Personal information value is not an abstract idea. On dark web marketplaces, a stolen identity has an actual price tag, a specific figure someone is willing to pay for details you probably think of as private but unremarkable.
Your name alone is worth very little. Your name paired with your phone number, your Aadhaar or PAN details, and your address is a different matter entirely, a package criminals actively buy and sell.
Most people never think about this until something goes wrong.
This post covers what makes your information identifiable in the first place, what your personal data is actually worth and who is buying it, how identity theft and impersonation happen at scale, and what synthetic identity fraud is and why it is so hard to detect. It is part of our wider guide to what hackers actually want from you.
What Makes Your Information Identifiable?
A handful of details make you specifically identifiable rather than anonymous: your full name, phone number, national ID, email address, and home address.
In India, your Aadhaar number and PAN function the way a Social Security number does elsewhere, a single identifier that unlocks banking, taxation, and government services when paired with the right supporting details.
None of these details are dangerous in isolation. A phone number alone reveals little. A phone number paired with a name, a date of birth, and an address becomes something criminals can build an entire fraudulent identity around.
This is exactly why a single data breach rarely feels urgent on its own, and why the real damage often comes from combining several smaller leaks into one complete profile.
Understanding personal information value this way, as something that grows with completeness rather than existing as a single fixed number, changes how seriously a single leaked field deserves to be taken.

What Is Your Personal Data Actually Worth, and Who Is Buying It?
UnitedHealth confirmed in January 2025 that the Change Healthcare data breach in the US had affected approximately 190 million people, the largest healthcare data breach ever recorded there, exposing names, national ID numbers, medical records, and payment details.
Stolen personal data sold on dark web markets accounts for more than 60 percent of identity fraud cases in the US, particularly identifiers and health records, according to Snappt’s Identity Fraud Statistics research for 2026.
Buyers range from individual fraudsters running small-scale scams to organised groups assembling thousands of profiles at once, since a complete identity package is worth considerably more than any single data point sold alone.
This is the clearest illustration of personal information value in practice: the price rises sharply once fragments are combined into something a criminal can actually use to impersonate you convincingly.
Indian personal data faces the same underlying market, Aadhaar and PAN details combined with banking information have real resale value to criminals running UPI fraud and loan fraud schemes, even where the exact pricing data is not always published.
The mechanism travels even where the exact price list does not. A criminal in any country wants the same combination, enough identifying detail to convincingly pass as you somewhere that matters.
This connects closely to the wider pattern covered in more depth in our guide to phishing, smishing and vishing and how to spot every type of fake message, since phishing is one of the most common ways this data gets harvested in the first place.

How Do Identity Theft and Impersonation Happen at Scale?
Once a criminal has enough identifying details, opening a fraudulent account, applying for a loan, or filing a false tax claim in your name becomes a matter of hours rather than days.
None of this requires the criminal to ever meet you, call you, or interact with you directly. The entire crime can be committed using only the data itself.
This is precisely where personal information value turns from an abstract market price into a direct financial loss for the person whose details were actually stolen.
Automated tools now let a single operator run this process against thousands of stolen profiles simultaneously, applying the same fraudulent template to each one and simply keeping whichever attempts succeed.
Volume, not precision, is the strategy. A success rate of just a few percent still produces real profit when the underlying attempt costs almost nothing to run at scale.
This mirrors the SIM-based version of the same crime covered in more depth in our guide to how criminals take over your phone number through SIM swap attacks, since a hijacked phone number is often the final piece needed to complete an identity takeover.
If you discover fraudulent activity carried out using your identity, report it as soon as possible through India’s National Cyber Crime Reporting Portal or the 1930 helpline.

What Is Synthetic Identity Fraud, and Why Is It Hard to Detect?
Synthetic identity fraud combines a real fragment, often a genuine national ID number, with fabricated details around it, a fake name, a fake date of birth, a fabricated address, to create a person who does not actually exist.
This is precisely what makes it so hard to catch. A synthetic identity has no existing credit history to contradict it, and no real person is actively watching for fraudulent activity under a name they never had.
A synthetic identity can be built up gradually over months, establishing what looks like a legitimate financial history before being used for a single large fraudulent transaction.
This patient version of the crime is often more profitable per identity than a quick, immediate fraud attempt, which is part of why synthetic identity fraud has grown steadily rather than faded as detection tools have improved.
The Identity Theft Resource Center offers free victim assistance and plain-language guidance for anyone trying to work out whether their information has been used this way.
Checking haveibeenpwned.com today to see whether your email has appeared in a known data breach takes less than a minute and is worth doing regardless of whether you suspect anything specific.
Recovering from identity theft once it has already happened is a longer process, covered step by step in our guide to your identity was stolen, here’s the step-by-step recovery plan.

Frequently Asked Questions
How much is my personal information actually worth to a criminal?
It depends on completeness. A name alone is worth very little, while a full package with ID numbers, address, and banking details can be worth considerably more on dark web markets.
Can I check if my data has already been leaked in a breach?
Yes. Checking haveibeenpwned.com with your email address takes under a minute and shows whether your information has appeared in a known data breach.
What is synthetic identity fraud exactly?
It combines one real detail, often a genuine ID number, with fabricated information to create a person who does not exist, which makes it particularly hard for banks and credit systems to detect.
What This Comes Down To
Your personal information has a price, and criminals know exactly what it is worth. Knowing what makes you identifiable is the first real step toward protecting it.
The one habit that helps most: check haveibeenpwned.com today, and treat any request for your Aadhaar, PAN, or banking details with the same caution you would apply to handing over cash.
If this was useful, share it with someone who needs to know.
