Blacksec

Administrator
Staff member
ROOT
VIP
Hey hackers — what are fullz gets answered in two sentences on a dozen glossary sites run by fraud-prevention vendors who've never touched the underground. This is the actual breakdown: what a fullz pack really contains, how the taxonomy works (fullz vs combos vs logs vs dumps — most people conflate all four), where they come from, why "fresh" matters more than price, what the marketplace reality looks like from the inside, and why the smartest move in this entire space is the one everybody quietly agrees on: never purchase CC or fullz from anyone. Street knowledge, structured properly, no corporate rewrites.
TL;DR: Fullz ("full information" / "full z-info") are complete identity records — the full dossier on one person rather than just card credentials. A typical pack bundles name, SSN, DOB, address, card number, CVV, and often secondary identifiers (phone, email, driver's license, mother's maiden name). They're harvested from breaches, infostealer malware, skimmers, and phishing operations, then sold — mostly to people who end up scammed, exit-scammed, or documented. The differentiation table below settles the fullz-vs-combo-vs-log confusion in one read.

What Are Fullz? The Definition​

Fullz = full information. In underground shorthand, it refers to a complete identity dossier on a single person — enough data points to impersonate them across financial, telecom, and government-adjacent surfaces. Where a "combo" is just an email:password pair and a "dump" is raw card track data, a fullz record is the expanded identity: the person, their identifiers, their payment instruments, and the verification data needed to pass knowledge-based checks.
The term's origin is straightforward: underground shorthand for "full information" — "full info" → "fullz," following the plural-z naming convention common to darkweb vocabulary. What matters isn't the etymology — it's the scope distinction: fullz means complete, and completeness is exactly what makes them the most damaging single artifact type in the stolen-data taxonomy.
Who uses the term and why: researchers cataloging breach corpora, fraud analysts building detection rules, journalists covering incidents, and the underground itself trading records. You'll see "fullz" in incident reports, courtroom documents, CTI feeds, and marketplace listings alike — it's crossed from slang into standard vocabulary, which is why understanding it precisely matters whether you're reading a leak report or scanning a news headline about a "fullz leak."

What's Inside a Fullz Pack? The Anatomy​

Here's the component breakdown — this is what people mean when they argue about whether something "counts" as fullz. Each data class serves a specific verification layer, which is why packs are assembled around completeness of verification coverage, not random data hoarding:
ComponentCategoryWhat it verifies (the reason it's included)
Full legal nameIdentity corePrimary matching key for KYC and account recovery flows
Date of birthIdentity coreKnowledge-based verification ("enter your DOB") on virtually every financial flow
Social Security NumberGovernment ID (US)High-trust verification: account opening, credit pulls, IRS-adjacent flows
Current + previous addressLocationAddress-history checks ("which address have you lived at?") — previous addresses defeat lookup-only verification
Phone numberContactSMS/voice OTP surface, account recovery, carrier-level identity binding
Email + passwordCredentialDirect account takeover of existing identities; password reuse expands reach
Card number (PAN) + expiryPaymentTransaction initiation
CVVPaymentCard-not-present verification step
Card PINPayment (rare)ATM/POS — the rarest component, sourced from skimmers with pinhole cameras or insider captures
Mother's maiden nameLegacy knowledgeOld-school security questions still deployed by legacy banking and telecom support flows
Driver's license / passport #Government IDIdentity document verification, high-value for impersonation of higher-trust surfaces
Employer / income dataProfileCredit applications, employment-verification bypass on lending flows
The completeness principle: a pack missing SSN and DOB but full on card data drifts toward "combo/dump" territory; a pack with identity core but no payment instruments is "PII/identity fullz." The market prices accordingly — every missing verification layer is a use case that dies, and pricing reflects exactly which layers survived the collection. This is also why "high balance fullz" listings (the term shows up constantly in search) are usually marketing fiction: balance data isn't static, any "balance" listed at sale time is a snapshot that decayed the moment it was written down.

Types of Fullz: The Taxonomy​

Not all fullz are built equal. The taxonomy that experienced researchers and analysts actually use:
TypeContents focusCollection origin (typical)Damage potential
CC FullzIdentity core + card data + CVVBreaches of merchants/databases, skimmersCard fraud + identity correlation
Bank FullzIdentity core + bank account + routingFinancial breaches, business email compromise, insiderDirect account takeover / ACH flows
Identity FullzName/SSN/DOB/address, no payment dataSSN breaches, gov/edu leaks, people-search aggregationNew-account fraud, synthetic identity assembly
Minors' FullzClean credit history of minors (thin files)School/insurance breachesLong-dormant fraud — often undetected for years
Elder FullzEstablished credit, low digital monitoringHealthcare, benefits breachesHigh-limit fraud against low-monitoring victims
Synthetic-Ready SetsMultiple real identities to mixAggregated from several sourcesFabricated identities that pass initial KYC
Why the taxonomy matters to defenders AND researchers: each type leaves a different incident signature. CC fullz correlate with chargeback spikes; identity fullz correlate with new-account-opening fraud months after the source breach; synthetic sets correlate with KYC-pass-then-default patterns on lending products. If you can classify the artifact type, you can predict the fraud typology — that's the entire analytical value of knowing this vocabulary properly instead of using "fullz" as a generic boogeyman word.

Fullz vs Combos vs Logs vs Dumps vs Cards​

The single most common point of confusion online — five terms used interchangeably by people who've never seen a real listing. Settle it once:
TermCore contentsFormatPrimary abuse scenarioMissing (vs fullz)
FullzComplete identity dossier (identity + contact + often payment)Structured record per personIdentity impersonation, account takeover— (it's the superset)
Combosemail:password pairsPlain text line listsCredential stuffing / reuse attacksIdentity attributes, payment data, DOB/SSN
DumpsCard track data (magstripe data: PAN, expiry, track2)Encoded track stringsPhysical card cloningIdentity entirely; no person attached
CVV (cards)PAN + expiry + CVV onlyCC | MM/YY | CVV linesCard-not-present transactionsCardholder identity, name, address
Logs / Stealer logsRaw machine dump: browser cookies, tokens, autofill, credentials, system infoFolder-per-victim archivesSession hijack (cookies/tokens bypass 2FA)Structured identity — it's raw material, not a dossier
The relationships, stated cleanly: combos are the wholesale of credential data (volume, low individual value). Dumps/CVV cards are payment-only artifacts. Logs are raw harvest — from which fullz get ASSEMBLED when someone parses the autofill data, cookies, and saved forms into a structured record. Fullz are the finished identity product: curated, person-complete, verification-complete. That assembly step — raw log → structured fullz — is where most modern fullz actually originate, because infostealer malware captures autofill identity fields incidentally while hunting for crypto wallets and session tokens.
The half-life of stolen identity data: fullz are perishable goods. Freshness determines everything about both research value and (unfortunately) criminal utility:
Fresh (days-old): source breach just hit, victim hasn't been notified, password still valid, card still active. This is what listings screaming "FRESH FULLZ" are pretending to sell — and the honest observation is that genuinely fresh high-quality data stays in collector hands or goes direct to high-trust buyers; it rarely sits in public shopfronts at all.
Aged (weeks-months): notification cycles have run, passwords rotated, some cards reissued. Still valuable for identity correlation research, degraded for anything time-sensitive.
Stale (months+): victims have changed credentials, cards reissued with new numbers, addresses updated. The record still documents a REAL person's REAL historical data (that's why breach archives remain research-relevant for years) but its operational utility has decayed to near zero.
Verification signals of decay researchers actually use: card BIN still active vs reissued ranges, email domain still alive vs defunct, breach date vs listing date delta, whether the password hash cracked format matches the source breach's known hash type. Data age isn't guesswork — forensic markers on the RECORD itself tell you its era, even without trusting the seller's claims (which you should never do anyway).

Where Fullz Come From: Collection Vectors​

The source landscape, documented thoroughly in breach reports, CTI research, and incident response literature — organized by vector:
  • Data breaches (the original source). Retail, healthcare, education, government — any database holding identity records joined with contact/payment data. Historic mega-breaches established the initial corpus of millions of records; those archives still circulate years later, which is why "fresh" is doing heavy lifting in any listing description.
  • Infostealer malware (the 2020s dominant vector). Commodity stealers (the family names appear constantly in vendor telemetry reports: RedLine, Raccoon, RisePro, Vidar and their successors) harvest browser autofill profiles, saved passwords, cookies, and session tokens from infected machines. The autofill data — name, address, phone, sometimes SSN fields people saved — IS identity data; when operators parse it into structured records, that's fullz assembled from logs. The volume shift this caused is enormous: identity data now flows continuously from endpoints instead of arriving in discrete breach events.
  • Skimmers (payment-specific). ATM skimmers with pinhole cameras, gas-pump overlays, e-commerce skimmer scripts (Magecart-class) capturing checkout form data server-side. Produces card-centric fullz: payment data + whatever identity fields the checkout form held.
  • Phishing / vishing kits. Credential harvesting pages that specifically request identity fields ("verify your account: DOB, SSN, card") produce fullz directly because the kit's form design targets completeness.
  • Insider access & public records aggregation. Healthcare insiders, telecom support reps with directory access, and people-search-site aggregation (which combines dozens of legal-but-exposed data sources into surprisingly complete dossiers) fill gaps between the above.
The researcher's lens: knowing the vector explains the record's shape. Breach-sourced fullz have consistent field structure (database schema leaks through); infostealer-sourced have machine fingerprints attached (which device, which browser); skimmer-sourced cluster geographically around compromised terminals. Vector forensics on a sample tells you where it originated without taking anyone's word for it.

Why "Fresh" Matters More Than Price (The Economics)​

Stolen data economics are simple enough to state in three lines, and understanding them explains every weird listing pattern you'll encounter:
1. Value = remaining verification life. A fullz set is worth exactly as much as its un-rotated credentials and un-reissued cards. Every hour after collection, probability of rotation increases. Value isn't about the data's completeness — completeness is assumed — it's about time since harvest.
2. Price signals honesty inversely. Cheap bulk listings = aggregated stale corpora (old breach data resold indefinitely). Expensive "fresh" claims = either legitimately fresh direct-source data (rarely public) or, most often, a marketing word with no verification behind it. The pricing structure itself is a tell: when price and claimed freshness don't correlate with verifiable source dates, you're looking at narrative, not goods.
3. The market is adversarial on every side. Sellers inflate freshness, buyers run validation bots against stolen cards to test them (killing the data's usefulness for everyone else), other buyers are informants, and some "shops" exist solely to capture payment from marks. When ALL participants are criminals, scammers, or law enforcement — honest trade becomes structurally impossible. This isn't a moral observation; it's a market-design one. It's why the underground data market churns through shop names like sandpaper.
Understand the economics and you understand the whole theater: every "verified fresh" banner is a claim nobody can enforce, every exit scam was structural, and every buyer who "tested before buying" was destroying the thing they paid for. The only consistently rational position in this market is refusal to enter it.

The Marketplace Reality: Scams, Honeypots, and Exit Games​

Since this is where curiosity always lands — the unvarnished truth about how these marketplaces actually operate, from people who've watched the cycle repeat for a decade:
The shop lifecycle is predictable: new shop opens with aggressive marketing and "verified" samples → accumulates buyers and payment volume → either gets raided, exit-scams with the balance, gets outcompeted by newer shops, or gets exposed as reselling stale data it never validated. The graveyard of past marketplaces is the longest list in this entire space. Ask anyone who's watched for multiple years: name five shops from five years ago that still operate with the same ownership. The silence is the answer.
The honeypot layer: some "shops" are collection operations — they exist to identify who's trying to buy stolen data (a marketable product for exactly the organizations you'd expect to buy such lists), or they're run by bad actors who simply never had inventory and existed to take payment. Free samples and "trial access" are the classic hooks. You cannot tell from outside which category a shop is in, because every category posts the same testimonials and uses the same language.
The validation trap: the practice of "testing" purchased card data before committing to a bulk buy sounds rational — and it is exactly why sellers of anything legitimately fresh would never sell to you. Testing generates transaction alerts, alert generates investigation, investigation generates trails. The act of validating destroys the asset class. Which means anyone selling to someone known to validate is selling compromised-by-design data. The loop closes on itself.
The people who lose consistently: new entrants. Every cycle, fresh buyers pay fresh prices for recycled data, learn the hard lessons everyone learns, and either leave or become the next generation's cautionary anecdote. The infrastructure (markets, shops, payment processors for crypto) rotates; the victim profile stays constant.

The Standing Rule: Never Purchase CC or Fullz From Anyone​

It's the rule pinned at the bottom of every guide on this site, and after the anatomy, taxonomy, economics, and marketplace breakdown above — you can see exactly why it's stated as absolute rather than advisory:
1. The product is structurally defective. Stale data, inflated freshness, validation-damaged cards — you're buying an asset whose core value proposition (freshness) cannot be verified before purchase and whose testing destroys it. The defect isn't in one shop; it's in the product itself.
2. Every purchase identifies you. Payment for goods (even crypto, even "privacy coins" with their chain-analysis realities) creates linkage. The buyer list of any seized marketplace becomes evidence — this has played out repeatedly in court records. The act of purchasing adds your identity to a dataset about people who purchase stolen data. You become inventory.
3. The counterparty is guaranteed untrustworthy. Re-read the marketplace section: scammers, exit artists, informants, honeypots. There is no version of this transaction where the other side is honest — honesty is not available in a market where all participants are by definition operating without recourse. "I found a trusted vendor" means "I found a vendor whose marketing I believed."
4. The knowledge path doesn't require it. Everything genuinely valuable in this space — how identity data works, how verification layers function, how fraud typologies map to breach types, how defenders detect each category — comes from studying STRUCTURES, not buying records. The researchers, fraud analysts, and security professionals who know this space deepest are the ones who never had a reason to purchase anything. Buy knowledge; it doesn't rot, doesn't incriminate, and doesn't get exit-scammed.
This isn't morality theater. It's the same calculus that closes every other section on this site: the transaction is a losing game by construction, the exit is more expensive than admission, and everything the market sells can be understood for free by someone willing to read carefully. Never purchase CC or fullz — build the understanding instead.

FAQ​

What does fullz mean?​

"Fullz" = full information: a complete identity dossier on one person rather than partial credentials. A fullz record bundles identity core (name, DOB, SSN), contact data (address, phone, email), and often payment details (card number, CVV) — enough to pass knowledge-based verification flows. The term comes from underground shorthand ("full info" → "fullz") and now appears in breach reports and CTI documentation alongside its use in underground markets.

What's the difference between fullz and combos?​

Combos are email:password pairs — one credential, no identity attached. Fullz are structured identity records — person-level completeness with verification attributes (DOB, SSN, address) that combos entirely lack. Combos fuel credential stuffing; fullz fuel identity impersonation and account takeover at verification layer. Combos can be MASS-produced from any breach; fullz require identity-field sources or assembly from richer data.

How are fullz made?​

Through five primary vectors: database breaches joining identity fields, infostealer malware capturing browser autofill profiles (the dominant modern source), payment skimmers capturing checkout/ATM form data, phishing kits designed to request identity fields, and aggregation from people-search/insider sources. The vector determines the record's shape — consistent schema fields suggest breach origin, machine fingerprints suggest infostealer origin, geographic clustering suggests skimmers.

Are fullz legal to possess?​

No — possession of stolen identity and payment data violates identity-fraud, unauthorized-access, and data-theft statutes in essentially every jurisdiction (in the US: CFAA, identity-theft statutes, 18 U.S.C. §1029 for payment instruments; equivalents exist everywhere). The data belongs to the identified individuals; possessing their stolen records is possession of contraband-adjacent evidence in every jurisdiction's framing. There is no "research exception" for hoarding real people's records — researchers work with sanitized, aggregated, or lawfully obtained datasets through institutional channels.

Why do people sell fullz if they're so valuable?​

Because freshness decay makes holding them irrational for most collectors (value melts daily), because most sellers can't convert records into money without operational exposure, and because the market structure — adversarial on every side per the economics section — means long-term holding rarely beats immediate liquidation. The sellers with the freshest data don't need public shops; the public shops sell what's left after the value has largely decayed.

How do I know if my data is in a fullz-style breach?​

Use breach-notification and monitoring channels: official breach notification emails where required by law, credit monitoring services (many breaches trigger court-mandated free monitoring), credit bureau freeze options (the nuclear-but-effective option), and reputable breach-corpus lookup services for historical exposure. If your SSN, DOB, and address combination has appeared in a known corpus: freeze credit, rotate reused passwords everywhere (not just the breached service), and treat any "your data is being sold" notifications you receive as phishing unless verified through official channels — the notification ecosystem is itself full of scams targeting breach victims.

Are "high balance fullz" listings real?​

The listings exist; the claims don't survive scrutiny. "Balance" is a moment-in-time account state that changes with every transaction — any balance listed at sale time decayed instantly. What exists: real records of people who HAD accounts, sometimes with institution names attached. What doesn't exist: verified live balance data sold publicly at scale (that would require persistent unauthorized access, at which point selling the record would be irrational versus using it). The phrase is marketing vocabulary targeting a specific buyer fantasy — the same fantasy every exit scam counts on.

Where To Go From Here​

You now have the full picture: anatomy (what's in the pack), taxonomy (how types differ), differentiation (vs combos/logs/dumps), source vectors (where they originate), decay economics (why freshness is everything), marketplace reality (why buying is structurally losing), and the rule that falls out of all of it. That's real understanding — acquired without purchasing a single record, which is the only way this knowledge holds its value.
BlackSec official channel: t.me/Blacksec_official — the only official channel we run. Drops, tradecraft, community. Anyone else using our name is running their own little operation.
Boards that pair with this guide:
  • Bins/CC — Freebie — BIN and card-data research threads where the taxonomy above gets applied practically
  • Gen / Checkers — validation-tooling discussions (for understanding detection and data-flow mechanics)
  • General Hacking — breach analysis, infostealer teardown discussions, CTI threads
  • Courses — the structured path: fraud typologies, detection engineering, how this whole ecosystem is studied professionally
Bottom line, one more time: never purchase CC or fullz from anyone. The market's defects are structural, the counterparties are guaranteed adversarial, and every dollar spent there buys identification rather than goods. Study the structures, keep your hands on your own keyboard, and let the people who ignored this rule fund the cautionary tales.
— BlackSec crew. Taxonomy current for 2026 collection ecosystems. The vector landscape evolves (stealer families rotate, breach shapes change): when your reading of live artifacts contradicts this page, trust the artifacts, update your mental model, and keep studying.