Nothing was leaked. This record is built from public & commercial data by companies the person in it never dealt with. This is an account of what that record makes possible, not a claim about what it has caused.
The call comes late on a Tuesday morning. The man on the line has her full name, the street she lives on, the year the house changed hands & the name of a relative. He is not guessing. He is reading.
That opening is a composite, built from the categories a federal catalog says these products return. It is not a report of any real call, household, or engagement of ours.
Nothing in it had to be stolen. No breach, no phishing email, no careless post. Every element sits in a record assembled, matched & sold while the person in it did nothing at all.
None of it broke a law. That is the part worth sitting with.
In 2014 the Federal Trade Commission issued orders to nine data broker companies & published what they produced. Nobody has repeated it since. The figures are twelve years old; the mechanism is still in operation.
One line matters more than any figure: none of the nine collected data directly from consumers. The material arrives from three places instead. Government records, from property and voter files to court and motor vehicle records. Publicly available material, from directories to crawled social profiles. Commercial data, purchase histories bought from businesses the person did deal with, for unrelated reasons. Seven of the nine also bought from or sold to each other, which the Commission said made it virtually impossible for a consumer to determine how a broker obtained his or her data.
The consumer product built on that is people search, & the Commission cataloged what it returns. Nineteen categories, among them "Address history," "Relatives," "Criminal records," "Neighbors (including sex offenders)," marriage & divorce records & property sales history. The information was there to be bought, & bought by companies & private individuals alike, with no vetting of the buyer or of how they meant to use it.
None of these are loose scraps. They are matched across many sources & merged into one confident profile of a specific person. There is no gate after the sale, & none was ever designed.
Writing on this subject goes wrong here. No government source connects the broker record to a dollar of fraud loss or to a single stalking case. The complaint data records how a scammer made contact, never where the number came from. The stalking survey never asks how an offender found the victim. Anyone quoting a figure for what this industry causes has invented it.
The Commission's only risk sentence about people search: these products "can be used to facilitate harassment, or even stalking, and may expose domestic violence victims, law enforcement officers, prosecutors, public officials, or other individuals to retaliation or other harm."
Beside it, two measurements. In 2019 the Bureau of Justice Statistics counted 3,419,710 people aged 16 or older stalked over twelve months. Of those, 955,470, or 41.5 percent, had an offender harassing or repeatedly questioning their friends & family for information about them. 2019 data, published 2022, & the newest that exists.
Separately, in the FTC's 2024 complaint data, a phone call was the identified contact method in 284,659 reported frauds & carried the highest median reported loss of any channel, $1,500. Reported losses from complaints filed, not a national total.
The pathway between those two facts has not been measured by anybody, & I am not going to draw it for you.
Identity thieves buy the data-broker file, & the public trail behind it, to learn the street you grew up on, your first car, your mother's maiden name, even your high school & its mascot. Sound familiar? Those are the most common security questions there are. The profile gives a clear picture of your habits over time. That, the Commission warned in 2014, can let an identity thief "predict passwords, challenge questions, or other authentication credentials."
Eleven years later the standard caught up. In July 2025 the National Institute of Standards & Technology published revision 4 of both halves of its digital identity guidelines. Verifiers SHALL NOT prompt subscribers to use knowledge-based authentication or security questions when choosing passwords. Knowledge-based verification SHALL NOT be used for identity verification. One narrow opening remains, that a provider MAY employ it inside a fraud management program. NIST's stated reason: the answers are too easy for an attacker to discover.
What follows is mine, & it is security practice rather than anybody's standard. Stop answering security questions truthfully; a first pet's name can be forty random characters in a password manager. Move every account that matters off SMS codes & onto an authenticator app or a hardware key. Ask the mobile carrier for a port-out PIN. Freeze the credit file at all three national bureaus. None of it depends on a broker doing anything, which is why it is the strongest ground available.
Removal is worth doing, but it is mitigation, not elimination. Brokers refresh their data by automated means such as web crawling, which is exactly why they told the Commission that deletion is futile: the same or seemingly related information simply reappears. So the best way to spend the effort is to go as close to the source as possible. Opting out of individual people-search sites is clearing the shelves while the warehouse keeps restocking them. We need to clear the warehouse.
We published a case study of a single account on a single day. An automated removal service's dashboard reported no exposures found. A check done by hand that same day found live listings still standing on sites the dashboard had marked clean, & reached a layer of wholesale suppliers that never appeared on the service's board at all. One account, one person, one day, a documented case & not a controlled study; "no exposures found" can be a matching miss rather than a false claim, & nobody is accused of lying. The lesson is narrow & it is not a scoreboard: a clean dashboard is a claim until somebody looks, & the person with the most reason to look is you.
The brokers make automation hard on purpose. Many gate the opt-out behind a CAPTCHA, an email you have to confirm, sometimes a phone call to verify, steps a person clears in a minute & automations stall on. That is the gap the case study caught: the board read clean because the automated run never got through the door, while a person walks right through it.
So this is upkeep, not a purchase that ends the problem, & it is work you can do yourself. Some requests will ask you to hand the broker identifying information so it can match you, so you will be disclosing in order to reduce a disclosure; read what each one asks & decide request by request.
| Live exposures found | ||
|---|---|---|
| Service reported | Found by hand | |
| On the sites it marked clean | 0 | 3 |
| Among the wholesale suppliers (not tracked) | 0 | 4 |
One documented case, one day, not a controlled study.
First, take the ground you control, in the order above: security questions, authenticator apps, the carrier PIN, the credit freezes. One afternoon, & it costs nothing.
Second, start reducing the record, beginning where your own identity is the key that opens the door. The free federal & industry registries are keyed to you & last for years: the national do-not-call registry, the credit pre-screen opt-out & the direct mail suppression file. If you live in California, there is one move worth more than all the individual opt-outs combined: the state takes a single deletion request & routes it to every data broker registered with it, 603 of them when I counted on 27 August 2026. That is the warehouse, cleared with one form. Other states are building the same thing; it is worth checking whether yours has one yet.
The record was built without you. Reducing it is the part you can run.
You can do all of this yourself, free, with the only cost being research & time. If you would rather not build it from scratch, we developed a toolkit that is already ordered: the request letters written, the brokers & their opt-out channels listed, & a tracker to keep it straight. It is the Digital Ghost Protocol Toolkit, $67 once, no subscriptions. You send every request yourself, which is the strongest method, but you have a solid blueprint to follow.
This article was produced with AI assistance. The perspective and security expertise are the author's own.