Desk live·
ForensicPost
Breaches/Data brokers/File 26-0111

Breached Broker Datasets Leave Consumers With No Account to Close

Most people appear in dozens of commercial datasets assembled without their participation. When one is breached, there is no account to close and no relationship to end.

Constructed geometry · not a chart of case data
TargetConsumers in broker datasets
ActorNone — commercial
D. Kennedy10 min readConfidence: medium2 sources reviewed

This database is organised around organisations that were breached. For most of them the affected people had some relationship — a customer, a patient, an employee.

The data broker files at 26-0502, 26-0207 and the identity aggregation at 26-0219 describe a different category, and it is worth stating the consumer position plainly.

There Is Nothing To Withdraw From

When a retailer is breached, an affected person can close the account, change the password, stop shopping there. The relationship is a thing they can act on.

A person in a broker’s dataset has no account. They cannot log in, cannot delete, and in most jurisdictions cannot compel deletion without first identifying which of many brokers holds them — which requires knowing they exist.

Notification Usually Does Not Reach Them

Breach notification depends on contact details and, practically, on the organisation being able to explain who it is. A broker notifying millions of people it has never contacted, about a relationship they did not know existed, is an exercise with no precedent and no incentive.

That is part of why exposures in this category surface as research findings — as at IDMerit and the aggregated credential store in 26-0615 — rather than as notification letters.

Why We File Them Anyway

Our standard is that the database records what happened to data, which is why it includes accidental publication at 26-0428 and misconfiguration at 26-0219 alongside intrusions.

Excluding this category because the affected people cannot be counted, notified or identified would make the database a record of organisations with customers, and the exposure here is at least as real for being invisible.

How we reported this

This is an analysis file built on published regulatory material and research, listed below, read against files previously published by this desk. Corrections: corrections@forensicpost.com.

Sources
  1. FTC takes action against data brokers for selling sensitive location dataEPIC
  2. FTC data broker enforcement actions in 2025-2026PrivacyOn
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary