The Price of Your Life: $0.12
In November 2023, researchers at Duke University wanted to know how hard it would be for a foreign adversary to buy sensitive data on U.S. military personnel.
Not hard at all, it turns out.
For twelve cents per person, they purchased health conditions, financial data, religious practices, and family information on active-duty servicemembers. When they asked about buying data on people stationed near Fort Bragg and other special operations bases, the data brokers didn't blink. One company demanded identity verification—unless the researchers paid by wire transfer instead of credit card. They wired the money. The data arrived. No questions asked.
The researchers then set up a fake company with a .asia domain, hosted on a server in Singapore, and tried again. Same result. Sensitive data on American military families, sold to what could have been a Chinese front company, for the price of a pack of gum.
"If our research team could do this in an academic study," lead researcher Justin Sherman told CNN, "a foreign adversary could get data in a heartbeat."
Welcome to the data broker industry.
You've never heard of most of these companies. They've heard everything about you.
What Is a Data Broker? (And Why Should You Care?)
A data broker is a company that collects information about you from hundreds of sources, packages it into a detailed profile, and sells it to anyone willing to pay.
That's it. That's the business model.
They don't make anything. They don't provide you a service. They just... know things about you. And sell that knowledge.
Where do they get your data?
Everywhere:
Public records: Court filings, property deeds, voter registration, marriage licenses, divorce decrees, bankruptcy filings, hunting licenses, fishing permits, and concealed carry permits (yes, really—even in states where sharing that is technically illegal)
Commercial sources: Loyalty card purchases, credit card transactions, magazine subscriptions, warranty registrations, sweepstakes entries, and those "surveys" you filled out for a chance to win an iPad
Online tracking: Every website you visit, every app you download, every ad you see (more on this nightmare later)
Your phone: Your precise GPS location, every single place you go, updated in real-time, often without your knowledge
Other data brokers: They buy and sell from each other, creating an incestuous web of surveillance where your data multiplies like a virus
What do they know?
Everything. And I mean everything.
A 2014 Senate investigation found data brokers selling lists with names like:
- "Rural and Barely Making It"
- "Ethnic Second-City Strugglers"
- "Retiring on Empty: Singles"
- "Tough Start: Young Single Parents"
- "Credit Crunched: City Families"
The World Privacy Forum found a data broker advertising a "Rape Sufferers List" for $0.079 per name.
Let me say that again: Someone compiled a list of rape survivors and sold it for eight cents a person.
LiveRamp, one of the largest data brokers, offers segments including:
- People with cancer
- People with Alzheimer's disease
- Muslims
- Jewish people
- African Americans
- "Poor people"
- "Payday loan prospects"
- Users of the LGBT dating app Grindr
- Unemployed individuals "seen at clinics/hospitals"
A January 2025 class action lawsuit against LiveRamp revealed they maintain profiles on 2.5 billion people with over 3,000 data points each. One plaintiff discovered LiveRamp had shared her information—including her Social Security number—with at least 62 third parties, including pharmaceutical companies, Google, Amazon, and Microsoft.
They knew about her health conditions. Her financial struggles. Her religious beliefs. Things she'd never told anyone except her doctor and her search engine.
The Body Count
This isn't just a privacy problem. People are dying.
Amy Boyer (1999)
Amy Boyer was 20 years old when a man who'd been stalking her since high school found her workplace address through a data broker called Docusearch. He paid $45 for her Social Security number and $109 for employment information. A Docusearch employee actually called Boyer, lied about who they were, and tricked her into revealing where she worked.
The stalker drove to her office and murdered her.
The New Hampshire Supreme Court ruled that Docusearch could be held liable—a landmark case. But here's the thing: Docusearch is still in business. Twenty-five years later, companies are still selling the same kind of data that got Amy Boyer killed.
Judge Esther Salas's Family (2020)
A gunman showed up at the home of federal District Judge Esther Salas. He shot and killed her 20-year-old son, Daniel, and critically wounded her husband. The attacker had compiled his target list using data broker services. He was also reportedly targeting Supreme Court Justice Sonia Sotomayor.
Congress responded by passing a law protecting federal judges' personal information from data brokers.
Just judges. Not you.
Minnesota State Representative Melissa Hortman (2025)
In June 2025, a gunman murdered Minnesota State Representative Melissa Hortman and her husband Mark in their home. Earlier that night, he'd shot State Senator John Hoffman and his wife (both survived).
When police searched the shooter's car, they found:
- A list of 45 Minnesota state and federal officials
- A notebook with home addresses, including Hortman's
- A list of 11 different data broker websites, with notes about which ones were free, how long their trials lasted, and how much information they required
"Data brokers get people killed every day," said data broker expert Jeff Jockisch. "The problem is that cops just don't look for that as a methodology."
Domestic Violence Survivors (Every Day)
For abuse survivors trying to escape dangerous partners, data brokers are a death sentence on a website.
An abuser can type their victim's name into a people-search site and get current addresses, past addresses, phone numbers, employer information, and family member names—for less than five dollars. Some sites offer this for free.
"If you have someone who's tried to kill you, for them to be able to just type in your name, and any known address that you've stayed at can pop up—it's scary," one survivor told ABC News in 2017. "Because now they know ways to start trying to find you."
The National Network to End Domestic Violence has documented case after case of GPS tracking, people-search websites, and data broker information being used to stalk, harass, and murder domestic violence victims.
The Elderly: America's Most Profitable Victims
If data brokers had a favorite target, it would be your grandmother.
In 2007, the New York Times exposed a company called InfoUSA that was selling lists with names like:
- "Suffering Seniors": 4.7 million people with cancer or Alzheimer's disease
- "Elderly Opportunity Seekers": 3.3 million older people "looking for ways to make money"
- "Oldies but Goodies": 500,000 gamblers over 55
Price: 8.5 cents per name.
One list description read: "These people are gullible. They want to believe that their luck can change."
InfoUSA sold these lists to companies that had already been investigated, prosecuted, or convicted of fraud. They knew their clients were criminals. They sold the data anyway.
But InfoUSA was just an appetizer.
Epsilon: The $150 Million Crime
Epsilon is one of the largest data brokers in the world, claiming profiles on 100 million U.S. households. In January 2021, the Department of Justice announced Epsilon would pay $150 million to settle criminal charges.
The crime? For nine years (2008-2017), Epsilon's Direct to Consumer unit knowingly sold data to scammers running fake sweepstakes and bogus astrology services. They sold over 30 million consumers' names to fraudsters who specifically targeted "elderly and vulnerable Americans."
From the DOJ press release:
"Epsilon employees knew that their clients had been arrested. They knew that their clients had been charged with crimes. They knew that their clients had been convicted. They continued to sell data anyway."
One single fraudster client defrauded 218,000 victims out of $23.7 million. Over 12,000 of those victims were scammed 20 or more times each by the same scheme. Epsilon sold this fraudster nearly 100 separate lists.
Two Epsilon executives went to prison.
Epsilon? Still in business. Still selling data. Now owned by French advertising giant Publicis Groupe, which paid $4.4 billion for it in 2019—after the crimes were committed.
In fact, Epsilon is still listed on LiveRamp's data marketplace, still selling "health segments" including "people who use adult diapers for bladder leakage."
The $150 million fine represented less than 10% of Epsilon's annual revenue.
Crime pays. Especially when your victims are old.
Real-Time Bidding: The Surveillance Machine You've Never Heard Of
Here's how the advertising industry watches you:
Every time you visit a website or open an app with ads, an auction happens. In the milliseconds before the page loads, information about you is broadcast to thousands of companies competing to show you an advertisement.
This is called Real-Time Bidding (RTB). It's a $117 billion industry. And it's the largest data breach in history—happening continuously, on purpose, by design.
What gets broadcast about you:
- Your precise location (often within meters)
- Your browsing history
- Your device information
- Your demographics
- Your interests and behaviors
- What you're reading right now
Who receives it:
Thousands of companies. Advertising networks. Data brokers. Analytics firms. And—this is the terrifying part—literally anyone who signs up as a "bidder."
Here's the dirty secret: You don't have to win the auction to keep the data.
Every company that participates in the bid receives your information, whether they show you an ad or not. Many of them just collect the data and sell it elsewhere. The RTB system explicitly prohibits this, but enforcement is essentially nonexistent.
The FTC recently caught a company called Mobilewalla doing exactly this. Between 2018 and 2020, Mobilewalla collected data on over 2 billion unique mobile devices from RTB auctions—without ever placing ads. They then sold this data to track:
- Union organizers
- People at Black Lives Matter protests
- Home addresses of healthcare employees (for competitors to poach them)
They categorized people into groups like "pregnant women," "Hispanic churchgoers," and "members of the LGBTQ+ community."
This was the first time the FTC has ever taken action against RTB data abuse.
The RTB system processes hundreds of billions of auctions per day. Every single one broadcasts your personal information to companies you've never heard of, in countries you've never visited, for purposes you'd never approve.
A 2024 report from the Irish Council for Civil Liberties found that the average European's data is shared via RTB 376 times per day. In the U.S., with weaker privacy laws, it's likely much higher.
"It's not James Bond," one national security expert told The Capitol Forum. "It's advertising stood on its head."
The Government Is Buying Too
You might think: at least the government needs a warrant to access my data, right?
Wrong.
Government agencies have discovered a neat trick: they can skip the warrant requirement entirely by simply purchasing data from brokers.
Immigration and Customs Enforcement (ICE) has a $22 million contract with LexisNexis. Documents obtained through the Freedom of Information Act revealed that ICE searched the LexisNexis database over 1 million times in just seven months.
The searches included:
- 700,000+ "Advanced Person Searches"
- 200,000+ phone provider record searches
- 63,000+ vehicle record searches
- 10,000 social media profile searches
- 6,000 jail booking searches (a way to circumvent "sanctuary city" laws)
An internal ICE memo instructed officers that LexisNexis "should be widely utilized by ERO personnel as an integral part of our mission." LexisNexis even provided ICE with educational seminars on how to most effectively use the data.
Other government customers include:
- Department of Homeland Security
- FBI
- DEA
- IRS
- Secret Service
- Coast Guard
- Defense Counterintelligence and Security Agency
- State Department
- Food and Drug Administration
- Department of Labor ($1.2 billion contract with LexisNexis)
The Fourth Amendment requires warrants for searches. But the "third-party doctrine" holds that you have no reasonable expectation of privacy in information you've shared with a third party.
Data brokers are the ultimate third party. They have everything. And they'll sell to anyone—including the government that's supposed to need a warrant.
Foreign Adversaries Are at the Table
Senator Ron Wyden has put it bluntly:
"Right now it's perfectly legal for a company in China to buy huge databases of sensitive information on Americans, and then share that information with the Chinese government. That's a huge problem for our country's security."
The Duke University study proved this isn't hypothetical. Researchers set up a fake company on a Singapore server with a .asia domain and successfully purchased sensitive data on U.S. military personnel with zero vetting.
Foreign actors don't even need to be clever about it. They can:
- Buy directly from data brokers
- Set up shell companies
- Participate in RTB auctions and collect the bidstream data
- Simply hack into data brokers' poorly-secured systems
In January 2025, location data company Gravy Analytics was hacked. The breach exposed 17 terabytes of data—30 million location points in the sample alone. The hacker claimed to have 200 billion total records.
The data revealed devices at:
- The White House
- The Kremlin
- The Vatican
- Military bases worldwide
- Abortion clinics
- Addiction treatment centers
- Domestic violence shelters
Apps that leaked location data to Gravy included: Tinder, Grindr, Candy Crush, Muslim prayer apps, Christian Bible apps, VPN apps (the irony), pregnancy trackers, Microsoft 365, and Yahoo email.
The FTC had already banned Gravy Analytics from selling sensitive location data just weeks before the hack. The data they were ordered to delete... got stolen instead.
Why Nothing Changes
With all this documented harm, why hasn't Congress passed a federal privacy law?
Follow the money.
Data brokers spend millions lobbying against privacy legislation. RELX, the parent company of LexisNexis, spent over $11 million lobbying the federal government in recent years. In 2020 alone, data broker lobbying rivaled spending by individual Big Tech giants like Facebook and Google.
When the American Data Privacy and Protection Act gained momentum in the House in 2022, data broker lobbying surged. RELX increased spending by 26% in a single quarter.
