SardineCon SF/2026

Learn More

What is Fullz?

SUBSCRIBE

Fullz is criminal slang for a complete stolen identity package: name, address, date of birth, a government ID or Social Security number, and financial or card data. It sells for far more than card data alone because it unlocks higher-value fraud, from synthetic identities to full account takeovers.

What is fullz, in plain English?

Fullz, a slang shortening of full information, is a bundle that describes a whole person, not just a card. A typical package pairs the basics, name, address, and date of birth, with a government identifier like a Social Security number, and often adds financial details, card data, and answers to common security questions. It is enough to impersonate someone convincingly.

That completeness is the point. Card data alone lets a criminal spend until the card is blocked, but fullz lets them become the victim in the eyes of a lender, a bank, or an onboarding flow. It is the difference between stealing a purchase and stealing an identity.

In the fraud economy, fullz is a premium product. It is priced above dumps because it opens doors that card data cannot: creating synthetic identities, taking over existing accounts, opening new accounts, and abusing loans or buy-now-pay-later credit. Finding fullz in a breach is a warning about the application and takeover fraud that will follow.

Fullz versus a dump

What changes

Dump

Fullz

What it contains

Card stripe data only

A full identity plus financial and card data

What it enables

Cloning cards to spend in person

Synthetic identity, account takeover, new-account and loan fraud

Channel

Card-present at swipe terminals

Applications, onboarding, and account access

Value to criminals

Cheaper, narrow use

Pricier, unlocks higher-value fraud

What it looks like in practice

In practice

A lender sees a run of new loan applications that all sail through identity checks. Each one has a matching name, address, date of birth, and government ID, and each answers the knowledge-based questions correctly on the first try. On paper they look like well-documented, low-risk applicants.

The common thread is that the data came from the same batch of fullz sold after a breach. The fraudsters are not guessing; they hold complete identities, so the usual verification barely slows them. The team only spots the ring by linking the applications through shared devices, reused phone numbers, and a burst of activity from a narrow set of sources.

Why it matters to operators

Fullz is what makes application and onboarding fraud so hard to stop. When an attacker holds a complete, real identity, document checks and knowledge-based questions pass cleanly, so a program that leans only on data matching will wave the fraud straight through. The defense has to shift toward device, behavior, and linkage signals that expose the fraudster behind the borrowed identity.

It also reframes what a breach means. If fullz is circulating, the risk is not limited to card spending; it points to a coming wave of new accounts, takeovers, and synthetic identities. Treating a fullz exposure as an early warning lets a team tighten onboarding and takeover controls before the downstream fraud arrives.

What to watch in the data

  • Too-perfect applications. New accounts or loans where every identity field matches and every knowledge question passes can signal fullz, not genuine applicants.
  • Shared infrastructure. Distinct identities linked by the same device, IP, phone, or email pattern point to one operator working a batch.
  • Post-breach surge. A rise in application or takeover attempts after a known breach suggests the stolen fullz are being monetized.
  • Synthetic blends. Real identifiers mixed with slightly-off details can mean fullz being used to build synthetic identities.
  • Cross-product reuse. The same identity appearing across account opening, lending, and takeover attempts is a fullz footprint.

Quick questions

How is fullz different from a dump?

A dump is just card stripe data, good for cloning cards. Fullz is a complete identity that enables account takeover, new-account fraud, and synthetic identities. Fullz is broader, pricier, and more dangerous downstream.

What is typically inside a fullz package?

Usually a name, address, and date of birth, plus a government identifier such as a Social Security number, and often card or bank data and answers to security questions. Enough to impersonate the victim.

Why does fullz cost more on criminal markets?

Because it unlocks higher-value fraud than card data alone. With a full identity, a criminal can open accounts, take over existing ones, and secure loans or credit, not just make purchases.

How does fullz feed synthetic identity fraud?

Fraudsters combine real elements from fullz, like a genuine Social Security number, with fabricated details to build a new identity that passes checks but does not correspond to a real person.

Why does finding fullz in a breach matter?

It signals downstream risk. Fullz points to coming application fraud, account takeover, and synthetic identity schemes, so it is an early warning to tighten onboarding and takeover controls.

Can identity verification alone stop fullz fraud?

Not reliably. Because the identity data is real and complete, matching checks pass. Catching it usually requires device, behavior, and linkage signals that reveal the fraudster behind the identity.

Go deeper

What to know alongside Fullz