/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Police are buying access to hacked data, including passwords, IP addresses, and more to help with investigations in an end-run around the usual legal processes

The sale is “an end-run around the usual legal processes.”  —  Joseph Cox  —  Hackers break into websites, steal information …

VICE Joseph Cox

Context & Ripple Effects

Joseph Cox's reporting puts law enforcement on the buying side of the breach-data trade: rather than serving a subpoena or warrant, investigators purchase access to stolen password and IP databases directly. The market has a documented history — LeakedSource sold access to billions of compromised credentials before it was taken offline following an alleged police raid, meaning the state has simultaneously raided this trade and shopped in it.

The traffic runs both ways. Later coverage showed hackers hijacking law enforcement email accounts to fire off Emergency Data Requests that ISPs and social networks honor quickly — so criminals exploit police legal shortcuts while police exploit criminal loot. A breach of police-app vendor ODIN exposed raid plans and AWS keys, underscoring how porous both sides' systems are.

First-order effects

  • Investigators gain immediate access to credentials, IP addresses, and account data without a subpoena, warrant, or paper trail, and the targeted individuals get no notification because no legal process was ever triggered.
  • Every company whose user database has been breached becomes an unwitting police data source, with its users' information queried by agencies under commercial terms instead of legal ones.

Second-order effects

  • Breach-data brokers face escalating legal exposure on the LeakedSource precedent — raids shut sellers down — pushing the trade toward more opaque resale chains that make provenance and consent checks impossible.
  • Platforms receiving Emergency Data Requests now have to treat the request channel itself as attackable, since compromised police mailboxes have been used to extract user data fraudulently.

Third-order effects

  • If both directions hold — cops buying stolen data, hackers spoofing cops — the warrant-and-notification framework stops being the operative boundary between state surveillance and crime, and pressure builds for verified, auditable channels for government data requests.
  • Breach disclosures acquire a second cost beyond remediation: leaked credentials become reusable investigative inputs, giving companies a structural incentive to limit what detail reaches any third party, legitimate or not.

The trend: Law enforcement and criminal actors are converging on the same illicit breach-data markets, with formal legal process becoming optional for both sides.

Discussion

  • @josephfcox Joseph Cox on x
    They added in the human trafficking context that this can mean using breached data to link a real person to a predatory account https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    A lot of hacked data is very publicly available. Here, SpyCloud (the company selling this access) is more just making it easier to search for police. But lots of data is harder to get, arguably not public, and SpyCloud has to hunt it out to then sell https://www.vice.com/... http…
  • @gossithedog Kevin Beaumont on x
    Between cops routinely paying their own ransomware and now buying hacked data, we really are empowering police in the US to pay criminals, to keep their jobs. https://twitter.com/...
  • @adam_k_levin Adam Levin on x
    Police are buying breached data in the hope that it can generate investigative leads, with the data including passwords, email addresses, IP addresses, and more. https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    A prosecuting attorney and head of a law enforcement-technologist task force dedicated to fighting human trafficking told them they use breached data. It's not always about prosecuting people, but finding missing persons too https://www.vice.com/... https://twitter.com/...