Their argument? Privacy protections would hamper fraud prevention and law enforcement investigations.
Of course, law enforcement is supposed to get warrants. The whole point of buying from data brokers is to skip that inconvenient constitutional requirement.
The irony is suffocating: Companies that profit from surveillance are lobbying against privacy laws by arguing they help catch criminals—while simultaneously selling data to actual criminals who target the elderly.
Meanwhile, every federal privacy bill dies in committee.
What's Coming in This Series
Over the next several weeks, I'm going to take you inside the data broker industry. We're going to name names. We're going to follow the money. We're going to show you exactly how the surveillance machine works—and what you can do about it.
Coming up:
- LexisNexis & RELX: The $22 million ICE contract, the retaliation scandal, and the company that surveilled a million immigrants
- LiveRamp: How Acxiom rebranded after Cambridge Analytica and built the largest "identity graph" in history
- Epsilon: The full story of the elder fraud conviction—and why they're still in business
- Clearview AI: 50 billion photos scraped without consent and the global backlash
- Gravy Analytics & Venntel: The FTC ban, the massive breach, and location tracking to abortion clinics
- National Public Data: 272 million Social Security numbers leaked—and why the company just... declared bankruptcy
- The Enforcement Crackdown: X-Mode, InMarket, Kochava, Mobilewalla, and the FTC's new offensive
- Real-Time Bidding Deep Dive: The $117 billion surveillance machine powering every ad you see
- How to Protect Yourself: A comprehensive guide to opting out, removing your data, and fighting back
This is the story of how corporate America built the most comprehensive surveillance system in human history—and convinced us it was just "advertising."
Time to meet the companies that know you better than you know yourself.
What You Can Do Right Now
1. Start opting out. Many data brokers are legally required to honor opt-out requests (especially in California, Vermont, and other states with privacy laws). It's tedious, but it works. I'll provide a comprehensive guide in the final article of this series.
2. Check what's out there. Search your own name on people-search sites like Spokeo, BeenVerified, Whitepages, and others. You might be horrified. That horror is motivation.
3. Lock down your location. Go to your phone settings right now. Review which apps have location access. Most don't need it. Turn it off.
4. Use privacy tools. Privacy-focused browsers (Firefox, Brave), ad blockers (uBlock Origin), and tracker blockers make a real difference.
5. Demand change. Contact your representatives. Tell them you support federal privacy legislation—real legislation, with teeth, not industry-written loopholes. The data broker lobby is powerful. Your voice matters more.
Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform protecting families and seniors from scams and digital threats. She has 20+ years in cybersecurity, including roles at Apple, the White House OCIO, and GuidePoint Security. Follow The Shield Blog for more investigations into the companies that profit from your data.
Sources:
- Duke University, "Data Brokers and the Sale of Data on U.S. Military Personnel" (November 2023)
- U.S. Senate Committee on Commerce, Science, and Transportation, "A Review of the Data Broker Industry" (2014)
- Department of Justice, "Epsilon Data Management LLC Agrees to Pay $150 Million" (January 2021)
- Federal Trade Commission, "FTC Takes Action Against Gravy Analytics and Venntel" (December 2024)
- Federal Trade Commission, "FTC Takes Action Against Mobilewalla" (December 2024)
- The Intercept, "ICE Searched LexisNexis Database Over 1 Million Times" (June 2022)
- Lawfare, "People Search Data Brokers, Stalking, and 'Publicly Available Information' Carve-Outs" (October 2023)
- The Record, "Minnesota lawmaker's alleged killer had list of data broker websites" (June 2025)
- Irish Council for Civil Liberties, "The Biggest Data Breach" (2024)
- Electronic Frontier Foundation, "Online Behavioral Ads Fuel the Surveillance Industry" (January 2025)
- The Markup, "The Little-Known Data Broker Industry Is Spending Big Bucks Lobbying Congress" (April 2021)
- Politico, "Privacy bill triggers lobbying surge by data brokers" (August 2022)
- LiveRamp Class Action Lawsuit, Northern District of California (January 2025)
- New York Times, "Bilking the Elderly, With a Corporate Assist" (May 2007)
Next in the series: "LexisNexis: The Company That Sold a Million Immigrants to ICE"
