Twelve Cents
A team of Duke researchers bought nearly 50,000 records on active-duty service members, veterans, and military families for a little over $10,000. Some datasets cost 12 cents a person. The records included names, home addresses, net worth, religion, health conditions, and information about service members' children. Precise location data was available for sale. The researchers did not buy it.
Nobody ran a background check on the purchase.
The researchers then repeated the test using a .asia domain name, a .asia email address, and a Singaporean IP address. Some brokers did impose controls. Others sold comparable sensitive datasets to the overseas buyer without substantial vetting.
There is no military aisle in that market. The same brokers sell everyone, and they ask everyone the same questions, which is usually none.
A Chevrolet Bolt owner found that out when his premium jumped 21 percent. He had already been judged by a 258-page file he did not know existed.
The Bill Arrived First
His name is Kenn Dahl. When he asked why his 2022 premium had climbed, an insurance agent told him to check his LexisNexis report. It listed the dates of 640 trips, their start and end times, the distance driven, and every instance of speeding, hard braking, or sharp acceleration.
The data came from OnStar Smart Driver, a General Motors program marketed as a way to become a smarter, safer driver. GM shared it with two brokers, LexisNexis Risk Solutions and Verisk, who sold it to insurers. Times reporters found documents suggesting dealers were paid bonuses for signing owners up. Kia, Mitsubishi, Hyundai, Honda, and Acura ran comparable programs.
A Florida driver sued GM, OnStar, and LexisNexis in March 2024. GM stopped the sharing that month and discontinued Smart Driver in April.
Dahl found out because he asked. He is the exception in this story.
Three People Who Never Got the Memo
Mary Louis applied for an apartment and was denied. She and another applicant, both holding federally funded housing vouchers, sued the tenant screening company SafeRent Solutions in federal court in Massachusetts in May 2022.
Start with the arithmetic rather than the fairness. The SafeRent Score did not count the value of the voucher. A housing voucher pays over 73 percent of the monthly rent directly to the landlord. The score was measuring the wrong number before anyone reached the question of discrimination.
The Justice Department and HUD filed a statement of interest in January 2023. The court denied SafeRent's motion to dismiss that July. A $2.3 million settlement received final approval in November 2024, and SafeRent agreed to stop including a score or an accept-decline recommendation in reports for voucher applicants. Louis eventually found an apartment through her son on Facebook Marketplace. It cost $200 more and sat in a less desirable area.
Then there is what happens when the buyer is a criminal.
In January 2021, the marketing firm Epsilon entered a deferred prosecution agreement with the Justice Department and paid $150 million. It admitted that from July 2008 through July 2017, employees in one of its units knowingly sold consumer lists to clients engaged in fraud. The unit sold data on more than 30 million consumers to fraudulent schemes, and employees kept selling to clients they knew had been arrested, charged, and convicted.
One client used nearly 100 of those lists to defraud more than 218,000 people of more than $23.7 million. Epsilon's own records showed that over 12,000 victims were defrauded more than 20 times each. Two former Epsilon employees were sentenced in the fall of 2024, one to 120 months and one to 48 months.
Twelve thousand people were hit again and again. None of them knew why the letters kept coming.
The last case ends the argument about whether this is abstract.
When police searched the vehicle of the man accused of the June 2025 attacks on Minnesota state legislators, they found a notebook containing a handwritten list of 11 people-search sites: TruePeopleSearch, Spokeo, Pipl, PeopleFinders, BeenVerified, Whitepages, TruthFinder, Intelius, Ownerly, US Search, and PeopleLooker. Investigators also recovered the handwritten names of 45 state and federal officials.
He did not hack anything. He shopped.
The Law Follows the Use, Not the Data
The Fair Credit Reporting Act was written because Congress concluded that files compiled about people, sold to third parties, and used to make decisions about their lives needed rules.
But the statute attaches its obligations to a purpose rather than to a dataset. Information assembled for decisions about credit, employment, insurance, and housing carries accuracy duties, consumer access, and dispute rights. The identical information sold for marketing, identity verification, or general risk scoring carries none of them.
That distinction splits the four cases in half.
Dahl and Louis were inside the statute, because the information was being used for insurance and housing. Both had a consumer-report framework around the decision.
The Epsilon victims and the Minnesota officials were outside it. Their information was being used to find susceptible consumers or to locate people, not to determine eligibility for anything.
Same market. Different legal status because of the use.
Being inside the statute is not the same as being protected from every kind of harm. Louis could obtain her report and dispute inaccurate information. But her case was not principally about a mistake in the file. It was about what the scoring model did with the information it had.
That fight came under a different law. Louis challenged the system under the Fair Housing Act and Massachusetts anti-discrimination law, arguing that the algorithm produced disparate outcomes for voucher holders. The FCRA could make the file visible. It did not answer whether the model built from that file was discriminatory.
A disclaimer does not settle which side of the line a company sits on. The FTC alleged that despite disclaimers on their websites, TruthFinder and Instant Checkmate operated as consumer reporting agencies because they marketed and sold background reports for employment and tenant screening. The complaint pointed to purchased search keywords including "best background check for landlords" and "pre employment screening." The companies paid $5.8 million.
If you furnish reports for a covered purpose, the law can follow the use regardless of what the footer says.
What the Brokers Sold, and to Whom
The service member study was funded by a US military grant. The team approached 12 data brokers and searched hundreds of broker websites drawn from state registries, finding thousands of references to military and veteran status, including datasets offered for sale. Brokers offered data geographically limited to particular regions and military installations, including Fort Bragg and Quantico.
The lead researcher's conclusion was that it was far too easy: sensitive military data for as little as 12 cents a record, with inconsistent customer verification and little meaningful vetting.
The reaction crossed party lines. Senator Bill Cassidy called it a gaping hole in the protection of US service members. Senator Ron Wyden called the industry out of control and a serious threat to national security.
That study is nearly three years old. The context has changed.
Since February 28, the United States has been in armed conflict with Iran. In April, six federal agencies warned that Iranian-affiliated actors were exploiting internet-connected industrial controllers across US critical infrastructure. They updated that advisory on July 22. As of August 9, attacks on water utilities had been reported in at least 12 states. Federal investigators suspect an Iran-linked campaign, although formal attribution has not been announced.
Targeting individuals is documented tradecraft. In September 2024, the FBI, US Cyber Command, Treasury, and the UK's National Cyber Security Centre published a joint advisory titled "Iranian Cyber Actors Targeting Personal Accounts to Support Operations."
A foreign service that wants to know where a service member lives, what they owe, and who their children are does not necessarily need to compromise an account. Some of that information has a price.
The Question Is Whether the Register Changed
The law has changed since Duke ran its experiment.
PADFAA, the Protecting Americans' Data from Foreign Adversaries Act, took effect in June 2024. It prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to any foreign adversary, defined as North Korea, China, Russia, and Iran, or entities those countries control.
Executive Order 14117 followed a separate track. The Justice Department's Data Security Program took effect in April 2025, restricting certain transactions involving sensitive American data and countries of concern.
In February of this year, the FTC sent letters to 13 data brokers stating that it had identified instances in which the recipient offered solutions and insights involving the status of an individual as a member of the Armed Forces. The agency did not name the companies, and the template letter alleges no specific violations. A warning is not an enforcement action.
That matters in both directions. The Duke study cannot prove what those brokers are doing today. What it shows is the market these laws inherited: in 2023, researchers presenting as an unfamiliar overseas buyer could purchase individually identified military data with little meaningful vetting.
It also matters that PADFAA reaches four countries. It does not touch the ordinary commercial market that produced Dahl, Louis, or the Epsilon victims.
The Signal
The consumer version of this problem can cost a person an insurance premium, an apartment, or their savings. The national-security version can locate a target. They are different harms produced by the same market.
The FCRA follows certain uses of the data. PADFAA has begun to follow certain buyers. Neither makes the broader data-broker market visible to the person being sold.
The Duke researchers showed what that market looked like before those rules arrived: a .asia domain, a Singaporean IP address, sensitive military records, and prices beginning at twelve cents.
The law now says somebody is supposed to check the buyer.
The question is whether anybody at the register actually does.
That is the signal this week.
Sources: New York Times reporting on GM, OnStar Smart Driver, LexisNexis, and Verisk; Louis v. SafeRent Solutions, D. Mass., and the Department of Justice and HUD statement of interest; FTC v. TruthFinder and Instant Checkmate; Department of Justice releases on Epsilon Data Management; federal criminal complaint in the June 2025 Minnesota case; Fair Credit Reporting Act; Fair Housing Act; Duke University Sanford School of Public Policy, "Data Brokers and the Sale of Data on US Military Personnel"; joint federal advisory on Iranian-affiliated cyber actors and its July 2026 update; joint FBI, USCYBERCOM, Treasury, and NCSC advisory on Iranian cyber actors targeting personal accounts; Protecting Americans' Data from Foreign Adversaries Act of 2024 and FTC warning letters of February 9, 2026; Executive Order 14117 and the Department of Justice Data Security Program.