a different identity.

  • Digital footprint analysis checks whether an identity actually has a history online. A name with no email age, no social presence, and no prior digital activity is a red flag on its own.

  • Behavioural biometrics looks at how someone fills out a form, not just what they type into it, picking up the rushed, scripted patterns that don't match how a genuine applicant behaves.

  • Velocity checks catch the same device or IP address applying under several different identities within a short window.

  • Consortium intelligence strengthens fraud detection by combining anonymised risk signals across multiple institutions, helping identify suspicious identities, devices, and patterns before they can be reused elsewhere.

Static document checks and one-time OTP verification are no longer sufficient to combat fullz-based fraud, as the fraudster already possesses the information that traditional verification methods are designed to validate.

This is why Sign3 relies on multiple fraud intelligence signals, including device fingerprinting, digital footprint analysis, behavioural indicators, and network-level insights. Together, these signals help businesses evaluate risk using attributes that stolen identity data alone cannot replicate.

Read More: What Is Behavioral Biometrics? A Complete Guide

How Can You Protect Yourself From a Fullz Attack?

To protect yourself from a fullz attack, limit the amount of personal data you expose and watch for warning signs that your identity may already be circulating among fraudsters or being used for unauthorised activity. No single step will eliminate the risk, but a combination of habits can reduce the risk factors. These include:

  • Regularly checking your credit report for accounts or loan inquiries that you did not initiate.

  • If you think your data has been breached, then freeze your credit card or set up fraud alerts.

  • Use a different password for each account, and turn on multi-factor authentication if you can.

  • Never click on links in unsolicited emails or messages asking for personal or financial details.

  • Avoid entering sensitive information while connected to unsecured public Wi-Fi.

  • Never download files or click links promising “free fullz,” “check tools,” or similar; these are common malware distribution traps.

  • Report suspected identity theft immediately through India's cybercrime helpline 1930 or the National Cyber Crime Reporting Portal at cybercrime.gov.in.

Read more: How to Report Cyber Fraud in India: 1930 Helpline & Cybercrime.gov.in Guide

For businesses, the same principle applies at scale: reducing reliance on data a fraudster can already possess, and adding verification layers built on device intelligence and digital footprint signals that are far harder to fake than a name, date of birth, or ID number.

Why Identity-First Fraud Defence Matters More Than Ever

Fullz have shifted identity fraud from a single stolen card number to a complete, reusable copy of a person's financial identity. This matters because it undermines checks businesses have long relied on: matching a name to an ID, verifying date of birth, confirming an address, since fraudsters using live fullz can bypass these without ever being who they claim to be.

Recognising the difference between live, dead, and fake fullz, and understanding how identity data is harvested, lets individuals and compliance teams act early rather than after the damage is done.

Organisations manage this risk best by pairing standard KYC with signals stolen data can't replicate. These include: device history, behavioural patterns, digital footprint consistency. Sign3 adds this layer of fraud intelligence, flagging high-risk identities before onboarding completes. Book a demo to map your fraud exposure in minutes.

FAQs

What does fullz mean in cybercrime?

Fullz is short for “full information.” It refers to a complete stolen identity package, bundling a victim's personal, financial, and often login details, sold as a single unit on dark web marketplaces and cybercrime forums rather than as scattered, single-item leaks.

What is fullz info?

Fullz info is the actual data set contained inside a fullz listing. It typically covers a person's full legal name, date of birth, residential address, government ID number, phone number, email address, and often bank account, card, or security question details, packaged together to enable end-to-end identity impersonation.

Is a fullz the same as a data breach?

No. The source events are data breaches where records are exposed, often from company servers. A fullz is the finished product that criminals build afterwards, often by combining and cross-referencing data pulled from multiple separate breaches into one profile per victim.

What is a dead fullz?

A dead fullz is identity data that has stopped being useful for fraud, either because the linked bank account or card has been closed, the details are outdated, or the record was already flagged and blacklisted after earlier misuse. Sellers sometimes mix dead fullz into bulk listings to pad out volume.

What is a live fullz?

A live fullz is a verified, currently active identity package. Sellers typically test it first, confirming the linked account is open, the ID number validates correctly, and any included credentials still log in, which is why live fullz command a higher price than unverified listings.

What is a fake fullz?

A fake fullz is data that has been fabricated, recycled from an old breach and relisted as new, or deliberately mismatched, such as a real name paired with an unrelated ID number. These are usually sold by scammers targeting other buyers on cybercrime forums, since such marketplaces offer no genuine buyer protection.

Is free fullz real?

Almost never. Listings or links advertising “free fullz” are overwhelmingly used as bait, either to install malware on the visitor's own device, harvest their credentials through a fake login page, or draw them into an advance-fee scam before any data actually changes hands.

What is the difference between fullz and dumps?

Fullz contain a complete identity profile spanning personal and financial details, making them useful for loan fraud, account takeover, and KYC bypass. Dumps are just the raw card track data that is captured through skimming, primarily used for cloning cards and usually blocked faster if misuse is identified.

How do fraudsters get fullz data?

Most fullz data is obtained via large data breaches, phishing emails or messages designed to gather data directly, skimming devices for physical or digital cards, malware that logs keystrokes and stored passwords, and data sniffed from insecure public Wi-Fi networks.

Where should I report identity theft in India?

Identity theft and suspected fullz-based fraud should be reported immediately through India's national cybercrime helpline at 1930, or by filing a formal complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in, ideally within the golden hour of noticing unauthorised activity.

Can businesses prevent fullz-based fraud during onboarding?

Yes. Traditional KYC checks alone struggle against fullz because the fraudster already holds every static data point being verified. Layering in device fingerprinting and digital footprint analysis adds behavioural and technical signals that stolen identity data cannot replicate, making synthetic and impersonated onboarding attempts far easier to catch.

About The Author

author image
Arvinder SinglaCo-founder & CEO

Arvinder Singla is the Co-founder & CEO of Sign3. With extensive experience in the gaming and fintech industries, he has been at the forefront of innovating fraud prevention solutions. His expertise drives Sign3's mission to deliver cutting-edge technology that safeguards businesses from evolving fraud threats.

Fraud Prevention Resources & Insights