-
A threat actor is advertising millions of US consumer records for sale on a cybercriminal forum.
-
The seller offered a sample containing 10,000 records free and is charging $750 for the complete database.
-
There is no public evidence available yet about the source of this database and the contents of the records.

A threat actor is allegedly selling what they described as a “2026 US consumer database” holding 153,139,484 records. The seller wants $750 for the whole stash. But they’re giving potential buyers a sample of 10,000 records to check out before making a deal.
00sec, a threat intelligence service, spotted this listing and reported the same record count, sample size, and price. It also identified the forum seller as B666.
That’s the only solid information available at the time of reporting. The listing does not name a company, website, or service from which the seller obtained the data. It also does not explain what each record contains. So far, no public evidence ties the database to a specific breach or victim organization.
The $750 Price Stands Out
Price is one of the oddest components of this case. The cost for more than 153 million records amounts to $750, meaning that the cost of each million records is under five dollars. A low price does not prove that a dataset is fake. Still, the database may contain old or duplicate information.
Criminal marketplaces often recycle stolen data. Sellers can combine records from older breaches, public sources and other databases, then package them as a new product.
Recorded Future reported something really interesting, recycled or reposted card data rose from 19 percent in 2023 to 36 percent in 2024. That finding involved payment-card data, not this consumer database. It still shows why a large record count does not automatically mean a new breach.
153 Million Records Does Not Mean 153 Million People
The number also needs context. A database can contain more records than people. One person may appear several times. The seller does not explain what “record” means here. The 153,139,484 number is precise, but it is simply the number stated in the listing.
The same applies to the seller’s claim that the data comes from 2026. Without a verified sample or source, there is no way to confirm when the information was collected.
No Public Sample Analysis Yet
The offer of 10,000 sample records could help researchers test the claim. They could compare the sample with known breaches and look for duplicate records or old contact details.
However, no credible public evaluation of the sample has been discovered through the sources examined in this report. A few things still need clarification. What category of personal data does the database contain? Is it current? How many records are unique? Those answers matter more than the raw record count.
Do Not Confuse It with the IDScan Incident
The 153-million figure may sound familiar because another major data incident involved a similar number. Earlier this month, the Nexus cybercrime service claimed to hold more than 153 million U.S. and Canadian driver’s license records. It also advertised millions of other identity documents.
That case involves IDScan.net. KrebsOnSecurity reported that samples matched real driver’s licenses and traced the data to IDScan.net’s identity-verification services. The FBI launched an investigation into the matter. IDScan.net said they were also investigating unauthorized access.
IDScan.net published a security incident notice on September 4. The company says it got word that someone may have accessed some of its data without permission, and they’re still digging into what happened. There is no public evidence showing that the latest 153,139,484-record consumer database came from IDScan.net. Similar numbers alone do not link the two cases.
What the Listing could Mean
If this database truly has fresh and accurate consumer info, it could have serious impacts. Such a large pool of personal information is valuable to criminals because they could use it for phishing and identity theft. The danger depends on the fields inside the records.
Large database claims have appeared in other underground-market listings as well. In a separate case, a darknet seller claimed to have a 7TB Chinese auto finance database containing 700,000 records, highlighting how criminals continue to market large datasets to potential buyers.
At this stage, there is no verified evidence that the listing contains Social Security numbers, passwords, payment-card data, medical information or other highly sensitive details.
The claim may also involve recycled information. That would still create privacy risks, but it would be very different from a new breach affecting 153 million people. For now, the listing remains what it is, a threat actor claiming to have a large database for sale.
While 00sec has documented the listing, no independent researcher has verified the database itself. No affected company has been identified. And the seller has not named a source system. Also, no public sample analysis has established the database’s contents or age.
The only way to know if those records are legit, unique, and recent is for independent experts to test the sample. Until that happens, treat that huge number as just a claim from the marketplace, not solid proof of a breach.