Crime slang is blunt. Fullz is short for “full information”: a bundle that describes a whole person, not a single card number. Films turn that bundle into a neon shop. Court papers and fraud glossaries treat it as raw material for impersonation. This article defines the term, separates it from card dumps, and maps the harm — including the India-shaped version built around Aadhaar, PAN and a registered mobile. It is not a guide to find, buy or use stolen data.
What “fullz” actually means
Security glossaries converge on the same picture. A fullz package is a complete set of identifiers for one living person: legal name, date of birth, address, and a government number, often joined by bank or card details, phone, email, and answers to common security questions. In the United States the government number is usually a Social Security number. Completeness is the product. A card can be spent. A full package can be used to apply — new accounts, loans, tax filings, takeovers of existing logins.
The word looks plural. Sellers still speak of “a fullz” as one unit: one victim, one folder. That folder does not have to be fresh or accurate. Public reporting describes data stitched from breaches, phishing and older leaks. The method is not the point here. The durable fact is reuse. A bank can cancel a card number in days. A national identity number is not rotated like a password. The same package can be copied and used more than once, by more than one stranger, long after the first fraudulent charge is reversed.
That is why fullz sit in a different risk bucket from a leaked password. Reset the password and the door changes. The date of birth and the government ID stay on the form the lender already trusts.
Fullz versus dumps and CVV packs

Three labels get mashed into “my data leaked.” They are not the same goods. Dumps usually mean track data lifted from a card’s magnetic stripe — a narrow tool for counterfeit-card or swipe fraud. A CVV pack is typically the card number, expiry and the short code printed on the card: enough to attempt a card-not-present purchase. Fullz add the person around the card. Knowledge-based checks — previous address, mother’s family name, which lender you used — become guessable when the folder is thick enough.
The harm timeline differs too. Card fraud often prints itself on a statement within a billing cycle. Identity-led fraud may sit quiet: a loan in another city, a second SIM linked to a government ID, a tax return filed before the real one. The victim meets the damage at the credit bureau or the tax portal, not at the grocery till. Delay is part of the injury. So is repetition. Closing one bogus account does not delete the identifiers that opened it.
Where the harm lands
Documented fraud types are unglamorous. New-account fraud in the victim’s name. Account takeover of email or banking. Tax-refund fraud. Loans and device EMIs. Medical billing on someone else’s identity. Then synthetic identity fraud: a real government number mixed with a fabricated name or address to grow a credit file that never belonged to a real household. The U.S. Federal Reserve, in its payments-fraud papers around 2019–2020, called synthetic identity fraud a fast-growing financial crime. That is an American institutional claim, not an Indian official tally. The mechanism still travels. If onboarding trusts a number plus a form, a complete stolen set is built to walk through that door.
Money is only the first layer. The second is paperwork: bank letters, police complaints, bureau disputes, months of “please prove you are you.” The third is the follow-on scam. The U.S. Federal Trade Commission has warned that prior fraud victims are recycled onto “recovery” lists — callers posing as officials who already know the last case. A stolen phone number and a known loss become the script for the next hit. The FTC’s Consumer Sentinel Network Data Book for 2024, released in March 2025, recorded more than 1.1 million identity-theft reports and $12.5 billion in reported fraud losses in the United States. Treat those as U.S. complaint figures, not a global shop price list.
FACT: Fullz is criminal slang for a complete identity package — at minimum name, date of birth, address and a national ID number — not merely a stolen card. Card dumps and CVV records are narrower. In India, identity theft is addressed under IT Act Section 66C; money movement is reported through 1930 and the National Cyber Crime Reporting Portal. A cancelled card is not the same as a replaced Aadhaar or PAN.
The same package in an Indian stack
The English slang shows up in Indian fraud talk. The fields change. Name, parent’s name, address, date of birth, Aadhaar, PAN, account number, IFSC, registered mobile, sometimes a scan of a passport or driving licence — once those sit together, a call centre or an onboarding form can be convinced it is speaking to the account holder. Passwords rotate. Aadhaar and PAN do not rotate on a weekly cycle. That permanence is the harm.
