A U.S. congressional investigation by the Joint Economic Committee’s Democratic minority estimated that identity theft tied to breaches at four major data brokers has cost American consumers roughly $20 billion, and highlighted how some brokers obscured legally required “opt-out” pages (including use of no-index tactics that made deletion/opt-out pages harder to find). The report, prompted by investigative reporting, said several large brokers subsequently engaged with congressional staff and changed practices to make it easier for consumers to control the collection and sale of their personal data.
California regulators separately escalated enforcement of opt-out requirements under state privacy law, with the California Privacy Protection Agency (CPPA) fining PlayOn Sports $1.1 million over allegations that its GoFan ticketing platform used tracking technologies for targeted advertising without providing a compliant, easy-to-use opt-out mechanism. The CPPA said users—including large numbers of high school students—were effectively forced to “agree” to tracking to access paid tickets and services, and that directing users to industry opt-out programs (e.g., Network Advertising Initiative / Digital Advertising Alliance) did not satisfy California’s requirement that companies provide their own opt-out tool and clear disclosures.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
California Privacy Protection Agency Executive Director Tom Kemp discussed the state's new Delete Request and Opt-out Platform (DROP), a tool intended to help California residents exercise privacy rights with data brokers. The discussion also emphasized California's broader enforcement and regulatory approach to data-broker oversight.
The Joint Economic Committee’s Democratic minority released an investigation estimating that major data-broker breaches over the last decade caused more than $20 billion in consumer identity-theft losses. The report also called for easier opt-out mechanisms and stronger oversight of the data-broker industry.
The California Privacy Protection Agency fined PlayOn Sports $1.1 million for allegedly failing to provide a legally compliant opt-out from tracking technologies and for improperly steering users to third-party opt-out tools. The agency also ordered the company to change its privacy disclosures, opt-out practices, and conduct risk assessments.
After the reporting on hidden opt-out pages, Sen. Maggie Hassan contacted several data brokers about their practices. Most later engaged with congressional staff and changed their sites to make privacy and opt-out pages more visible, while Findem reportedly did not.
The Markup and CalMatters, in collaboration with WIRED, reported that some data brokers used no-index tags to keep legally required California opt-out pages from appearing in search engines, making them harder to find.
A 2025 TransUnion breach was cited by the Joint Economic Committee’s Democratic minority as one of the recent major data-broker breaches linked to consumer identity-theft losses.
A 2023 breach involving National Public was included among the major data-broker breaches used by congressional investigators to estimate consumer losses from identity theft.
The Exactis breach was identified in the congressional investigation as another major data-broker incident that helped drive large-scale consumer identity-theft harms over the last decade.
Equifax suffered a major data breach that was later cited by a congressional investigation as one of four large data-broker-related incidents contributing to identity-theft losses exceeding $20 billion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
lawfaremedia.org
Open sourcedatabreaches.net
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.