
By Andréanne Bergeron, Security Researcher
You type in your email address for a 10% discount. You share your phone number to verify an account. You enter your name on a sign-up form. Each disclosure feels trivial because, in isolation, it is: an email address costs $0.0002 on the dark web, and a name costs about the same. Pair them together in a breach, and the price doesn’t double, it explodes. New research across 318 breaches reveals that stolen data bundles are systematically worth more than the sum of their parts.
Key Takeaways About the Value of Combining PII
- Personal data value is superadditive, meaning combined data is worth far more than the sum of its parts. 52% of multi-PII breaches sell for more than the additive sum of individual PII prices, even under conservative measurement.
- The specific combination of data types matters more than the quantity of data exposed; structure drives value more than size.
- The main risk is not individual data exposure, but data aggregation across multiple seemingly harmless sources.
- Everyday data disclosures (e.g., discounts, sign-up forms, loyalty programs) can become high-risk when combined over time.
Identity-First Threat Intelligence
Track Your Organization’s Cumulative Data Exposure Across Breaches
A breach of emails alone looks minor. Add phone numbers from a second incident and names from a third, and attackers hold the highest-value combination on the underground market — worth thousands of times more than its parts. Flare monitors dark web marketplaces, breach databases, and stealer logs to detect when your organization’s data is being aggregated across sources, before it’s weaponized for SIM-swapping, spear-phishing, or account takeover.
The Claim: “I Have Nothing to Hide”
“I have nothing to hide” is a common justification for dismissing concerns about PII. It reflects the belief that individual data points hold little value. In isolation, this assessment is not entirely inaccurate: on illicit markets, an email address or a name may be exchanged for only a fraction of a cent.
However, this perspective fundamentally misunderstands the dynamics through which data acquires value. Personal data operates multiplicatively rather than additively. In other words, when combined, otherwise trivial elements form coherent and highly exploitable profiles.
Our research team analyzed 348 documented security breaches in which we identified 88 distinct PII types and determined a per-user underground market price. The findings are unambiguous: stolen PII is not additive. Bundles of data are superadditive, meaning the whole is worth dramatically more than the sum of its parts (Read the detailed description of the methodology in What is the Cost of your Data on the Dark Web?).
The Commodity Myth: Why Cheap PIIs Are Deceiving You
The commonly cited prices of personal data are well known: credit card details, email addresses, and social security numbers sell for a few dollars or even cents. While it is interesting to know the value of each PII, it offers limited insight into the true impact of data breaches.
We know that attackers acquire and exploit data in bundles, not in isolation, such as through an automated Telegram bot that takes one victim’s email and constructs a fuller profile from multiple breach databases.
Our dataset confirms this across 316 usable breach records. Prices derived from breaches exposing a single type of PII vary widely (spanning several orders of magnitude) as shown in the table below.

Email addresses and SSNs are worth very little by themselves. It’s not that these types are worthless, it’s that their value is almost entirely conditional on what they’re paired with. Sell an email address alone and you have a spam list. Add a name and you have a spear-phishing target. Add a phone number and you have a SIM-swap vector. The combination is categorically more dangerous.
Assessing The Bundle Surplus
Measuring the Gap
We define the bundle surplus as the difference between the observed price of a data breach and the price we would expect if we simply added up the value of each data type on its own.
This is a conservative measure for two reasons. First, many breaches include data types for which we do not have reliable standalone prices, so their value is not included in the calculation. Second, when the surplus is positive, it already means the breach is more valuable than the sum of known individual parts, even before accounting for missing values.
The results show that in 52% of breaches involving multiple PII types, the actual market price exceeded what you’d get by simply adding up the individual prices of each data type. Attackers already account for this when buying stolen data.
The Pairing Map: Which Combinations Create Value
To validate our approach, we compared multiple regression models and found that interactions between PII types explain substantially more variation in breach value than either individual PII types or bundle size alone (see the Methodology section below for details). We therefore extended the analysis to identify which specific PII combinations generate the highest value when they appear together.
With nearly as many variables as observations, we could not use the standard regression approach since it can no longer tell which interactions are real and which are noise. That is why we used Lasso, a technique that automatically discards weak or redundant variables and keeps only the ones doing genuine predictive work. Of 195 candidate features, 47 survived. One pair (Genders × Marital statuses) was strong enough to show up as significant even without this filtering, making it the most robustly supported pair in the dataset.
Pairing Map
| PII Pair | Effect | Std. Coef. |
|---|---|---|
| Complements | ||
| Email addresses × Phone numbers | ▲ Complement | +1.899 |
| Email addresses × Names | ▲ Complement | +0.733 |
| Credit cards × Names | ▲ Complement | +0.536 |
| Credit cards × Email addresses | ▲ Complement | +0.372 |
| Password × Phone numbers | ▲ Complement | +0.177 |
| Account balances × Names | ▲ Complement | +0.139 |
| Dates of birth × Physical addresses | ▲ Complement | +0.104 |
| Account balances × Physical addresses | ▲ Complement | +0.059 |
| Password × Physical addresses | ▲ Complement | +0.058 |
| Genders × Job titles | ▲ Complement | +0.046 |
| Genders × Marital statuses | ▲ Complement | +0.031★ |
| Substitutes | ||
| Job titles × Physical addresses | ▼ Substitute | −0.157 |
| Genders × Government issued IDs | ▼ Substitute | −0.106 |
| Dates of birth × Usernames | ▼ Substitute | −0.100 |
| Device info × Email addresses | ▼ Substitute | −0.057 |
| Phone numbers × Photos | ▼ Substitute | −0.018 |
To note: Genders × Marital statuses also significant under standard OLS (p=0.006), the only interaction robust enough to survive without regularization.
Reading the Pairing Map
The strongest pair (email × phone number (β=+1.899)) isn’t surprising once you trace the attack chain. Email alone enables phishing. Phone alone enables SMS scams. Together they unlock 2FA bypass via SIM-swapping, multi-channel credential stuffing, and voice phishing with email confirmation. The combination is qualitatively more dangerous than either component.
Email × name (+0.733) reflects spear-phishing readiness as personalized attacks convert at dramatically higher rates than generic ones.
Credit cards × names (+0.536) is the card-present fraud enabler. A card number alone works online. Add a name and it passes physical point-of-sale verification which is a qualitatively different and typically more profitable fraud vector.
Account balances × names (+0.139) and account balances × physical addresses (+0.059) together tell the financial fraud story: balance data identifies which accounts are worth targeting; identity and address data provide the authentication material to execute takeover. Neither layer is sufficient alone.
Genders × Marital statuses deserve attention precisely because they survived both Lasso and standard OLS. On its own this combination seems trivial as they are demographic metadata. The two PII together enable precise audience segmentation for social engineering campaigns, insurance fraud profiling, and synthetic identity construction that mimics real demographic patterns.
The Substitute Pairs: When More Data Destroys Value
Not all data combinations create value, some actually reduce it. When two data types tend to appear together in low-value breaches, their co-occurrence becomes a signal that the breach probably isn’t very useful to attackers.
Job titles combined with physical addresses illustrate this clearly. This pairing is typical of HR datasets or LinkedIn-style scrapes: professional background information without passwords, financial data, or authentication credentials. While such data may have value in certain contexts, it is not operationally useful for attackers on its own. Lacking any actionable elements, the market tends to treat it as low-value “filler” data.
Recommendations for Security Teams
The superadditive nature of PII has practical implications for how organizations classify, protect, and respond to data exposure.
- Rethink breach severity scoring. Most breach-impact assessments weight the number of records exposed. This research shows that combination matters more than count. A breach of 10,000 records containing email, phone number, and name (β = +1.899 and +0.733 respectively) may represent a higher realized threat than a breach of 100,000 records containing only email addresses. Severity models should account for which fields co-occur in the same record, not just which fields were exposed.
- Segment and isolate high-value pairings. The pairing map identifies which combinations attackers value most. Where possible, avoid storing complementary PII types in the same database, the same table, or under the same access controls. If email addresses and phone numbers must coexist, treat that store as a high-value target regardless of whether it contains traditionally “sensitive” fields like financial data.
- Monitor for cross-source aggregation. A breach of your loyalty program (names + emails) combined with a breach of your authentication system (emails + phone numbers) gives an attacker the full high-value triple without either breach appearing severe on its own. Track your organization’s cumulative exposure across incidents, not just the severity of each one independently.
- Communicate risk in aggregation terms. When justifying security investment to leadership, the superadditive framework provides concrete language: “Our customer database pairs email, phone, and name in the same record for 4 million users. Based on underground market pricing, that combination is worth orders of magnitude more per record than any single field alone. The breach impact model changes accordingly.” This reframes data protection from a compliance checkbox into a quantifiable economic exposure.
The Bottom Line
A single data point, like a lone jigsaw piece, reveals little and appears worthless. This is why individuals routinely disclose information such as email addresses, names, and phone numbers to apps, to websites, to loyalty cards, to online forms that promise a 10% discount.
However, the value of personal data emerges through its aggregation. While an email address alone may be worth a fraction of a cent on illicit markets, its combination with other identifiers creates a coherent and exploitable profile. Our findings indicate that such combinations can be worth orders of magnitude more than the sum of their individual parts.
But when those pieces end up together, something changes. Our research shows that the combination of email, name, and phone number can fetch thousands of times its additive value on underground markets. Attackers do not buy your data for what each piece is worth alone but rather buy it for what it unlocks together. The claim “I have nothing to hide” assumes that data stays as isolated as the moment you shared it, which is not the case.
Identity-First Threat Intelligence
Track Your Organization’s Cumulative Data Exposure Across Breaches
A breach of emails alone looks minor. Add phone numbers from a second incident and names from a third, and attackers hold the highest-value combination on the underground market — worth thousands of times more than its parts. Flare monitors dark web marketplaces, breach databases, and stealer logs to detect when your organization’s data is being aggregated across sources, before it’s weaponized for SIM-swapping, spear-phishing, or account takeover.
Methodology
We ran three regression models to isolate exactly where breach valuation models break down.

The jump from the bundle size model to the pairwise interactions model tells the whole story. Adding bundle size barely moves the needle as R² goes from 0.722 to 0.737. In other words, the market doesn’t care much whether a breach has five or eight PIIs if they are the wrong combination.
Adding pairwise interactions (i.e. which specific PIIs appear together) pushes R² to 0.914 and drops AIC by 165 points. To put it simply, 19.2% of breach price variance is explained purely by bundle composition. The bundling is much more important than the PII by itself. It is the single largest driver of price.





