The quiet seizures: how the SSNDOB takedown dismantled a data broker for identity thieves
When federal agents seized four domains belonging to the SSNDOB Marketplace in June 2022, there were no dramatic raids on servers hidden behind Tor and no headline-grabbing hauls of narcotics. The operation quietly cut off a service that had sold names, dates of birth and Social Security numbers for roughly 24 million Americans.
A marketplace built on identities
SSNDOB was not a drug market or a carding bazaar in the usual sense. It was a lookup service: buyers paid between small sums and hundreds of dollars to pull Social Security numbers, birthdates and background data on almost anyone in the United States. According to the Justice Department, the marketplace generated more than $19 million in sales revenue over its lifetime (US v. Chychasov, DOJ case page). The customer base tells its own story. Blockchain analysis by Chainalysis found SSNDOB processed over $22 million in bitcoin since 2015, with a median purchase of about $220 but individual transactions reaching $100,000 (CyberScoop). Those are not casual shoppers; those are fraud operators stocking up.Where the data came from
Security journalist Brian Krebs documented years earlier that SSNDOB's operators ran a small but potent botnet embedded inside some of America's largest data brokers, including LexisNexis, Dun & Bradstreet and Kroll Background America (KrebsOnSecurity). The intrusions went undetected for months. That supply chain is what made SSNDOB dangerous. Rather than reselling dumps from public breaches, the service could query authoritative records directly from aggregators that hold files on nearly every US adult. A leaked copy of its own database showed more than 1,300 customers had spent hundreds of thousands of dollars pulling records on over four million Americans as far back as 2013. The service also licensed API access to high-volume resellers, which reliably out-earned all manual lookups combined. In practice, SSNDOB became wholesale infrastructure for the identity theft economy.The coordinated takedown
On June 7, 2022, seizure orders were executed against ssndob.ws, ssndob.vip, ssndob.club and blackjob.biz, effectively ceasing operations. The FBI and IRS Criminal Investigation led the effort in close cooperation with authorities in Cyprus, where police seized physical servers, and Latvia (DOJ press release). Court documents describe administrators who advertised on criminal forums, provided customer support, monitored deposits, rotated domains, scattered servers across countries and required bitcoin payment. An indictment followed in February 2022. Administrator Vitalii Chychasov was arrested in Hungary in March 2022, pleaded guilty in August 2023 and was sentenced to eight years in prison that November, with $5 million forfeited.Identity theft can have a devastating impact on a victim's long-term emotional and financial health, IRS-CI special agent Darrell Waldon said at the time of the seizure.
Why these cases get less attention
Seizures of drug markets like Hydra dominate headlines because the scale is visceral: tons of narcotics, millions of transactions, visible harm. Data brokers like SSNDOB operate differently, and their victims rarely know they have been harmed at all. There is also no single dramatic victim. When a Social Security number is sold, it surfaces months later as a fraudulent loan, a hijacked tax refund or an account opened in someone else's name. The connection back to the original sale is nearly invisible, so the story never becomes personal. Finally, these services avoid the aesthetics that draw coverage. SSNDOB looked like a mundane e-commerce site with search boxes and support tickets, not a shadowy bazaar. Boring interfaces, it turns out, make for quiet takedowns:- No flashy listings, just database queries priced per record
- Victims who often never learn their data was traded
- Harm that surfaces downstream, detached from the source
- Mainstream infrastructure rather than Tor-only hidden services