Data brokers selling sensitive military information

Share post:

A study by Duke University has uncovered how sensitive personal information about active-duty service members, their families, and veterans is being sold by data brokers for a mere $0.12 per person.

The study’s lead author, Justin Sherman, expressed shock at the ease with which they were able to access highly sensitive identifiable information that is not publicly available. The researchers purchased comprehensive records on tens of thousands of military service members for a fraction of a cent per person, including names, home addresses, emails, political affiliations, personal finances, health information, religious affiliations, marital status, and the presence of children in the home.

The researchers were able to purchase data geofenced to specific military bases, such as Fort Bragg and Fort AP Hill, demonstrating the potential for targeted attacks on service members. They also encountered minimal vetting from data brokers, even when posing as foreign buyers using a Singaporean IP address and a .asia domain name.

Data brokers operate in a largely unregulated environment, with only a few states requiring registration and a recent California law mandating data deletion upon request. At the federal level, privacy laws are virtually nonexistent, despite numerous attempts at legislation.

The study’s co-author, Hayley Barton, emphasized that “anyone with an email address can go out and do the exact same thing” and purchase sensitive personal information. This ease of access underscores the urgency for legislative intervention to protect individuals’ privacy and national security.

The sources for this piece include an article in Gizmodo.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways