
Darknet Diaries Episode 177 Explores Identity Theft and Data Broker Risks
This episode of Darknet Diaries explores two major stories that highlight the dangers of identity theft, data brokers, and cybercrime. The first story recounts a shocking case of identity theft that spanned over three decades, where a man named Matthew Kierans stole the identity of a homeless coworker, William Woods, and lived under his name for years. The second story delves into the world of data brokers and hackers, focusing on a massive data breach involving National Public Data, a company that collected and sold personal information without consent. Both stories reveal systemic failures in protecting personal data and the devastating consequences for victims. The episode begins with the harrowing tale of William Woods, a homeless man whose wallet was stolen by Matthew Kierans in 1988. Kierans used Woods’ birth certificate and Social Security card to assume his identity, obtaining a driver’s license, bank accounts, and even a high-paying IT job at the University of Iowa. For over 30 years, Kierans lived as William Woods, marrying and starting a family under that name, while the real William remained unaware. The deception unraveled in 2019 when Woods discovered loans taken out in his name and confronted the bank. Instead of recognizing Woods as the victim, authorities accused him of identity fraud, leading to his wrongful arrest, imprisonment, and forced psychiatric treatment. The real culprit, Kierans, was only exposed after a DNA test confirmed Woods’ identity. This story underscores how easily personal information can be exploited and how difficult it is for victims to reclaim their identities, especially when institutions fail to verify claims properly. The technical aspect here involves the misuse of personally identifiable information (PII), such as Social Security numbers and birth certificates, which are often used as the foundation for identity verification systems. The practical implication is the need for stronger identity verification methods, such as biometric data or multi-factor authentication, to prevent such fraud. The second half of the episode shifts to the world of cybercrime and data brokers, focusing on the hacker known as USDoD (later identified as Luan Barbosa) and the data broker National Public Data, run by Salvatore Verini Jr. USDoD gained notoriety for breaching high-profile targets, including the U.S. Department of Defense and the FBI’s InfraGard system, by exploiting vulnerabilities in software and using social engineering tactics. Social engineering involves manipulating people into revealing sensitive information or granting access, often by impersonating trusted individuals. USDoD’s hacking spree culminated in the theft of 2.9 billion records from National Public Data, a company that scraped and sold personal data without consent. The breach exposed names, Social Security numbers, addresses, and other sensitive information, putting millions at risk of identity theft. The episode explains how data brokers like National Public Data operate by collecting public records and purchasing or scraping data from social media, loyalty programs, and other sources. The technical concept here is data scraping, where automated tools extract large amounts of information from websites, often bypassing terms of service. The practical implication is the lack of regulation around data brokers, which allows them to profit from personal data while exposing individuals to significant risks. The breach also highlights the challenges of holding data brokers accountable, as victims often have no recourse when their information is leaked. The episode also explores the broader implications of data privacy and government surveillance. It discusses how agencies like ICE purchase data from brokers to bypass warrant requirements, exploiting a legal loophole that allows them to access personal information without judicial oversight. This raises ethical concerns about privacy rights and the Fourth Amendment, which protects against unreasonable searches and seizures. The episode critiques the lack of transparency and public consent in these practices, arguing that individuals have no control over how their data is collected, stored, or sold. The practical takeaway is the importance of personal privacy measures, such as using encrypted messaging apps like Signal, privacy-focused browsers like Brave, and end-to-end encrypted email providers like Proton. These tools help individuals protect their data from both cybercriminals and overreaching governments. The episode also mentions the failed attempt to pass the American Privacy Rights Act, which would have allowed individuals to opt out of data collection by brokers. The bill’s failure underscores the influence of lobbying and corporate interests in shaping privacy laws, leaving individuals to fend for themselves in protecting their data. In the end, the episode serves as a cautionary tale about the vulnerabilities of personal data in the digital age. It highlights the need for stronger regulations, better identity verification systems, and individual vigilance in safeguarding privacy. The stories of William Woods and the National Public Data breach illustrate how easily identities can be stolen and how difficult it is to recover from such violations. The episode concludes with a call to action for listeners to take proactive steps to protect their privacy, emphasizing that no one else will do it for them.