What Data Brokers Know About You and How Scammers Use It
Photo credit: Telecom360.net | Connecting You To The Latest In Telecom
In this article
Scammers often know your name, employer, and address before they contact you. Here's where that data comes from and why it makes attacks more convincing.
Key Takeaways
- Data brokers compile personal profiles from public records, app data, and purchase histories without your direct consent.
- Scammers purchase or scrape this data to personalize attacks, making phishing and vishing far harder to detect.
- Details like your employer, neighborhood, and relatives' names allow attackers to impersonate trusted contacts convincingly.
- You can request removal from many data broker databases, though the process requires ongoing effort.
- Reducing your public digital footprint limits how much brokers can collect about you over time.
Where Scammers Get the Details That Fool You
When a scammer calls and already knows your name, the name of your employer, and the street you live on, that information almost certainly came from a data broker profile. Data brokers — companies that aggregate personal records and sell access to them — have been operating for decades, but their outputs now feed directly into modern social engineering attacks.
Scammers use this pre-gathered intelligence to practice pretexting: constructing a believable backstory before making contact. A caller claiming to be from your bank's fraud department sounds far more credible when they can recite your home address to "verify your identity." The detail itself becomes the weapon.
4,000+
Estimated data broker companies operating in the US
The Privacy Rights Clearinghouse and various industry analysts estimate thousands of companies qualify as data brokers, ranging from large consumer reporting agencies to small people-search sites.
$200B+
Estimated annual US data broker industry revenue
Industry research organizations tracking the data economy have placed the collective annual revenue of the US data brokerage sector at over $200 billion, reflecting the scale of commercial demand for personal profiles.
96%
Of spear-phishing attacks use personalized details
According to cybersecurity research from Barracuda Networks, the vast majority of spear-phishing attempts include personalized information about the target to increase credibility.
For a deeper look at how personal data gets collected across the digital ecosystem, see our comprehensive guide to online privacy.
What Data Brokers Actually Know
The scope of a compiled broker profile surprises most people. A typical profile may include:
- Full legal name and aliases — including maiden names and nicknames drawn from public records
- Current and past addresses — compiled from property records, utility registrations, and credit header data
- Employer and job title — often sourced from professional networking sites and resume databases
- Relatives and household members — derived from census data, voter rolls, and address co-occurrence
- Estimated income and net worth — modeled from property values, vehicle registrations, and purchase data
- Phone numbers and email addresses — aggregated from app sign-ups, loyalty programs, and public listings
- Political affiliation and religion — inferred from voter registration records where publicly available
Each data point in isolation is fairly innocuous. Combined into a single record attached to your name, the profile provides enough context for a skilled social engineer to impersonate a coworker, a utility provider, or even a family member.
Public Records Are a Significant Source
Much of the data in broker profiles originates from genuinely public records — property deeds, court filings, business licenses, and voter rolls — that governments make available by law. This means the information is technically legal to collect and compile. The privacy concern lies not in any single record but in the aggregation of dozens of them into a single, searchable profile tied to your identity.
How Scammers Convert Data Into Attacks
With a detailed profile in hand, attackers shift from generic mass-blast scams toward targeted spear-phishing and vishing (voice phishing). The attack patterns follow predictable templates:
Impersonation of trusted institutions
A caller references your real bank, your actual employer, or a utility company servicing your real address. The specificity signals legitimacy and lowers your guard before the actual request — usually for credentials, a one-time code, or a payment — arrives.
Family emergency fraud
Knowing the names of your relatives, scammers can call posing as a grandchild, sibling, or friend in distress, or as a law enforcement officer referencing a real family member by name. This variant disproportionately targets older adults.
SIM swap setup
Broker data helps attackers answer the security questions carriers use to verify identity, enabling them to port your number to a device they control. Understanding this risk is covered in detail in our article on SIM swap fraud and how to prevent it.
Verify Before You Trust Any Caller
If a caller references personal details to establish legitimacy, treat it as a reason for caution rather than confirmation of identity. Hang up and call the organization back using a number you independently verify — from the company's official website, not one the caller provides. Legitimate institutions will never penalize you for taking this step.
Reducing Your Exposure Over Time
Eliminating your presence from data broker databases entirely is not realistic for most people, but meaningfully reducing your profile is achievable through consistent habits:
- Submit opt-out requests to major data brokers directly. Most are legally required to honor them, though you will likely need to repeat requests every few months as data is re-ingested from upstream sources.
- Audit app permissions regularly. Location, contacts, and calendar access granted to apps often flow into third-party data pipelines without your awareness.
- Limit public social media. Employer, hometown, and family relationship data displayed publicly on social profiles feeds directly into broker aggregation.
- Use unique email addresses for different services so that data leaks from one provider cannot easily be cross-referenced with other accounts.
For more on your legal rights and practical steps to limit broker reach, see what data brokers know and how to limit their reach. You can also explore the broader landscape of mobile-targeted threats in our overview of digital threats for smartphone users.
