Data brokers selling sensitive military information

Share post:

A study by Duke University has uncovered how sensitive personal information about active-duty service members, their families, and veterans is being sold by data brokers for a mere $0.12 per person.

The study’s lead author, Justin Sherman, expressed shock at the ease with which they were able to access highly sensitive identifiable information that is not publicly available. The researchers purchased comprehensive records on tens of thousands of military service members for a fraction of a cent per person, including names, home addresses, emails, political affiliations, personal finances, health information, religious affiliations, marital status, and the presence of children in the home.

The researchers were able to purchase data geofenced to specific military bases, such as Fort Bragg and Fort AP Hill, demonstrating the potential for targeted attacks on service members. They also encountered minimal vetting from data brokers, even when posing as foreign buyers using a Singaporean IP address and a .asia domain name.

Data brokers operate in a largely unregulated environment, with only a few states requiring registration and a recent California law mandating data deletion upon request. At the federal level, privacy laws are virtually nonexistent, despite numerous attempts at legislation.

The study’s co-author, Hayley Barton, emphasized that “anyone with an email address can go out and do the exact same thing” and purchase sensitive personal information. This ease of access underscores the urgency for legislative intervention to protect individuals’ privacy and national security.

The sources for this piece include an article in Gizmodo.

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday May 17, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, May 17th,...

Cyber Security Today, May 17, 2024 – Malware hiding in Apache Tomcat servers

Malware hiding in Apache Tomcat servers, new backdoors found, and more Welcome to Cyber Security Today. It's Friday, May...

MIT students exploit blockchain vulnerability to steal 25 million dollars

Two MIT students have been implicated in a highly sophisticated cryptocurrency heist, where they reportedly exploited a vulnerability...

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways