Personal data about U.S. government employees, military personnel, veterans, and their families is widely available through commercial data brokers and people-search sites.
Research, intelligence and policy documents, congressional findings, and federal court decisions have identified foreign-adversary access to Americans’ sensitive personal data as a national-security risk. This information can support intelligence gathering, surveillance, profiling, spearphishing, impersonation, coercion, blackmail, and other targeting activity.

Data brokers openly advertise government and military data
A 2021 report from Duke University’s Sanford School of Public Policy examined ten major data brokers and separately analyzed multiple people-search websites.
The report found brokers openly advertising sensitive information about current U.S. government employees, current and former members of the military, and other U.S. individuals. It also found that people-search sites made it possible to locate the home addresses, phone numbers, relatives, and other personal details of senior military personnel.
The report identified several potential applications for this information. Foreign intelligence organizations could use broker data to build profiles of politicians, diplomats, civil servants, intelligence personnel, military leaders, and their families. Those profiles could support intelligence collection, surveillance, information operations, coercion, and blackmail.
Individually identifiable military data can be purchased cheaply
A 2023 Duke University study examined the sale of personal information about active-duty service members, veterans, and their families.
Researchers scraped 533 data brokers’ websites and found 7,728 hits for the word “military” and 6,776 hits for the word “veteran.” They contacted twelve brokers and purchased military-related data from three.
In one phase of the research, the buyers used a .asia domain, an associated email address, and a Singaporean IP address. Among the purchases were:
- Records on 5,000 active-duty service members and veterans in Washington, D.C., Maryland, and Virginia containing names, home addresses, email addresses, and mobile phone numbers. The records cost $0.32 per person.
- Records on 5,000 active-duty service members and veterans containing names, home addresses, phone numbers, email addresses, age, sex, marital status, homeownership, home value, and personal interests. The records cost $0.12 per person.
- Records on 5,048 military personnel in Fort Bragg, Fort A.P. Hill, Quantico, Washington, D.C., Maryland, and Virginia. The data included names, home addresses, email addresses, age, gender, net worth, occupation, education, marital status, ethnicity, language, religion, credit rating, and information about their children. The records cost $0.25 per person.
Across the datasets purchased for the study, prices ranged from $0.12 to $0.32 per record. The researchers also found broker advertisements offering data for as little as $0.01 per record when purchased at scale.
The authors concluded that this information could be used by foreign and malicious actors to profile and target active-duty personnel, veterans, their families, and their acquaintances.
Commercial data can provide a low-cost intelligence resource
A 2021 report published by the NATO-accredited NATO Strategic Communications Centre of Excellence examined the security implications of commercial data brokerage.
The report described the information held by data brokers as a “treasure trove for malicious actors.”
The report found that commercially available data can give hostile states, terrorist organizations, and other malicious actors access to sensitive information without the cost and operational requirements associated with traditional intelligence collection.
It identified potential uses including:
- Identifying and profiling military and government personnel
- Spearphishing and impersonation
- Extortion, blackmail, and doxing
- Identity theft
- Surveillance and intelligence gathering
- Tracking personnel movements
- Identifying military facilities, operations, and exercises
- Building lists of personnel associated with particular organizations or activities
The report also found inconsistent screening and customer-verification practices across the data-broker industry, creating opportunities for malicious actors to acquire information through commercial channels.
Foreign state actors have targeted large stores of Americans’ personal information
In 2020, the U.S. Department of Justice charged four members of China’s People’s Liberation Army in connection with the 2017 breach of Equifax.
The indictment alleges that the defendants stole names, dates of birth, Social Security numbers, and other personal information belonging to approximately 145 million Americans. The FBI described the incident as the largest known theft of personally identifiable information by state-sponsored actors.
The case illustrates that cyber intrusion is another route through which a foreign state can acquire a large repository of Americans’ personal data.
The risk has been recognized across the U.S. government
The national-security risk extends beyond the findings of individual research organizations. The Department of Justice states that the risks posed by foreign-adversary access to Americans’ sensitive personal data have been repeatedly recognized by all three branches of the U.S. government.
Executive Order 14117 states that countries of concern can use sensitive personal data to track and build profiles of federal employees and contractors for blackmail and espionage. It identifies foreign access through data brokerages as posing “particular and unacceptable risks” to national security.
The 2024 National Counterintelligence Strategy states that foreign intelligence entities are seeking to take advantage of commercially available tools to conduct surveillance and collect large amounts of personal data. A 2024 House Committee on Energy and Commerce report accompanied legislation subsequently enacted as the Protecting Americans’ Data from Foreign Adversaries Act of 2024. The law prohibits data brokers from making personally identifiable sensitive data of U.S. individuals available to any foreign adversary country or any entity controlled by a foreign adversary.
DOJ also cites the Supreme Court’s 2025 decision and the D.C. Circuit’s 2024 decision in TikTok Inc. v. Garland, both of which addressed national-security concerns involving foreign-adversary access to extensive personal information.
The U.S. government is restricting foreign access to sensitive data
The Department of Justice’s Data Security Program, which took effect on April 8, 2025, addresses foreign-adversary access to U.S. Government-related data and Americans’ bulk sensitive personal data through commercial transactions.
The program prohibits covered data-brokerage transactions with countries of concern or covered persons. It also restricts certain vendor, employment, and investment agreements unless applicable security requirements are met. Under the program, government-related data includes sensitive personal data, regardless of volume, that is marketed as linked or linkable to current or recent former U.S. government employees or contractors, or former senior officials, including members of the military and Intelligence Community.
The program also prohibits evasive transactions and places conditions on certain data-brokerage transactions with other foreign persons to address proxies and onward transfers. DOJ identifies espionage, surveillance, counterintelligence, economic espionage, and the development of military and artificial intelligence capabilities among the potential uses of this information.
The exposure risk extends beyond covered foreign transactions
The Data Security Program establishes important controls over foreign access to sensitive personal data through commercial transactions. It prohibits or restricts covered transactions involving countries of concern and covered persons. Its scope, however, is defined by particular transactions and parties. DOJ’s program FAQs state that purely domestic data transactions between U.S. persons generally fall outside the program unless a U.S. person has been designated as a covered person.
Personal information exposed through publicly accessible people-search profiles remains available to malicious actors. Duke’s 2021 research found that anyone could search these sites for senior military personnel and uncover home addresses, phone numbers, relatives, and other personal information. The report describes risks involving criminal organizations, terrorist organizations, domestic terror organizations, and abusive individuals.
Foreign intelligence organizations can also pursue personal data without purchasing it openly under their own identities. The 2021 Duke report identifies front companies and the hacking of data brokers as potential acquisition routes. Duke’s 2023 study found inconsistent customer-verification practices and minimal screening by some brokers, including sales made through a .asia domain without verification of the purchaser’s identity. The Data Security Program’s anti-evasion and onward-transfer provisions are designed to address proxy purchases and indirect transfers.
Cyber intrusion presents a separate acquisition route outside the commercial transactions governed by the program. In the Equifax case noted above, the indictment alleges that members of China’s People’s Liberation Army hacked the company’s systems and stole personal information belonging to approximately 145 million Americans. The case illustrates how a foreign state can acquire a large repository of personal data without engaging in a commercial transaction governed by the program.
The Data Security Program is an important national-security measure, but its transaction controls govern access through covered commercial transactions. They do not remove profiles already exposed through data broker and people-search sites, where the information remains exploitable by a range of malicious actors. Agencies therefore need a complementary way to reduce the personal information publicly available about their personnel and limit the intelligence those actors can gather.
Optery for Business provides:
- Patented search technology that finds 40 to 50 more exposed profiles per person on average than other services
- Automated removals from more than 640 data-broker sites
- Support for more than 1,000 sites through Custom Removals
- Before-and-after screenshots documenting removals
- Recurring monthly scans and removals to address new exposures
- Centralized administration and detailed reporting
- Bulk enrollment and self-service deployment
- SSO/SAML and SCIM integration
- SOC 2 Type II attestation
Government organizations, including those already using another personal-data-removal service, can use Optery’s free scan to identify profiles that remain exposed. Book a demo or contact the Optery team at Carahsoft to begin a free 30-day trial for a select group of high-risk personnel.

