For most people filling in their email address in on Have I Been Pwned it likely is not a matter of "will be" but "has been".
Not from the US but in no particular order here is the sort of data that is already out there for me:
My bank account number
My phone number (recruiters have the audacity to call me here and pretend to be shocked when I tell them they can't have gotten hold of my phone number in any legal way).
Email address (same story with recruiters as with my phone number)
Date of birth
Gender
Full name
Physical address
Education level
And a bunch more.
And there could be much more. But it is not as shitty as it is for a large amount of women in the country who participated in national cervical cancer screening.
If you don't think your data will leak or isn't already out there, then you are sorely mistaken.
In fact, I strongly believe the percentage of Americans would be much higher in this article if the US had a federal level proper data leak disclosure laws like we have in the EU. I know various states have disclosure laws but afaik they aren't as strict as the GDPR requirements and allow for quite a few cases where companies can decide it isn't a risk for some reason.
(recruiters have the audacity to call me here and pretend to be shocked when I tell them they can't have gotten hold of my phone number in any legal way).
I work as an executive in cybersecurity, and I get cold calls from vendors attempting to sell me things all the time. This is fine on my work phone, which I basically always ignore anyway, but I also get frequent calls on my personal phone.
I've grilled these salespeople multiple times about it. It usually goes something like.
"Hi, yeah, I'm not interested. I'm just curious, where'd you get this phone number? Its my personal number and I never use it for anything work related.
"Oh, we got it from your LinkedIn"
"Its not on my LinkedIn"
"Oh, well it probably used to be, so it's in our system"
"Its never been on my linkedin, or any publicly available website for that matter."
"Oh... Uhh... I'm not sure then"
"Okay. You should probably look into that. Anyway, never call me again."
The sheer balls of a company that sells cybersecurity services for a living using leads they purchased from data brokers fed by data breaches will never cease to impress me. You're trying to sell me a product that will stop attackers, while using the fruits of their labor to feed your sales pipeline.
Oh yeah, at one time I got a guy mailing me on my personal mail about a work field related thing. Something about a collaboration with my company and all that.
The only way they could have put my work field and my personal mail together is through a data leak. I outright asked them, got a vague answer. So I then replied that the only way they reasonably could have gotten my personal mail and connected it to my work activities was through a data leak. And that as such I had to report this to our national data protection agency as a GDPR violation.
To which they replied, somewhat peeved, with something along the lines of "If I had known that you would question me about the legality of how I am using your mail address I would not have contacted you". No shit Sherlock, you are using questionable methods and of course you were hoping to get away with it.
How to find the name of the owner of almost any property in America:
Pick a random address.
Seach 'city, state property tax lookup'
After a click or two on the relevant municipality website,you can now plug in said address.
Now you probably have the names for the current and past owners, sale history, tax assessment info and more.
And that's how I found out who my actual landlord was, and not the management company. Then, having a name and address, you can search all the various socials, and for average people who keep their profile public, congratulations, you know their carreer path, their families, etc.
For $0.26 each, 200 minimum, you can now send a highly detailed fraudulent instructions to a bunch of addresses "get a 50% discount" on your property tax bill by paying early.
Goddorie wat een lijst. Was je klant bij Odido ofzo?
Yup, though a lot of it was already out there. Or would be with the latest breach of that logistical partner of Bol and half of the companies in the Netherlands.
A small selection of all the breaches I've been involved in
2026: Odido
2024: Trello
2021: Ticketcounter
2020: Gravatar
2019: Deezer
2016: Dailymotion
2016: MoDaCo
2015: Trillian
2015: vBulletin
2013: Adobe
2013: imgur
2012: Drobox
2012: LinkedIn (guess where those recruiters get their info from)
2012: last.fm
Not all of them contain the same data of course. But much of the information that would have been in the Odido leak would also have been in the Ticketcounter leak for example.
I think the better statistic was that only 11% disagreed with the statement. With how many site registrations require more and more personal data it has to be a statistical inevitability. And all it takes is a single slip up from 1 company, or subsidiary, or employee and its out there pretty much for good.
I would highly doubt things are going to get better in the future for your online privacy.
The article talks about the bubble of the early internet of high quality sites that did not exploit the users popping.
The bubble did not pop. It was popped because of profit, because modern business does not understand the concept of enough and of social responsibility and because tech illiteracy is so rampant.
creesch | a day ago
For most people filling in their email address in on Have I Been Pwned it likely is not a matter of "will be" but "has been".
Not from the US but in no particular order here is the sort of data that is already out there for me:
And there could be much more. But it is not as shitty as it is for a large amount of women in the country who participated in national cervical cancer screening.
If you don't think your data will leak or isn't already out there, then you are sorely mistaken.
In fact, I strongly believe the percentage of Americans would be much higher in this article if the US had a federal level proper data leak disclosure laws like we have in the EU. I know various states have disclosure laws but afaik they aren't as strict as the GDPR requirements and allow for quite a few cases where companies can decide it isn't a risk for some reason.
papasquat | a day ago
I work as an executive in cybersecurity, and I get cold calls from vendors attempting to sell me things all the time. This is fine on my work phone, which I basically always ignore anyway, but I also get frequent calls on my personal phone.
I've grilled these salespeople multiple times about it. It usually goes something like.
"Hi, yeah, I'm not interested. I'm just curious, where'd you get this phone number? Its my personal number and I never use it for anything work related.
"Oh, we got it from your LinkedIn"
"Its not on my LinkedIn"
"Oh, well it probably used to be, so it's in our system"
"Its never been on my linkedin, or any publicly available website for that matter."
"Oh... Uhh... I'm not sure then"
"Okay. You should probably look into that. Anyway, never call me again."
The sheer balls of a company that sells cybersecurity services for a living using leads they purchased from data brokers fed by data breaches will never cease to impress me. You're trying to sell me a product that will stop attackers, while using the fruits of their labor to feed your sales pipeline.
Truly impressive stuff.
creesch | a day ago
Oh yeah, at one time I got a guy mailing me on my personal mail about a work field related thing. Something about a collaboration with my company and all that.
The only way they could have put my work field and my personal mail together is through a data leak. I outright asked them, got a vague answer. So I then replied that the only way they reasonably could have gotten my personal mail and connected it to my work activities was through a data leak. And that as such I had to report this to our national data protection agency as a GDPR violation.
To which they replied, somewhat peeved, with something along the lines of "If I had known that you would question me about the legality of how I am using your mail address I would not have contacted you". No shit Sherlock, you are using questionable methods and of course you were hoping to get away with it.
DefinitelyNotAFae | a day ago
Absolutely LOL
papasquat | a day ago
Hilarious reply.
"If I would have known you were going to call the cops on me I would have never broken into your house!"
updawg | a day ago
To be fair, "your information wouldn't be out there if company x had used our product" is a decent marketing pitch, if a bit unethical.
PraiseTheSoup | a day ago
"Impressive" is a word you could and did use, but I think I would go with "disgusting".
tanglisha | a day ago
Folks already seem to have forgotten about the Equifax data breach. There's been a lot going on since then, I guess.
vord | a day ago
How to find the name of the owner of almost any property in America:
Pick a random address.
Seach 'city, state property tax lookup'
After a click or two on the relevant municipality website,you can now plug in said address.
Now you probably have the names for the current and past owners, sale history, tax assessment info and more.
And that's how I found out who my actual landlord was, and not the management company. Then, having a name and address, you can search all the various socials, and for average people who keep their profile public, congratulations, you know their carreer path, their families, etc.
For $0.26 each, 200 minimum, you can now send a highly detailed fraudulent instructions to a bunch of addresses "get a 50% discount" on your property tax bill by paying early.
CptBluebear | a day ago
[...]
Goddorie wat een lijst. Was je klant bij Odido ofzo?
I've had leaks and probably have plenty of my personal data strewn around, but you've been extra unlucky it seems.
creesch | 20 hours ago
Yup, though a lot of it was already out there. Or would be with the latest breach of that logistical partner of Bol and half of the companies in the Netherlands.
A small selection of all the breaches I've been involved in
Not all of them contain the same data of course. But much of the information that would have been in the Odido leak would also have been in the Ticketcounter leak for example.
Grenno | a day ago
I think the better statistic was that only 11% disagreed with the statement. With how many site registrations require more and more personal data it has to be a statistical inevitability. And all it takes is a single slip up from 1 company, or subsidiary, or employee and its out there pretty much for good.
I would highly doubt things are going to get better in the future for your online privacy.
post_below | 23 hours ago
That means at least 48% of Americans don't know their data has already been breached.
Tiraon | 20 hours ago
The article talks about the bubble of the early internet of high quality sites that did not exploit the users popping.
The bubble did not pop. It was popped because of profit, because modern business does not understand the concept of enough and of social responsibility and because tech illiteracy is so rampant.