Data Brokers, Scams and $20 Billion: What Senator Hassan's Report Found About Hidden Opt-Out Pages

On February 27, 2026, Senator Maggie Hassan (D-NH), Ranking Member of Congress's Joint Economic Committee, released a report on data brokers, scams and the losses that connect them. It puts a figure on that connection for the first time: identity theft flowing from just four data broker breaches has cost U.S. consumers more than $20 billion. The same investigation documents a smaller, stranger finding. Five registered data brokers had coded their opt-out pages so search engines would not show them. After a senator's staff asked why, four of the five removed the code. The fifth never answered.

Who wrote the report, and what the $20 billion measures

The document is a Joint Economic Committee Minority report, written by Hassan's staff, titled "Opt-Out Obstacles". The headline number is not broker revenue and not a guess at total harm. It is an estimate of what consumers lost to identity theft after four specific breaches at companies the report treats as data brokers: Equifax in 2017 (147 million U.S. residents exposed), Exactis in 2018 (230 million), National Public Data (about 270 million; the report dates it to 2023, and it became public in 2024) and TransUnion in 2025 (4.4 million).

The method is laid out in the report. Staff started from a Javelin finding that just over 30 percent of breach victims experienced identity theft in 2017, cut that share by 10 percent a year to stay conservative, applied Bureau of Justice Statistics figures on how many identity theft victims actually lose money (58 to 69 percent, depending on the year), and multiplied by the BJS median loss of $200. Summed across the four breaches, that is $20.9 billion in nominal losses. Other broker breaches were left out only because nobody published a U.S.-resident count for them; the 2019 People Data Labs leak of 622 million records is the example the report gives. The $200 median is also low compared with what courts have recognized: the Equifax settlement allowed claims up to $20,000 per person.

CalMatters covered the release the same day, rounding the figure to $21 billion. If you want the wider set of numbers on how often breached records circulate, our identity theft statistics page collects them.

The hidden opt-out pages: five brokers, one line of code

In August 2025, WIRED reported that more than 30 registered data brokers had placed "no index" code on the pages where consumers request that their data be deleted or not sold. A no-index tag tells Google and other search engines to leave a page out of results. The page still exists, and the company can still say it offers an opt-out. It just cannot be found by the way most people look for anything.

On August 13, 2025, Hassan sent inquiry letters to five of the companies WIRED had named: Comscore, Findem, IQVIA Digital, Telesign and 6sense Insights. The letters asked each to explain the design of its opt-out, disclose any code excluding privacy pages from search, share any audits of opt-out visibility or success rates, and say what it had changed since the WIRED story. Responses were due September 3, 2025.

What each company did after the letter

The report's table is more interesting than the summary, because the five companies reacted five different ways.

  • Comscore reviewed its site, confirmed its "Data Subject Rights" page had carried no-index code, attributed it to an earlier version of the page, and removed it.
  • Telesign removed the code from its "Privacy Request" page and added a footer link to it. Telesign also argued its opt-out had always been reachable, because a form hosted on its vendor OneTrust's site did appear in search results, which is true and also means a consumer would have had to find a third-party page titled "Telesign Privacy Rights Form" to exercise a right against Telesign.
  • 6sense disputed WIRED's framing, saying its "Privacy Center" page was indexed all along, but confirmed that its "Privacy Policy" page, which links to the opt-out form, had carried the code (to limit spam, it said) and that it removed the code after the story ran. 6sense was also the only one of the five that told the committee it hires third-party auditors to check both opt-out visibility and how often requests succeed.
  • IQVIA told the committee in September 2025 it had replaced its old "Your Privacy Choices" page with a new one built under a June 2025 OneTrust contract, and that the new page carries no such code. In an earlier response it had said it had no plans to remove the code from the old page, partly on the theory that no-index does not actually hide a page and that people could find the opt-out through a Google AI Overview; when committee staff searched "IQVIA privacy opt-out form", the overview they got did not link to the page.
  • Findem did not respond to the senator's letter or to repeated follow-up from committee staff. As of the report, its "Do not sell or share my personal information" page still carries the no-index code, and the report notes that Findem's own 2024 disclosures show it declined to process 80 percent of the privacy requests it received, citing "insufficient data."

Four fixes out of five is a real result. It also took a Senate committee's letterhead to get it, and Findem's non-response cost it nothing, because a Minority report has no enforcement power. State regulators do, and California's has been fining brokers under its Delete Act since August 2026.

How data brokers turn into scams' raw material

The report's mechanism is simple. Brokers hold Social Security numbers, home addresses, family relationships and, in some cases, banking details. When that data leaks (through a breach) or is sold to the wrong buyer, scammers use the details to build a script that sounds legitimate.

Compare two versions of the same call. In the generic version, someone claiming to be from your bank's fraud department asks you to confirm your account number, and most people who have heard the pitch hang up. In the version built on broker data, the caller reads your home address back to you as proof of legitimacy, names your adult daughter because she appears next to you in a people-search listing, and mentions a recent large purchase that lines up with a marketing file. None of that came from your bank. It came from a broker file, and the small accurate details are what make the call work. Our guide to social engineering attacks covers the scripts in more depth.

Why data brokers, scams and hidden pages keep showing up together

Five companies received formal letters. Hundreds of brokers are registered in California alone, and most will never hear from a senator. The report frames its findings as one thread of a wider inquiry into scams that also covers satellite internet providers, dating platforms, AI companies and federal agencies, which is a fair signal of how much of the problem sits outside any one industry.

The no-index tactic also isn't unique to ad-tech brokers, and it isn't only a search-engine problem. In our own removal work, PeopleConnect's suppression center, which covers TruthFinder, Intelius and Instant Checkmate, lives on a subdomain none of the consumer brands link to prominently, and it asks for your email, name and date of birth before it shows you anything (our PeopleConnect guide walks it). On FastPeopleSearch, the opt-out is reached from a footer "Do Not Sell or Share" link, the form arrives as an emailed link that expires in 24 hours, and the identical flow runs on its sister sites. Nothing about those pages is illegal. They are simply designed so that the path of least resistance is to give up.

What actually protects you

A report can name companies and get four of them to change a line of code. It cannot remove your listing from the brokers that never got a letter, and it cannot undo the four breaches it priced. The National Public Data example makes the point: the site that lost an estimated 270 million Social Security numbers is back online under new ownership, serving names, addresses and relatives, and opting out of the relaunched site does nothing about the data that left with the hackers in 2024. Our guide to where brokers get your information explains why that supply chain restocks the listings after you remove them.

What is in your control is narrower and more tedious: find each listing, file each opt-out, and check again, because scrubbed profiles reappear when brokers re-ingest public records. Delist My Data is being built to do that work on a schedule and re-file when a listing comes back. We're in pre-launch; join the waitlist for founding-member access.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.