What Personal Data is Most Valuable to Hackers?

Hackers and cybercriminals place the highest value on data that’s hardest to replace or is most useful for fraud. While that obviously includes financial details and login credentials, it also includes medical records and identity documents such as passports or National Insurance numbers. Why? Some of this data can be resold multiple times on the dark web, making certain breaches far more damaging than others.
Why some data is worth more than others
In a word: permanence. Think about it like this: if an organisation accidentally exposes your password, and a hacker or cybercriminal gets access to it, that password is only useful for the time period between its exposure and you changing it. Once you’ve changed your password, in fact, the stolen information is almost completely useless.
So, if changing a password is easy, and that makes it a less valuable prospect for cybercriminals, the opposite is also true: the more permanent data becomes more highly prized. You can change a password, but you can’t change your date of birth or medical history.
Financial Information
Bank details and card numbers
No surprises here! Bank details and other financial data are among the most sought-after information for cybercriminals because they can immediately be used for the purchase of tangible goods. Most websites that handle such sensitive data take care to mask it through the use of tokens or hashes – encrypting your data so that even if it were to fall into the wrong hands, it would be close to useless. However, this isn’t always the case, and data breaches have previously involved the exposure of full card numbers, CVVs and sort codes – everything you’d need to complete a transaction.

Why financial data is quick to monetise… but quick to cancel
Banks and other organisations have been playing catch-up to the fraudsters for years, but now there are many secure processes in place that can deter malicious actors. For example, many banks offer a fast-tracked way to freeze or cancel cards and accounts that you believe have been compromised and employ large departments of anti-fraud experts. As a result, financial data could be less valuable to cybercriminals than you expect as a result of its impermanence.
Passwords and login credentials
The password reuse problem
Passwords are easy to change, so you’d think that they’d rank poorly in the eyes of cybercriminals. Unfortunately, even though changing login credentials is simple, our actual behaviour says otherwise: according to Forbes, a password is reused for as many as four accounts on average. Worse, 46% of people report having their password stolen within the past year. In light of those statistics, you can see why passwords, even if they’re simple to change, are considered quite valuable to cybercriminals.
‘Credential stuffing’ (in plain English)
Whatever your view on Artificial Intelligence (AI), there’s no question it’s transforming the world – for better and for worse. In the case of cybersecurity, AI is presenting a raft of new challenges against which organisations are sometimes ill-equipped to defend. It’s significantly boosted a technique called ‘credential stuffing,’ which involves cybercriminals trying your leaked account data in multiple sites as quickly as possible. That means logins exposed on one site can be quickly made useful on another, if you tend to reuse passwords.
Medical records
Why health data can be worth more than card details on the dark web
Where a bank card can be cancelled or reissued, the same can’t be said for medical records. If you suffered an illness or required medical attention, that – in terms of record-keeping, at least – becomes a permanent part of who you are. Additionally, medical records often include things like your name, date of birth, address and NHS number, all of which can be deployed in complex identity fraud schemes.

Insurance fraud and blackmail risk
The damage suffered as a result of your medical records being exposed isn’t always financial or material. In fact, the sensitivity of such information can be weaponised against you, potentially causing serious distress. For example, if your mental or reproductive health records are exposed, this information could be used as blackmail or for targeted harassment – both potentially lucrative avenues for malicious actors.
Identity documents (Passports, driving licence, National Insurance number)
Why this data is the most damaging long-term
You can reset a password. You can cancel a credit card. But you can’t change your National Insurance number. Once such identity documents have been exposed, it can be very difficult – or even impossible – to acquire new information that’s safe from malicious actors. That makes it even more important to only entrust such details to organisations with a proven record of data security.
Identity theft and loan/account fraud
Opening credit accounts, taking out loans, passing identity verification checks… all of this and more is possible with sophisticated identity theft techniques, many of which are made possible through the negligent exposure of data online. Victims of identity fraud will know that it can take months to clear your name in the eyes of banks and other organisations, which adds distress alongside the material damage victims can suffer.
Contact details and addresses
The exposure of your name and address may seem less consequential than other data mentioned in this article, especially if you already use your real name online, but this isn’t always the case. Malicious actors can use a process known as ‘data enrichment’ to execute their schemes. Typically, this involves collecting information from several sources and building a distinct profile that can be used for more severe crimes such as identity fraud. Names and addresses are useful building blocks in this process by themselves but can also be used to unlock more data in other account by answering security questions and passing other identity checks.

Protected characteristics
Bank account details and login credentials can be resold by cybercriminals – they might not use the information themselves, but instead ‘flip’ it to those who can. When it comes to protected characteristics such as sexuality, religion and health status, these cannot be resold in the same way. Instead, this information can prove valuable to malicious actors because of its potential use for blackmail, extortion and coercion. The Information Commissioner’s Office describes this information as ‘special category data,’ which receives greater protection under UK GDPR law due to its sensitivity.
How cybercriminals actually use or sell this data
Malicious actors can use this data in the following ways:
- Dark web marketplaces: The ‘dark web’ refers to websites that are hidden from search engines and are therefore much less accessible. As a result, they can often host illicit activity, such as the buying and selling of stolen data.
- Credential stuffing bots: Using complex algorithms and artificial intelligence, stolen data can be employed across the internet to gain access to as many accounts as possible.
- Phishing lists: If cybercriminals become aware that an individual is vulnerable to scams or blackmail attempts, they may include that individuals’ data in phishing lists. If you’ve noticed an uptick in the number of spam emails you’ve received, it’s possible your data has been exposed and added to a phishing list.
What should you do if your data was exposed?
If you find out that your data has been exposed online, it’s important to take action as soon as possible. You can find out how here.
Frequently Asked Questions
What is the most valuable data on the dark web?
Identity documents and medical records tend to command the highest prices, because unlike a password or bank card, they can't simply be cancelled or reissued. Financial data is stolen more often, but it loses its value quickly once a card is frozen — permanence is what really drives price on the dark web.
Why do cybercriminals want medical records if they can't sell them?
Medical records aren't valuable because they can be sold directly, but because they're permanent and detailed enough to support long-running identity fraud — combining your name, date of birth, address and NHS number. Sensitive details like mental or reproductive health history can also be used for blackmail or targeted harassment, which is a different kind of value altogether.
Is my address alone valuable to cybercriminals?
On its own, your name and address are relatively low value. The risk comes from "data enrichment," where cybercriminals combine your address with other leaked fragments from different breaches over time to build a fuller profile that can be used for identity fraud or to pass security checks.
How much is stolen personal data worth?
Prices vary by data type and change over time, but as a general rule, permanent and hard-to-replace data — like identity documents and medical records — is worth more than easily-cancelled data like card numbers. Rather than quote a specific figure, it's more useful to think about what a cybercriminals can actually do with the data, and for how long.
Can cybercriminals do anything with just my email address?
Yes — an email address alone can be used for phishing attempts, and if you've reused a password across multiple sites, it becomes a starting point for credential stuffing attacks. It's also a common building block in data enrichment, where it's combined with other leaked details to build a more complete profile of you.


