How Bad Actors Find Your Personal Data (And How to Stop It)

Three individuals in a conference room intently watch as a television plays a video of someone running on a treadmill, transitioning to a weight bench, then moving to a rowing machine. One of the viewers, Robin, feels a light tap on the shoulder as their attorney asks, "Robin, did you hear the question?" Robin turns to face Alex, opposing counsel, and asks, "You had people following me? How long has this been going on?"

Alex repeats the question: "Can you confirm if you are the individual seen in this footage?" Robin's body stiffens, and a quiet "Yes, that is me" escapes their lips. Alex flips through the pages of a document and states, "In your previous deposition, three days after this footage was captured, you stated that your injuries prevented you from attending the gym..."

Time blurs under the bright fluorescent lights, and Robin is eventually informed that they are done for the day. They slowly stand, and just before exiting the room, turn to Alex and say, "I wonder how you would feel if people started following you around."

When they return home, Robin navigates to Alex's LinkedIn profile and begins noting every piece of identifying information they can find: face, full name, employer, professional email address, education, birthday, hometown. That should be enough.

Robin begins their search with breached data brokers and identifies a unique user handle tied to one of Alex's online profiles. Searching this handle reveals breached data taken from a credit reporting agency, which contains a physical address located in Alex's hometown. This must be them. Robin navigates to a popular people-search website, pays for a $25 monthly subscription, and starts by searching that address. It is an apartment address, and over 50 associated individuals appear, but Robin quickly identifies the correct profile based on the listed names and birthdates.

Robin begins searching the social media profiles the report has attributed to Alex, and before long comes across a public account with a matching profile picture. One monitor displays street-view addresses while the other scrolls through the profile's timeline. Two months ago, Alex was tagged in a photo posted by their significant other showing them napping on a porch, and the paneling of that house looks familiar. That's right. It's the address on Oak Street.

Early the next morning, before the sun begins to rise, Alex starts to pull out of their driveway when they notice a pair of headlights illuminate nearby. On this silent street, Alex begins their commute by making a right, as does the vehicle behind them. The next block is another right, which the other vehicle makes as well. The driver of this vehicle, Robin, sees Alex's head frantically alternate between the road and the rear-view mirror, and smiles as their previous thought is answered.

This is an anonymized story that focuses on tools and methodologies well within reach of the average individual. While open-source intelligence (OSINT) is employed by investigative and law-enforcement personnel to combat bad actors, it is important to remember that any OSINT resource can also be exploited by those same bad actors for malevolent purposes. After reading this paper, you will understand how bad actors obtain your personal data, how you can limit their impact, and how to prevent future bad actors from obtaining your personal data.

Why Is My Personal Data Available?

All data available for purchase falls into one of two categories: the data we knowingly or unknowingly surrender to the public sphere, and the data that is stolen from us or the services we use. The former refers to public records and the content we share online. The latter refers to breached data.

Regarding public records, while there are jurisdictions that actively protect personal data, the United States generally assumes that data held by the government is available to a public records request. The Freedom of Information Act (FOIA) established the standard that any person has the right to request access to federal agency records or information. States then modeled their public records legislation after FOIA, including the California Public Records Act, which echoes this sentiment in granting every person a right to inspect any public record. While both acts carve out exemptions for certain record types, they often do not protect our home addresses and other personal data against disclosure. On the contrary, jurisdictions such as Los Angeles County actively advertise the depth and scope of real property data available for purchase. These factors ultimately gave rise to commercial data brokers that not only harvest real property rolls, but also utility records, voter registration, phone numbers, and even social media profiles, all packaged and sold to anyone with a credit card.

While social media is unlikely to appear on government records, data brokers often identify profiles based on the bevy of data available from these official sources. Updating an online biography to include your hometown, university, or occupation allows friends and family to easily locate your profiles. The same is true for data brokers and bad actors. It is important to recognize that the cost of this convenience is privacy, and not necessarily only our own. In 2021, Senators Amy Klobuchar and Lisa Murkowski wrote a letter to the Federal Trade Commission noting that people-search sites often include the names and addresses of family members, and that the availability of this data makes it difficult or impossible for domestic violence victims to safely relocate with relatives. When evaluating your digital footprint, you have to account for yourself as well as your relatives and close associates.

Finally, regarding data breaches, this is unfortunately one area we have little control over beyond utilizing strong and unique passwords. As of 2018, cybercrime was estimated to be a $1.5 trillion industry, with data trading accounting for $160 billion of that total. With figures this high, it becomes apparent why bad actors would be so interested in our data. Once a platform's vulnerability is identified and its data has been harvested, it can be sold on the dark web for fractions of a penny per account. After the point of sale, the owner of this data may keep it for personal use or disseminate it to the surface web. In the latter scenario, this stolen data can then be harvested by commercial data brokers. In the story this paper opened with, Robin utilized a paid database to locate additional information about Alex. These are often useful tools for individuals and security professionals to assess risk and build corrective plans, but any OSINT resource designed for good can be twisted for nefarious purposes.

What Should I Do to Protect Myself?

At this point, it is normal to feel some anxiety about your privacy. The good news is that there is one change you can make to assert control: don't share personal data with anyone unless you absolutely have to. Deed your property under an anonymous trust, make your social media profiles private, and do not reuse login credentials across different platforms. These are three small changes that limit dissemination of your data.

Being privacy-oriented is a habitual practice, and not one that is always going to be the easiest option. However, if there is one actionable item you apply after reading this paper, it should be to block or remove non-essential cookies and trackers on the platforms you visit. One of Meta's recent ad campaigns has pushed the narrative that good ideas deserve to be found, and that the company is able to connect you with relevant businesses without sharing any of your identifying information. The issue with this assertion is that research has shown 99.98% of Americans can be re-identified based on their recorded demographic attributes. Make no mistake when reading a company's pledge to consumer privacy, because the only ones in a position to value it are the consumers themselves. To quantify exactly how much consumer privacy is valued, we need look no further than Amazon's Ad Verification program, which tracks the ads you view across different browsers and applications in exchange for $2 per month. Protecting your privacy means assigning it greater value than what data brokers are willing to pay for it, and taking measures such as deeding your home to a trust and rejecting cookies are the first steps toward making it more difficult for data brokers to package your data for sale.

How Can I Remove Data Available Online?

The names, nature, and number of data brokers are ever-changing, but the methods used to combat them are generally the same. In 2018, California voters passed the California Consumer Privacy Act (CCPA), which gave consumers the right to know what personal data platforms collect, the right to delete that collected data, and the right to opt out of its sale. In response, data brokers created avenues for consumers to place these requests, some less burdensome than others. The CCPA, and subsequent legislation passed in Nevada (2019), Virginia (2021), Colorado (2021), Utah (2022), and Connecticut (2022), has given consumers the ability to reclaim ownership of their data from brokers who are all too eager to disseminate it for a fee. At the time of writing, this means roughly 19% of the US population can cite legislation when exercising their privacy rights. While there are platforms that have adopted a blanket approach to privacy, it would be unwise to assume all data brokers will adopt this behavior until a large majority of states enact their own privacy acts. Until such a point, any privacy-oriented individual should avoid adding to the already robust stockpile data brokers have collected by keeping their personal data exactly what it should be: personal.

 
StoriesMalcolm Rivera