In July 2026, public reports described an alleged Bank of Baroda data dump. The threat side claimed a large set of customer and internal files, including Aadhaar-linked fields. The bank’s public line was narrower: an employee email account was compromised, the incident was contained, and core banking systems were not accessed. This article does not verify the dump, price it, or map where files sat. The usable lesson is the bank’s own distinction — email-layer data can still feed convincing phishing even when the ledger itself was not opened.
Separate public investigations have described fake-KYC print networks that mimic government portals and generate counterfeit Aadhaar, PAN and birth-certificate templates. In April 2026, Ahmedabad cyber police announced arrests in an alleged racket that changed Aadhaar-linked mobiles and used AI-generated face clips to push KYC. Those are allegations and police claims, not convictions recited as folklore. The pattern is consistent: identity fragment, mobile control, onboarding gap. Fullz is the folder that tries to hold the fragments in one place.
Myth: a clean shop that sells “a person”
Cinema wants a catalogue and a checkout. Documented reality is messier. Stolen sets are described as circulating after breaches and on closed channels. Listings are not a consumer-protection market. Many are stale, duplicated, or bait — a second fraud against the person who thought they were buying a first fraud. Countdown pages that demand irreversible crypto for “proof your name is in the file” follow the same advance-fee shape already documented around fake hitman ads and fake “red room” paywalls. This site will not open that door.
A second myth: leak equals instant ruin. Sometimes a charge appears at once. Sometimes a synthetic line is cultivated for a long time. Sometimes the pack is too old to clear a modern check. A third myth common in India: “an Aadhaar number in a paste and the country collapses.” A number alone is not a finished attack. A number plus address, photo and a live mobile is how a phone call starts sounding official. The risk is social engineering powered by completeness, not a movie download bar.
Documented angle: why the file outlives the card
Payment credentials are designed to be replaced. National identifiers are designed to stay stable so the state and the bank can recognise you next year. U.S. explainers repeat that a new Social Security number is granted only in limited cases. India’s Aadhaar and PAN rules differ on paper; daily life is similar — you do not collect a new identity number after every headline. One leak can therefore feed more than one attempt, in more than one sector, without a new “hack.”
Civil complaints in other countries now spell the slang out in pleadings: name, address, card data, SSN, date of birth assembled as a fullz package. The word has left chat logs and entered legal English. That is evidence of harm-as-category, not a shopping review. Synthetic files add a cruel twist. The bureau record is half real, half invented. The person whose number was borrowed spends months proving a negative: “I did not open that line.” No extra statistic is required to see why the injury lasts longer than a reversed card payment.
India’s public rails for money-out events remain the same across this cluster of explainers: the 1930 helpline, the National Cyber Crime Reporting Portal, the bank’s published number — not a stranger who already knows your last four digits and wants a “verification fee.”
FAQ
What does fullz mean?
Criminal slang for a full identity package on one person: name, date of birth, address, government ID, often financial and contact fields. It is not a synonym for “any leaked password.”
Is a name and birthday enough?
Alone, they are a starting point. Combined with other leaked or public fields they can thicken into a package that answers verification questions. Completeness is what raises the harm.
What is the Indian equivalent?
The same logic with local fields: Aadhaar, PAN, bank account, registered mobile, address. The slang may stay English. The damage shows up in KYC, UPI/bank fraud and credit files.
Should I go looking for my name in stolen lists?
No. This article does not describe how. Pages that charge crypto to “check” a name are a common scam pattern. Use official bank channels, your credit report, UIDAI authentication history where relevant, 1930 and cybercrime.gov.in.
Is trading this data a crime?
Possessing, selling or using stolen identity data to open accounts or take loans is criminal conduct. In India, IT Act Section 66C addresses identity theft; cheating and forgery sit under other provisions. This is a harm explainer, not a charging manual.
Disclaimer
This is not a guide to visit the dark web, locate stolen-data listings, or buy “fullz.” Pages that demand cryptocurrency or fees to show stolen files, recover money, or “verify your leak” are often scams. Seeking or trafficking stolen identity data is a crime. If money has moved, use 1930 and the National Cyber Crime Reporting Portal, and call your bank on its published number. Vista Hub does not host leak files and does not verify underground listings.