This message comes from Capital One. Say hello to stress-free subscription management. Easily track, block or cancel recurring charges right from the Capital One mobile app. Simple as that. Learn more at capitalone.com slash subscriptions, terms and conditions apply. Hey, it's Keith Romer, real quick before the show today. It's election season. NPR has you covered with three podcasts that we are making for you every day.
Number one, the NPR Morning News podcast. Up first, that one comes out 7 a.m. Eastern every weekday. Later on in the day, we have the NPR Politics podcast. Whenever there is big news going down, few hours later, NPR Politics podcast will be out with a show breaking it down.
Finally, there is Consider This. This is the one where NPR covers one big story in depth every weekday evening. So up first in the morning, consider this in the evening and the NPR Politics podcast. Any time, important developments go down. It's like going around the clock, election news survival kit from NPR Podcasts. Okay, thanks for listening. Here's the show.
This is Planet Money from NPR. I recently got a letter in the mail and it's pretty likely you got one of these two. It is the special kind of letter that sometimes gets turned into a Planet Money episode. And that is because this letter is just the tip of an iceberg beneath the water is a profoundly deep mass of bought, sold and stolen personal data. My data and maybe your data too.
I took this letter to Jim Francis. Okay, so I got, where is it? I got a letter from ticket master. It says here. Yeah, it says the date on it July 17th, 2024. Did you get one of these? I did not get one. I'm not a ticket master customer, but my clients got that letter. Jim has clients because he is a lawyer at Francis mailman sumulus. He focuses on consumer protection and class actions.
And he knows all about why ticket master sent these letters. Now it has nothing to do with my last purchase tickets to see future and Metro Bowman because that's how I roll. But everything to do with a data security incident ticket master was hacked and Jim he is suing them on behalf of some disgruntled customers. I mean, who among us is not a disgruntled ticket master customer. So many reasons to be disgruntled with ticket master.
Now ticket master says they are investigating what happened. It is possible some bad actors took my personal data ticket master sent me this letter as a warning. Did ticket master like do this out of the kindness of their heart. Did they just feel bad? They lost my data. Why did they send this?
They would tell you they did it out of the kindness of their heart and they're concerned for their customers. The reality is some if not all states have a data breach notification law requiring the company to notify consumers. The minute they find out that there's a breach.
So sure I was curious about the breach and how it happened, but I can fast Jim. I wasn't actually worried. I mean how bad is it that my data is out there like I'm a little bit like yeah this is not my first data breach rodeo this happens all the time. Why should I even bother carrying.
Well, one of the things that varies among data breaches is the nature of the information if somebody has all of your information your name your date of birth your social security number your address your personal habits things like that that is significant and that is serious.
And you do have to be vigilant probably for forever because of that now if it was something just forever your forever if it was just your zip code for example right okay but what we understand to be the case here is this is a wide variety and a wide net of PII Amanda they've maybe got your PII or personally identifiable information.
So things like your social security number your cell phone number PII is kind of the jackpot of data yeah Jim says that could make me a victim of identity fraud a target for phone scams someone could try to get a new credit card in my name that would be bad. And whatever was leaked in the ticket master breach that is just some of the data about me that exists online.
You know one of the things that I have just learned over the years you know almost 25 years of doing this is that the amount of consumer data that's collected is just it's mind boggling you know it's your voting affiliation your religious affiliation your addresses what type of clothes you buy your key strokes your fingerprints your shopping habits your everything right you leave a trail and a footprint wherever you go and whatever you want to do.
Of course this isn't just about my trail and my footprint yeah Jim says that the ticket master breach was part of an even bigger hack impacting the customers of lots of companies so this is like potentially hundreds and hundreds of millions of people. Yeah that's huge lot of these data breaches are huge this one's particularly large. Oh God. Amanda it sounds like Jim is maybe starting to stress you out a little bit there I don't know why you think that.
Hello and welcome to Planet Money I'm Keith Romer Amanda we have to keep making the show. She need a second you go on ahead I'll catch up. Okay and that's Amanda Aronchick today on the show the ticket master data breach. We are going to follow this all the way to find out where did my data go how scared should I be and what am I supposed to do about it. And how the personal and private information for all of us is being bought sold and stolen.
This message comes from NPR sponsor at Lassian at Lassian makes the team collaboration software that powers enterprise businesses around the world including over 80% of the Fortune 500 with at Lassian's AI powered software like Jira confluence and loom you'll have more time to do the work that matters. In fact at Lassian customers experience a 25% reduction in project duration per year unleash the potential of your team at at Lassian dot com.
This election season you can expect to hear a lot of news some of it meaningful much of it not give the up first podcast 15 minutes sometimes little less and will help you sort it out what's going on around the world and at home three stories 15 minutes up first every day. Listen every morning wherever you get your podcasts.
Amanda your growing paranoia is basically right yeah I figured yeah our data is being compromised more and more often the number of data breaches has been steadily ticking upwards for two decades and 2023 was I guess a banner year for data breaches. Yeah it's it's a little too soon to say but 2024 could set a new new record. So where did my stolen ticket master data go.
What exactly was taken the letter from ticket master says it's just my name my basic contact info payment card info which is bad. That's bad but Jim the lawyer suggested the people who stole it might have had much more than that. We sent what we knew about the breach to friend of the show Skyler Dvene he is the former director of technology at WNYC the NPR station here in New York. He agreed to help us try to track down your data Amanda find out where it went.
Okay so Skyler you and I are setting up our computers maybe I should make a zoom link. Yeah why don't you send me that by email I guess. Okay apparently after failing to get ransom money from ticket master a hacker group called shiny hunters posted the data for sale for half a million dollars on a dark website called breach forums. So Skyler and I decided to log on to breach forums and see if we could find the data ourselves. I don't think you're going to want to click on any media on the site.
Okay okay. So this is not a place where we just freely click. If you've heard of places like 4chan yeah you know there's going to be a lot of racial slurs and horrible language. Okay. People hang out there. Obviously we want to be careful here and we do not advise you to do this at home dear listener. Skyler has created an anonymous account for us. He set up a private window that makes us hard to track. Skyler is a low key IT guy. He's unfazed but he's still prepared for anything.
Now I'll admit I was expecting something different. We would download a special browser and we'd be visiting like the infamous Silk Road which was apparently the best place online for fireworks cocaine porn social security numbers. I swear I wouldn't know. No no no I would you know. This is a web forum. It is dedicated to the buying and selling of stolen data. Looks a little bit like Reddit but the background is all black. Can we find the ticket master data here? Oh probably not anymore.
I think this is a very like ephemeral chat system. So we just poke around. The forum is actually somewhat gamified reminds me a little bit of dual-lingo. Keep your stolen data streak alive. Exactly. There is this ranking system. You can be a VIP data seller or an MVP or top level and actual God selling stolen data. Yesterday Skyler says he saw posts offering more than 57,000 lines of data from BCP, the largest bank in Peru. And close to 155,000 lines of data from Banco, Fala Bella in Chile.
Today there is some juicy US data. This appears to be somebody selling social security numbers. Can we look at that? Yeah so let's take a look. So up at the top they give a list of the fields that they're providing. First name, last name, email, mailing address, your phone numbers, social security number, data birth drivers. Skyler explains that this is the hackers posting a summary of the data fields they have. And then below that there's a little sampler.
Maybe the details they have for five or ten different people. Now you usually only have one social security number. You only get one date of birth. And once someone has those details about you, it's not like you can ever get them back. Yeah, these are incredibly valuable pieces of personally identifying information. They are really helpful if somebody wants to steal your identity. But we were not here to just look at any old data breach.
We were looking for my data specifically, that ticket master data. Can you scroll up for a second? Yeah. And then as we start to poke around the message boards, can we look for shiny hunters? Like is there way to search this? Let's see, shiny hunters. Band. Their name is crossed out. We have no clue why. We figure we have reached a dead end. But we continue to search the word ticket master. And then we notice something a little odd. A post from a user with an avatar like shiny hunters.
The avatar is from Pokemon. But it is a different username. Spider hunters. And apparently they are an MVP at selling stolen data. And the first has a big ticket master logo right at the top. Ticket master will not respond to request to buy data from us. They care not for the privacy of 680 million customers. So give you the first million users free. What do you make of this? I mean, it certainly looks related, right? And the timing somewhat matches.
Skylar, I think you found the ticket master data bleak. It certainly looks like it could be. Now, my data is not part of the tiny sample that is posted here. But if someone bought my ticket master data, they would presumably have a lot on me. And they could combine it with data that was compromised in some other data breach. Maybe they could get into my phone or my eye cloud or my bank account. The only way we could know for sure is if we went and bought that data.
But as much as we get money, like to get our hands dirty, learning about the economy, we did not get permission to buy stolen data on the dark web. But we have learned a lot about this market. It is brazen, it is bustling, and it is organized. Skylar does point out that we shouldn't necessarily take all of this at face value. Some of the people in this forum might actually work on the security side of things. The FBI has actually shut down the site multiple times.
It's even possible the entire site is a honey pot, just a way to monitor and trap hackers. Still, just in case this is a real post, Amanda, you went ahead and sent a message to spider hunters to ask if they wanted to discuss your data. Spider hunters, by the way, is not spelled the way you might expect. It's SP1D3. You don't have to worry about that part. Oh, I just feel like it's more respectful. It's more respectful. Yeah, here we go. Hello, spider hunters.
And one of the hosts of the NPR show Planet Money, where a popular NPR podcast that covers business, finance, and economics, is this too much? Does this seem like I'm just asking for them to donate as a listener? Uh... We finished the email. I had one of those emojis with the tongue out because we're fun like that. Also, an email address they can reach us at, and we hit send. I do not leave my own personal contact info though, because hey, they already have it.
So, while we wait to see if we get a response from spider hunters, we decide that the next thing we need to do is figure out how Amanda's data was stolen. What exactly happened? And this leads us to an equally unsettling market for our data, the legal market, where our personal information is bought and sold every day. That's after the break. If you enjoy Planet Money, you should try out NPR+.
With Planet Money Plus, you get sponsor-free listening and exclusive bonus episodes from just this show. But you can upgrade to the NPR Plus bundle and access perks from over 20 of NPR's most popular podcasts and more. Give a little, get a lot in return. Visit plus.npr.org. Hey there, it's Tamer Keith. I cover the White House. I know this is hard to believe, but one day, the election will be over. Then, the winner gets a lot more powerful. It's my job to report on what they do with that power.
That's public accountability, but it's not possible without public support. So please support our work. Sign up for NPR Plus. Go to plus.npr.org. Studies have shown that elections can spike feelings of stress and anxiety. That's why NPR's pop culture happy hours there to help you feel more grounded as we talk about the busiest TV movies and music. Try a show on HBO's industry or a roundtable on rom-coms to take a step back from the news of the day, at least before you plunge back in tomorrow.
New episodes every week on pop culture happy hour from NPR. Support for NPR and the following message come from the Walton Family Foundation, working to create access to opportunity for people in communities by tackling tough social and environmental problems. More information is at WaltonFamilyFoundation.org. In my letter from Ticketmaster, they say that my data was stolen from an unnamed data services provider. Turns out this is a tech company called Snowflake.
Snowflake does data storage and analysis. Basically, if you are a company that needs to keep a lot of data somewhere, Snowflake could be like your warehouse for it. That's what they are for Ticketmaster for at least some of their user data. By the way, we did write to Ticketmaster and to Snowflake, but they didn't get back to us in time for this episode. Now, one thing that is not spelled out in Amanda's original data breach letter is how her data was stolen. But here's what we found out.
Back in April, a cybersecurity company started noticing something suspicious. Some bad actor or bad actors was targeting Snowflake and some of the companies that use Snowflake. Companies like AT&T, Advanced Auto Parts, Neiman Marcus, Cricket Wireless, the cybersecurity researchers figured out that hackers had stolen a bunch of Snowflake customer logins. These were the logins that, like Ticketmaster or AT&T would use to access their data on Snowflake.
So obviously, somebody should have changed their password. People change your passwords. These accounts were also not set up with two-step authentication, you know, where you're logging in and then you get asked for your password and then you also get your cell phone ping for another code, two steps to confirm that it is actually you trying to access your sensitive and valuable data. People turn on two-step authentication.
Ticketmaster and Snowflake did not require users to use two-step authentication. So it was like there was a little window that was easy to pry open and the bad actor went right through that window and stole the data of millions of people. Including probably my data. Did you get one of these? I did get one of these as a fellow Ticketmaster user. Okay. Justin Sherman thinks his most recent Ticketmaster purchase was Tickets to Sizzle,
aside from loving contemporary R&B. Justin also founded a company called Global Cyber Strategies in DC. And he's the go-to guy for all things cybersecurity, data privacy, AI. Justin says that Snowflake, the company at the center of the breach, their business isn't just about storing and analyzing data. They also operate a data broker marketplace. And it's like eBay for your data. You type in health or location, you hit enter, you add to cart and you check out.
This data marketplace is part of a multi-billion dollar industry that makes its money off of the buying and selling of personal information. A lot of personal information. How many pieces of data about me do you think are out there? I'm glad you asked this question. So there are single companies that sell 13 or 14,000 plus data points on one person. Okay. Okay. So let me get my, I'm going to break this down for me. So one data point is my first name. One data point is my last name.
One data point is my data birth. What are the other 12,997 other data points? Let's put it this way. If you think of every single moment of your life that can be tracked, those are the kinds of data points that can be bought and sold. Yeah, that's how a lot of the internet gets paid for. We get to use websites for free. And those websites make money by collecting data about us and selling that data on to whoever will pay for it.
And what has been happening over the last decade is some companies have collected a truly astounding amount of data. Justin says they've become these giant centralized repositories for all of our personal information. We all know the saying don't put all your eggs in one basket. Yeah. My 13,000 eggs.
Exactly. When the companies or government agencies take thousands of those eggs on hundreds of millions of people and plop them in one place, you're building a really attractive target where if someone gets in, all of this aggregated commercial data is sitting there ready for the taking. So in many ways, the illegal market depends on the legal market on all of these companies collecting all of our information. Now, Justin isn't just worried about hackers stealing our data.
He has also really troubled by this fundamental invasion of our privacy online. How these companies buy and sell our personal information on the legal market. So the next thing he wants to show me is part of that legal marketplace. It's a website that sells lists of senior citizens. So what we're looking at here is a database that it says, quote, gives you access to seniors who are currently being cared for by an adult child or family member. So this is people who require pretty extensive care.
Seniors who require care. These are people who require extensive care. There are over 20 million people in this database. It is for sale. And you'll see here that it includes ways you can contact these people. They're postal information, their email, and much more. And this isn't like scurrying around the law. Like this is legal legal. This is driving down the highway, mind and my own business legal. This site says it is a direct marketing company.
Their business is selling lists of people who fit certain demographics. What's really horrible is there's a phrase suckers lists. And this refers to exactly what we're looking at on the screen. It refers to databases about people that companies have determined or gullible. This is often elderly people and often includes diminished cognitive capacity. So suffering from Alzheimer's or dementia. And the reason they're called suckers lists is scammers love these lists of people.
It is creepy enough when I imagine a bunch of cyber criminals buying and selling my data. But it's even creepier when it is happening in the legal market. So what are the rules governing that giant basket of my 13,000 eggs? To find out, we called up a regulator, not just any regulator, but the director of the Consumer Financial Protection Bureau, Rohit Chopra. Of course, the first thing I do is show him my letter from ticket master. Did you get one of these? Oh, the breach notification letter.
Yeah, I got that. Look, I get these things on an almost monthly basis. CFPB directors, they're just like us. For director Chopra, his downfall was buying tickets for the Eagles, the football team, not the band. Go birds. Yeah, very authentic. Thank you. So back to the reason I reached out to director Chopra, the rules. Now, there is, of course, HIPAA, which prevents your doctor from selling your private health information. There's also a law protecting students.
Some states have their own privacy laws too. Really though, director Chopra says there is not much more than that. In the US, we don't have that many laws that put restrictions on the type of data you can harvest on people, except really for one, the Fair Credit Reporting Act of 1970. Before 1970, all kinds of businesses in the US kept track of all sorts of personal information. We've had a long history in our country of companies digging up dirt on all of us. Did we pay our bills on time?
Who are we associating ourselves with? Are we cheating on our spouse? Companies would sell reports about us, about our character, about who's a good one, and who's laid on their bills. Director Chopra is talking about credit reporting, and the company is that determine what today we call your credit score. Isn't this sort of a service? Like this is how commerce works. You need to know if somebody is worthy of credit, worthy of loans. Maybe it's a very reasonable thing to do.
Well, I think where the concerns were was the consumer never really consented to any of this. The reports that were about them could have been totally inaccurate or just full of rumors. And I think there was a sense in the Congress that there needs to be some limits on this, because it isn't just creepy, it really felt unfair. Tense the Fair Credit Reporting Act of 1970.
It's been amended a few times since then, but basically the law requires that credit bureaus make sure the information they have is accurate. Make sure a consumer can access these reports, and that people can dispute anything that's not accurate. And these credit bureaus can't just sell this data to anyone that wants it. It is for potential employers or potential lenders or potential insurers, that kind of thing. That is how our data is supposed to be managed.
But when we actually look at today's economy, we see a lot of other companies who are essentially doing the same exact thing. Selling our background information, digging up dirt on us for companies that want to sell things to us using targeted marketing. And these data brokers, they don't usually consider themselves covered by this law. They say they're not credit bureaus. Even though they might be selling things like info about our salaries.
So we are developing rules that will bring some sanity into how our personal data is handled. And in many cases, on whether it should be trafficked at all. The idea is for these new rules to extend some of the protections that are in the Fair Credit Reporting Act to the other companies that have a lot of our data. The CFPB says they're publishing these proposed rules soon. But for now, without more regulation, I guess this is on me. My data is out there doing godly knows what.
And it seems there's not much I can do about it. The most obvious thing I can do is in that original letter from Ticketmaster. They have offered me free credit monitoring. I asked Jim the lawyer to help me decide whether or not I should take it. You will have access to one or more credit monitoring services through one of the big three credit bureaus, TransUnion Equifax or Experien. So basically one of those big three credit bureaus will monitor my online info.
In my case, it's going to be TransUnion. Yeah, if spider hunters sold your data to a bunch of scammers, they might try to get a credit card in your name, steal your identity, puno's. And this monthly report will let you know if something like that actually happens. By the way, spider hunters never did message me back. I will probably never know where my data ended up. So maybe credit monitoring is a good option. Jim and I look at the offer together. Okay, and have a code.
Careful. So, yeah, so should I not do this or should I put in my activate now? Well, let's see, hang on a second. Yeah, just look here to see terms and conditions. Oh, this is so great to look at terms and conditions with a lawyer. Oh, yeah, very helpful. It says right here, if you click on it, the terms and conditions below contain an arbitration agreement and a class action waiver. There you go. So you're out of the class and you can't bring a class action against TransUnion.
So basically, if I take the free credit monitoring service, I waive my right to Sue. Then Jim says, let us take a closer look at some of the other terms and conditions. Oh, by the way, by accessing credit view dashboard, you agree that TransUnion may use and share your information? No. Yes. So the company that you're hiring to protect you is using this as a grab bag to sell your data. Jim points to the very bottom of TransUnion's website. In small font, there are the words privacy policy.
If you click that link, you will find pages and pages about all the ways in which they disregard your privacy. So it says when you enroll, TransUnion is collecting the usuals. My cell number, my date of birth, my social security number, and this privacy policy is saying that they may also start collecting and selling more personal information. My ethnicity, my real status, where I work, where I am, what I've been putting into online forms, how long it took me to fill in those online forms.
Oh, and everything I buy, everywhere I go, and everything I do online. So you clicked in as something as a result of a data breach to use their credit monitoring service and you've just agreed for them to share all of your data and use it basically however they want. Oh, it's really bad. Jim, it's so bad. It's so cynical. It's so bad. It's bad. It's bad.
We reached out to TransUnion. A spokesman said that the arbitration waiver, the part where Amanda had to waive her right to sue them, that was posted in error. We checked, and it has now been removed. A spokesman also said when Amanda logged in to get her credit monitoring that she was using a product called My True Identity. That the information TransUnion requests when consumers enroll in My True Identity is, quote, essential for verifying their identities and providing the requested services.
And that My True Identity does not sell consumers personal information to any third party for any reason. End quote. So TransUnion is saying that no, they will not sell my usuals, my cell number, my date of birth, my social security number. They won't sell the information that I gave them to enroll in this program. But I definitely had to agree to their privacy policy, which today it's pretty clearly that they're going to collect other personal information and maybe sell that.
And who knows, what if that data someday gets stolen in a data breach by a hacker? Which I mean, it feels like we're back at the beginning of the episode of end. Yeah, we might as well just start it again. Little Mobius strip planet money. There you go. We could just play it over and over and over again endlessly. Has it started? It starts like this. Okay, hold on. Wait, wait. What's this over here? Oh, it's my letter from ticket master. Did you get one of these?
Oh, uh, yeah, I did get one of those. No, you don't lie. Oh, I didn't get one Amanda. Let me tell you what it says right here. Notice of data breach. Oh, it's bad. Today's episode was produced by Sam Yellow Horse Kessler and edited by Meg Kramer, engineered by Kho Takasovie Chernovin with an assist from Crazy Lee and fact checked by Danya Sulema. Outspot Mark is our executive producer. Thanks this week to Brent Braseland at Piper Sandler, Joel Fishbine at Truest Securities and Troy Hunt.
I'm Keith Rover and I'm Amanda Aronchick. This is NPR. Thanks for listening. Once again, we find ourselves in an unprecedented election. And with all that's happening in the lead up to the big day, a weekly podcast just won't cut it. Get a better grasp of where we stand as a nation every weekday. On the NPR Politics Podcast, here are seasoned reporters digging into the issues that are shaping voters decisions. And understand how the latest updates play into the bigger picture.
The NPR Politics Podcast, listen on Spotify. As we're all navigating a device of election, no matter what happens, the question remains how the heck are we going to move forward together. So in this season of the Storycore Podcast from NPR, stories from people who made a choice to confront the conflicts in their own lives head on. And in sharing stories from the bravest among us, maybe we can take their lead and find some hope for the rest of us. Get the Storycore Podcast wherever you listen.
Listening to the news can feel like a journey, but the 1A Podcast guides you beyond the headlines and cuts through the noise. Listen to 1A where we celebrate your freedom to listen by getting to the heart of the story together, only from NPR.