Back to all lessons
Awareness Lessons
4 months ago

Data Broker Illegally Sells 7 Million Americans' Personal Information to Scammers

Troy Murray exploited weak data protection controls to illegally harvest and sell personal information of 7 million elderly Americans to criminal organizations over seven years. The case highlights how inadequate access controls and data governance can enable massive privacy violations that directly harm vulnerable populations. Organizations must implement strict data handling policies and monitoring to prevent unauthorized collection, use, or sale of personal information, especially for protected groups like the elderly.

Tactical Insight

Immediate actions

  • Implement data classification systems to identify and protect sensitive personal information
  • Establish strict access controls limiting who can view, extract, or transfer personal data
  • Deploy data loss prevention (DLP) tools to monitor and block unauthorized data transfers

Long-term improvements

  • Develop comprehensive data governance policies with regular audits of data handling practices
  • Create legal agreements prohibiting unauthorized use or sale of customer data by employees and contractors
  • Implement privacy-by-design principles in all systems that process personal information

Detection measures

  • Monitor database access logs for unusual data extraction patterns or large-volume queries
  • Set up alerts for bulk data exports or transfers to external systems
  • Conduct regular background checks and ethical reviews for employees with access to sensitive data