Skip to main content
    All Blog articles
    Data & Privacy
    13 min read

    The Company That Sold Your Grandmother to Scammers (For Nine Years)

    Epsilon knowingly sold data on 30 million consumers to scammers who targeted the elderly. For nine years. Even after their clients got arrested. DOJ settlement: $150 million. Two executives sentenced to prison.

    Author
    By Catherine “Cat” Karow
    Published
    Published December 27, 2025
    Updated
    Updated May 10, 2026
    Data & Privacy

    ZoraSafe Blog

    The Company That Sold Your Grandmother to Scammers (For Nine Years)

    The Business Model

    Let me tell you about a business unit called "Direct to Consumer."

    Sounds innocuous, right? Like maybe they help companies send coupons. Maybe some email marketing. The kind of corporate-speak that puts you to sleep.

    Here's what "Direct to Consumer" actually meant at Epsilon Data Management:

    Selling lists of elderly Americans to criminals who would steal their money.

    For nine years.

    While knowing exactly what was happening.

    Even after their clients got arrested.

    This isn't speculation. This isn't alleged. In 2021, Epsilon admitted it as part of a $150 million settlement with the Department of Justice. In 2024, a federal jury convicted two of their executives. In February 2025, a federal judge sentenced them to prison.

    Crime pays. Especially when your victims are old.


    How It Worked

    Epsilon's headquarters is in Irving, Texas. Their main sales office is in Westminster, Colorado. They specialize in something called "data modeling"—using algorithms to predict which consumers are most likely to respond to marketing.

    Legitimate companies use this for things like figuring out who might want to buy a new car. Or who's in the market for a vacation.

    Epsilon's "Direct to Consumer" unit had a different specialty.

    According to DOJ court documents, they developed models to identify "opportunity seekers"—a charming industry term for people who respond to mail offers.

    In plain English: They built algorithms specifically designed to find people most likely to fall for scams. And then they sold that list to scammers.


    The Scams

    Epsilon's criminal clients ran two main types of fraud:

    The Sweepstakes Scam

    You know those letters that say "CONGRATULATIONS! YOU'VE WON $2.5 MILLION!"?

    According to the indictment, these mailings "falsely appeared to be personalized, formal communications from a government agency, law firm, or other official entity."

    They told victims they'd won a sweepstakes or contest. All they had to do to claim their winnings was pay a small "processing fee" or "tax."

    Victims who paid the fee received nothing. Well, that's not quite true—they received "a barrage of additional solicitations making similar false promises."

    Because once you've proven you'll pay, you get added to the "sucker list" and sold again.

    The Astrology Scam

    These mailings promised that a "psychic" had received a personalized vision about the recipient. For a fee, victims could receive individualized astrological services or "unique, supernatural objects."

    In reality, the mailings were mass-produced. The "personalized visions" were form letters. The supernatural objects were worthless trinkets.

    But to an elderly person living alone, receiving what looks like a personal message from someone who cares about their future? That's a powerful psychological hook.

    Epsilon knew this. Their algorithms were designed to find exactly these people.


    They Knew

    I want to be absolutely clear about this: Epsilon employees knew they were helping criminals steal from the elderly.

    Read that again.

    Their clients were getting arrested.

    Their clients were getting charged.

    Their clients were getting convicted.

    And Epsilon kept selling to them anyway.

    Here's how the Lawfare analysis described it:

    "Due to their regular interaction with the fraudulent 'opportunistic' clients, the Employees were familiar with the clients' practices, as well as their deceptive solicitations."

    They weren't confused. They weren't fooled. They knew exactly what their clients were doing. And they took their money anyway.


    The Numbers

    Let me give you a sense of scale.

    Metric Data
    Time period July 2008 to July 2017 (9 years)
    Victims' data sold More than 30 million consumers
    Fraud schemes supplied Dozens of clients

    One single client:

    • Received nearly 100 lists from Epsilon
    • Defrauded 218,000 victims
    • Stole $23.7 million
    • Had victims who were scammed 20+ times each—more than 12,000 of them

    Let me repeat that last part: Over twelve thousand elderly people were scammed twenty or more times by the same scheme. Not different scams—the same one.

    How is that possible?

    Because once you respond to a scam, your name goes on a special list. Industry insiders call these "mooch lists" or "sucker lists." The data brokers track who's already been victimized, and they sell that information to other scammers.

    Translation: They used what they learned from scammers to make their entire business better at targeting vulnerable people.


    The Executives

    In June 2021, while Epsilon was signing its deferred prosecution agreement, the DOJ also indicted two individuals:

    Robert Reger, 57, Boulder, Colorado

    • Worked at Epsilon from 2005 to 2017
    • Built and led the "Direct to Consumer" unit
    • Rose to Senior Vice President
    • The jury found he "intentionally joined in the conspiracy and had specific intent to defraud victims"

    David Lytle, 64, Leawood, Kansas

    • Worked at Epsilon from 2012 to 2018
    • Business Development Manager for the Direct to Consumer unit
    • Recruited clients—including the fraudulent ones
    • "Responsible for signing up many of the clients engaged in fraud"

    In May 2024, after a two-week trial, a federal jury convicted both men on:

    • Conspiracy to commit mail and wire fraud
    • Seven counts of substantive mail fraud

    At trial, "elderly victims and their adult children testified about the scam letters victims received falsely promising cash prizes."

    The Sentences (February 2025):

    Executive Sentence
    Robert Reger 10 years in prison
    David Lytle 4 years in prison

    A third executive, Vice President Steven Fritz Kessler, pleaded guilty in 2018 to conspiracy to commit mail fraud. He received five years' probation and a $29,000 fine.


    The Corporate Penalty

    Now let's talk about what happened to Epsilon—the company.

    In January 2021, Epsilon entered into a Deferred Prosecution Agreement with the DOJ.

    What does "deferred prosecution" mean? It means no trial. It means no public court battle. It means Epsilon admits guilt, pays a fine, and promises to do better.

    The fine: $150 million total

    • $127.5 million for victim compensation
    • $22.5 million criminal penalty

    Context for that fine:

    • Epsilon's annual revenue: approximately $2.1 billion
    • The fine represented less than 10% of one year's revenue
    • The criminal penalty ($22.5 million) was actually less than the base fine recommended under sentencing guidelines ($25 million)

    What Epsilon agreed to do:

    • Pay for a claims administrator to distribute victim compensation
    • Implement "compliance measures" to prevent future fraud
    • Allow consumers to request their information not be sold

    What Epsilon did NOT have to do:

    • Go to trial
    • Admit wrongdoing in open court
    • Face any restriction on their business operations

    The victim compensation results:

    • $122 million has been returned to more than 200,000 victims
    • Quick math: That's about $610 per victim on average.

    Meanwhile, just ONE of Epsilon's fraudster clients stole $23.7 million from 218,000 people—an average of $109 each. And that's one client out of dozens.


    The New Owner

    Here's where it gets really interesting.

    In 2019—after the crimes occurred but before the DOJ settlement was announced—Publicis Groupe acquired Epsilon for $4.4 billion.

    Publicis is the world's largest advertising company. They're a French multinational with a market cap of tens of billions of dollars. Their clients include some of the biggest brands on Earth.

    When the DOJ settlement was announced in 2021, Publicis issued a careful statement noting that the events occurred before their acquisition, and that the previous owner (Alliance Data Systems) had indemnified them for all costs.

    Translation: "Not our problem. The old owners are paying."

    But Publicis kept Epsilon. In fact, they made Epsilon central to their entire business strategy.

    According to Publicis's own announcements:

    • Epsilon is "at the core" of Publicis Groupe
    • Epsilon became their "unique data-tech platform"
    • Epsilon is "embedded in more than half of Publicis Groupe's top 30 accounts"
    • Epsilon's CORE ID platform represents "200+ million people"

    In March 2025, Publicis acquired Lotame to strengthen Epsilon further. Combined, they claim to reach 91% of adult internet users worldwide with access to 4 billion customer profiles.

    Epsilon's CEO Bryan Kennedy retired in 2021—the same year the DOJ settlement was announced.

    The company marches on.


    Why This Matters

    You might be thinking: "Okay, but they got caught. They paid a fine. Two executives went to prison. Justice was served."

    Was it?

    Let's review:

    • Nine years of knowingly selling elderly people to scammers
    • At least 30 million consumers' data compromised
    • Over 200,000 identified victims
    • Tens of millions of dollars stolen
    • Two executives imprisoned (good!)
    • Corporate fine that amounts to pocket change
    • Company acquired for $4.4 billion and still operating
    • Now has access to 91% of adult internet users worldwide

    The two executives who went to prison are a rare exception. In most data broker cases, no individuals face consequences at all. The company pays a fine, issues a press release about their commitment to compliance, and continues operating.

    And the data? The algorithms? The "models" that identify vulnerable people?

    Those are still out there. Still being refined. Still being sold.


    The Bigger Pattern

    Epsilon isn't unique. Remember the research from Article 1?

    In 2007, the New York Times exposed a company called InfoUSA selling lists with names like:

    • "Suffering Seniors" (4.7 million people with cancer or Alzheimer's)
    • "Elderly Opportunity Seekers" (3.3 million older people "looking for ways to make money")
    • "Oldies but Goodies" (500,000 gamblers over 55)

    The list descriptions literally said: "These people are gullible. They want to believe that their luck can change."

    In 2021, KBM Group—another data broker—paid a $42 million settlement for the same pattern of behavior: selling consumer lists to elder fraud schemes.

    This isn't a few bad apples. This is a business model.

    Data brokers have discovered that elderly people:

    • Often have savings
    • May have cognitive decline
    • Are more trusting of official-looking mail
    • Are frequently lonely and isolated
    • Are less likely to report fraud (shame, confusion, or not wanting to worry family)

    And data brokers have built sophisticated tools to identify exactly these people and sell access to them.

    The fraud schemes couldn't exist at scale without the data brokers. The data brokers couldn't exist without the fraud schemes providing them with ever-more-refined targeting data.

    It's a symbiotic relationship. One that destroys lives for profit.


    Protecting Your Family

    If you have elderly relatives:

    1. Talk to them about mail scams. Explain that legitimate sweepstakes don't require fees. Real psychics don't send mass mail. Government agencies don't demand payment via mail.

    2. Help them opt out. Go through the major data broker opt-out processes together. It's tedious, but it reduces the volume of targeting.

    3. Monitor their mail. If possible, help review what's coming in. Look for the warning signs: urgent language, requests for fees, promises that seem too good to be true.

    4. Set up financial safeguards. Talk to their bank about fraud alerts. Consider setting up account monitoring.

    5. Report fraud. If they've been victimized, report it to:

    • National Elder Fraud Hotline: 1-833-FRAUD-11 (1-833-372-8311)
    • FTC: reportfraud.ftc.gov
    • Your state's attorney general

    The Uncomfortable Truth

    We want to believe there are guardrails. That companies can't just... do this. That there are laws, regulations, oversight.

    The Epsilon case proves otherwise.

    For nine years, a major American corporation knowingly facilitated elder fraud. Multiple employees knew. Multiple executives participated. The company's own systems tracked what was happening.

    And when they finally got caught?

    Two executives went to prison. The company paid a fine smaller than its annual revenue. A French advertising conglomerate bought them for $4.4 billion. And they're still operating today, with data on hundreds of millions of people.

    That's not a failure of the system.

    That IS the system.


    Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform protecting families and seniors from scams and digital threats. She has 20+ years in cybersecurity, including roles at Apple, the White House OCIO, and GuidePoint Security. Follow The Shield Blog for more investigations into the companies that profit from your data.


    Sources

    • U.S. Department of Justice, "Marketing Company Agrees to Pay $150 Million for Facilitating Elder Fraud Schemes" (January 2021)
    • U.S. Department of Justice, "Former Senior Executive and Former Sales Manager Convicted of Selling Data on Millions of U.S. Consumers to Perpetrators of Mail Fraud Schemes" (May 2024)
    • U.S. Department of Justice, "Epsilon Senior Executive and Sales Manager Both Sentenced for Selling Data on Millions of U.S. Consumers to Fraudsters" (September 2024)
    • Lawfare, "Data Brokers, Elder Fraud, and Justice Department Investigations" (January 2023)
    • CBS News Colorado, "Former Colorado data company executive convicted of mail and wire fraud, sold data on millions of people" (June 2024)
    • AARP, "Epsilon to Pay $150M For Helping Facilitate Elder Fraud" (January 2021)
    • Denver Post, "Massive marketing company to pay $150 million for facilitating elder fraud scheme" (January 2021)
    • Publicis Groupe, "Publicis Groupe Finalizes the Acquisition of Epsilon" (July 2019)
    • Epsilon, "Epsilon Positioned at the Center of Publicis Groupe Growth Strategy" (October 2020)
    • USA v. Epsilon Data Management LLC, Case No. 21-cr-00020 (D. Colo.)
    • USA v. Robert Reger and David Lytle, Case No. 21-cr-00213 (D. Colo.)

    Next in the series: "Gravy Analytics: The Company That Tracked You to the Abortion Clinic (And Then Got Hacked)"

    Hashtags

    #DataBrokers #ElderFraud #Privacy #Scams #Epsilon #Publicis #ConsumerProtection #DOJ #SeniorSafety

    Share this article

    Share: