U.S. military members' personal data being sold by online brokers

Use of SSNs and Identifiers

  • Many note the U.S. military and broader U.S. institutions still heavily rely on SSNs as universal identifiers, often printed on every form and piece of paper.
  • Criticism that SSNs are treated as both “username” and “password” by banks and others, enabling serious identity theft.
  • Some argue SSNs should only be used for Social Security; others ask what alternative unique ID government services should use.
  • Comparisons to countries where a national ID is widely used as a neutral identifier but not as an authenticator.

Military Recordkeeping and PII Exposure

  • DoD has smartcards and 2FA, but its paper-heavy culture means SSNs and other PII appear on huge volumes of documents.
  • Service records, DD-214, and security clearance forms (SF-86) are described as “complete identity packages,” repeatedly copied, emailed, and handled by many people.
  • VA and contractors are criticized for lax handling, including a case where PII was put on a thumb drive and ended up sold on the dark web.
  • The OPM breach is cited as a prior, larger catastrophe, including fingerprints and clearance data.

Are Service Members’ Data Uniquely Sensitive?

  • One view: everyone’s data is being sold; focusing on military is just framing.
  • Counterview: service members are special national-security targets and have denser, more sensitive dossiers; framing this as a national security problem may be necessary to spur Congress to act.

Data Brokers, Regulation, and Liability

  • Strong support for a comprehensive U.S. privacy law targeting data brokers; some propose outright banning the sale of personal data.
  • Others worry partial regulation just reproduces GDPR-style “consent theater.”
  • Repeated calls to flip incentives: make personal data a liability with heavy penalties for breaches so companies minimize collection and retention.

Doxxing, Drones, and Physical Threats

  • Some extrapolate from Ukraine’s drone warfare to potential civilian “drone drop” attacks once addresses and other data are easily purchasable.
  • Others argue conventional violence (guns, knives) is still easier; drone attacks are technically and logistically harder, though examples of weaponized consumer drones are noted.
  • Broader concern that detailed, cross-linked personal data (address, politics, religion, purchases) enables targeted harassment and violence.

Job Market, LinkedIn, and Clearance Signaling

  • Concern that online job applications and fake postings could be used to harvest PII, especially for defense-related roles.
  • Debate over LinkedIn groups and profiles advertising security clearances: some see it as a dangerous targeting aid; others note there’s little empirical evidence of widespread lethal targeting based on this, though it’s acknowledged as a plausible attack vector.