Skip to main content
Reference · Updated August 2026

Data Broker Case Studies

Data-broker and personal-data exposure can create real safety risks. These documented, sourced cases involve stalking, murder, swatting, targeted harassment, or regulatory concern; each source states what is established and what remains uncertain. Each case ends with a practical privacy lesson rather than a promise that one removal request prevents harm.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 24, 2026
A possible personal-data exposure chain: information is collected or published, another party obtains or uses it, a safety risk may follow, and a law, ruling, or regulatory response may result. Provider-specific removal can address one lookup path but cannot guarantee that every downstream copy changes.
The cases involve different sources and different evidence. A provider-specific request may reduce one lookup path, but it cannot be assumed to prevent every downstream harm or change every copy.
Loading Case Outcome Explorer…
1999–2003 · A 20-year-old dental assistant in New Hampshire

Amy Boyer: the murder that put data brokers on trial

What happened

Liam Youens, who had been obsessed with Amy Lynn Boyer since high school, paid the online investigation service Docusearch for her Social Security number and then her workplace address. Docusearch obtained the work address through a pretextual ("pretexting") phone call. On October 15, 1999, Youens drove to Boyer’s workplace and fatally shot her as she left, then killed himself.

The role of data brokers

Boyer had no relationship with Docusearch and no way to know it was assembling and selling her identifying information. The broker sold her SSN and work location to a paying stranger without verifying his intent, the exact business model that people-search and data-broker services still run on.

What changed

In Remsburg v. Docusearch (2003), the New Hampshire Supreme Court recognized a duty of reasonable care in the circumstances before it because criminal misuse of sold personal data was foreseeable. Congress did not enact the original S. 2554 proposal as introduced, but it did enact a modified section titled "Amy Boyer’s Law" as section 635 of Public Law 106-553 in 2000; its text included exceptions and delayed application, so do not describe it as a blanket ban on all Social Security number use.

The removal lesson

The case shows why a broker-held work address or identifier can create safety risk when disclosed to a stranger. Removing a matching listing may reduce one lookup path, but it does not recall copies held elsewhere or establish that a threat actor used a particular source.

How to protect your personal information online
2024–2025 · Mobile-phone users whose precise location was collected

Location brokers tracked visits to clinics, shelters, and places of worship

What happened

The FTC brought actions involving Gravy Analytics / Venntel and X-Mode Social / Outlogic. The agency alleged that the companies collected or used precise location data and placed sensitive locations or audience segments at risk. The allegations, orders, and affected data differ by case; read the cited FTC materials rather than combining them into one universal model.

The role of data brokers

Precise location can reveal visits to places such as medical facilities, houses of worship, or shelters. An app or advertising SDK may be involved without the user having a direct relationship with the named data broker, but the collection path must be established for the specific case.

What changed

The FTC finalized orders in April 2024 for X-Mode Social / Outlogic and in January 2025 for Gravy Analytics / Venntel, prohibiting specified sales or uses of sensitive location data and requiring case-specific deletion or compliance steps. The complaints’ underlying allegations and the orders’ precise terms differ by case; they do not establish that every location-data company uses the same practice or that a phone setting removes historical data.

The removal lesson

Review app permissions, advertising controls, and the current privacy choices offered by the relevant app or platform. A device setting or broker request can address one layer of collection; it does not prove that every downstream copy or independent source changed.

Location data brokers explained
2020 · A federal judge and her family

A judge’s home address, a murdered son, and Daniel’s Law

What happened

In July 2020, a disgruntled attorney posing as a delivery driver arrived at the New Jersey home of U.S. District Judge Esther Salas. He shot and killed her 20-year-old son, Daniel Anderl, and wounded her husband. The attacker had compiled a dossier on Judge Salas, including her home address, which was readily available online.

The role of data brokers

The attacker had access to the judge’s home address and other identifying information. The cited sources support the safety significance of exposed judicial information, but they do not establish that a particular people-search site supplied every item in the dossier.

What changed

New Jersey enacted Daniel’s Law for defined covered persons, covered information, and qualifying written requests; the current statute and amendments control its scope and timing. Congress later enacted the federal Daniel Anderl Judicial Security and Privacy Act for the federal judiciary, but that federal program is not the same as a nationwide self-service broker deadline.

The removal lesson

Address privacy is a legitimate safety concern. Covered people should use the current statute or program that applies to them; everyone else can review provider-specific suppression routes, source controls, and safety-planning resources without assuming Daniel’s Law applies.

What is Daniel's Law?
2024–2025 · Judges, election officials, public figures, and ordinary targets

The swatting epidemic runs on people-search addresses

What happened

Recent reporting and prosecutions describe swatting and doxxing incidents involving public officials, public figures, and other targets. The scale, source of the address, and legal consequences vary by case; the sources below provide context rather than a complete incident census.

The role of data brokers

A published address can make a target easier to locate, but it is not established that people-search sites supplied the address in every swatting case. Treat source-specific removal as one preventive measure alongside account security, platform reporting, and a safety plan.

What changed

States and federal prosecutors have used different criminal statutes and sentencing theories for swatting-related conduct. A legislative response or prosecution does not establish a universal address-removal duty for every publisher.

The removal lesson

If swatting or doxxing is a credible concern, document the threat, contact appropriate authorities or an advocate, and review the exact public listings and account controls involved. Removing a provider listing may reduce one lookup path but cannot undo information already obtained.

Remove your address and phone from data brokers
2024 · Clinic staff, doctors, and reproductive-health providers

Targeting reproductive-health workers with broker data

What happened

Reporting in 2024 documented concerns that anti-abortion activists and harassers could use readily available personal information, including home addresses and phone numbers, to target reproductive-health-care workers. The source describes a safety risk; it does not establish one identical broker pipeline for every worker.

The role of data brokers

A published address or contact detail can make a worker easier to locate. The relevant source, publisher, and remedy must be checked for the specific person rather than inferred from the existence of a broker ecosystem.

What changed

The reporting contributed to calls for stronger address-confidentiality protections and source-specific privacy measures for health-care workers. It does not establish that a particular clinic or provider adopted a uniform data-removal program.

The removal lesson

For people facing a targeted safety risk, combine an advocate-informed safety plan with review of exact public listings, applicable address-confidentiality programs, and provider-specific opt-outs. No single measure is a universal safety solution.

Address Confidentiality Programs by state

Generate requests in under 60 seconds

Generate Your Opt-Out Requests

Each case illustrates why it can be useful to review public listings and provider routes. OfflistMe prepares browser-local, user-reviewed requests for recorded workflows; you decide what to send, complete any provider verification, and keep the response. No request guarantees deletion or prevents every future exposure.

One-time from $9

Related reading