Experian Sold Consumer Data to ID Theft Service
An identity theft service that sold Social Security and drivers license numbers — as well as bank account and credit card data on millions of Americans — purchased much of its data from Experian, one of the three major credit bureaus …
Context & Ripple Effects
Brian Krebs has been pulling threads on SSNDOB, the underground identity-theft service, all month: in late September he reported the crew had breached LexisNexis and other large data brokers to feed its marketplace. Today's report goes further up the supply chain — the service did not only steal data, it bought much of its inventory of Social Security numbers, driver's license figures, and bank-account and card data on millions of Americans directly from Experian.
The significance is the counterparty: Experian is one of the three major credit bureaus, meaning a criminal resale operation cleared whatever vetting sits between a credit bureau's consumer files and its paying customers. Syndication beyond Krebs was thin at publication — mostly social shares — so the story's force rests on the sourcing claim itself.
First-order effects
- Experian's commercial data-sales operation faces immediate scrutiny over how an identity theft service qualified as a legitimate bulk buyer of SSNs, license numbers, and financial account data on millions of consumers.
- Consumers whose records were sold were exposed through a paid transaction rather than a hack, so no breach-notification machinery was triggered — most had no way to know their data left Experian's files.
Second-order effects
- Rival bureaus and the broader data-broker industry get pulled into the blast radius: every large seller of consumer PII can expect questions about buyer-side due diligence after the September SSNDOB breaches plus this confirmed sale.
- Identity-monitoring and fraud-protection vendors gain a concrete selling point — the data leaked through a bureau's own sales desk — reshaping demand for services pitched as a hedge against exactly this failure mode.
Third-order effects
- If bureaus cannot distinguish criminals from clients at the point of sale, the case strengthens for formal regulatory oversight of data brokers — mandatory buyer vetting, audit trails on sensitive-data transactions — replacing today's largely self-regulated market with compliance costs that favor the biggest incumbents.
The trend: Consumer data brokerage is being pushed from an opaque business-to-business trade toward regulated infrastructure, with each confirmed lapse at a major bureau hardening the argument for statutory buyer-vetting rules.