U.S. military members' personal data being sold by online brokers
Use of SSNs and Identifiers
- Many note the U.S. military and broader U.S. institutions still heavily rely on SSNs as universal identifiers, often printed on every form and piece of paper.
- Criticism that SSNs are treated as both “username” and “password” by banks and others, enabling serious identity theft.
- Some argue SSNs should only be used for Social Security; others ask what alternative unique ID government services should use.
- Comparisons to countries where a national ID is widely used as a neutral identifier but not as an authenticator.
Military Recordkeeping and PII Exposure
- DoD has smartcards and 2FA, but its paper-heavy culture means SSNs and other PII appear on huge volumes of documents.
- Service records, DD-214, and security clearance forms (SF-86) are described as “complete identity packages,” repeatedly copied, emailed, and handled by many people.
- VA and contractors are criticized for lax handling, including a case where PII was put on a thumb drive and ended up sold on the dark web.
- The OPM breach is cited as a prior, larger catastrophe, including fingerprints and clearance data.
Are Service Members’ Data Uniquely Sensitive?
- One view: everyone’s data is being sold; focusing on military is just framing.
- Counterview: service members are special national-security targets and have denser, more sensitive dossiers; framing this as a national security problem may be necessary to spur Congress to act.
Data Brokers, Regulation, and Liability
- Strong support for a comprehensive U.S. privacy law targeting data brokers; some propose outright banning the sale of personal data.
- Others worry partial regulation just reproduces GDPR-style “consent theater.”
- Repeated calls to flip incentives: make personal data a liability with heavy penalties for breaches so companies minimize collection and retention.
Doxxing, Drones, and Physical Threats
- Some extrapolate from Ukraine’s drone warfare to potential civilian “drone drop” attacks once addresses and other data are easily purchasable.
- Others argue conventional violence (guns, knives) is still easier; drone attacks are technically and logistically harder, though examples of weaponized consumer drones are noted.
- Broader concern that detailed, cross-linked personal data (address, politics, religion, purchases) enables targeted harassment and violence.
Job Market, LinkedIn, and Clearance Signaling
- Concern that online job applications and fake postings could be used to harvest PII, especially for defense-related roles.
- Debate over LinkedIn groups and profiles advertising security clearances: some see it as a dangerous targeting aid; others note there’s little empirical evidence of widespread lethal targeting based on this, though it’s acknowledged as a plausible attack vector.