Data brokers, impersonation networks, and AI moderation systems now share a common failure mode: automated loops that exhaust the users and enterprises they claim to serve.
A career consultant found several fake LinkedIn profiles impersonating a colleague. She reported them. What came back was a string of automated replies and boilerplate policy citations. No human ever looked at the case. If you’ve tried to remove your information from a data broker site, or report a deepfake impersonation on social media, you already know this feeling. It’s the phone tree that never lets you talk to a person, no matter how many times you press zero and swear at your phone.
For security teams, that’s not just a bad user experience story. Automation deployed without accountability becomes its own attack surface. And attackers are already exploiting it faster than platforms can respond.
The Data Broker Economy Runs on Non-Consent
Data brokers collect and resell personal information: Social Security numbers, home addresses, financial behavior, health data, political leanings. Most of it gathered without anything close to meaningful consent. The industry pulls in an estimated $300 billion a year doing this. Pile up that much sensitive data with almost no oversight, and the outcome is predictable. The 2024 National Public Data breach exposed records for more than 170 million Americans. A separate incident in October 2025 aggregated roughly two billion email addresses pulled from broker databases and malware-infected devices.
The Electronic Privacy Information Center has documented cases where brokers exposed a domestic violence survivor’s address or workplace to an abuser. Some survivors avoid legal help or new jobs for exactly this reason, because each of those steps creates a fresh record a broker can turn around and sell. Regulation hasn’t caught up. The Consumer Financial Protection Bureau withdrew its proposed data broker protection rule back in May 2025.
This goes beyond compliance checkboxes. Broker-aggregated PII feeds social engineering, executive impersonation, and targeted phishing. And once a record enters the resale chain, the blast radius is continuous.
Opt-Out Requests Are Built to Fail
The removal process is a case study in adversarial design, honestly. An email request gets redirected to an opt-out form. The form generates an automated denial, usually citing a state privacy law that doesn’t even apply to you. The denial invites an appeal by replying to the same email address. That reply triggers another auto-response saying the inbox doesn’t handle privacy requests, and pointing you right back to the form.
Nothing about that loop is broken. It works exactly as designed, just not for the person stuck inside it. Senator Maggie Hassan’s investigation in August 2025 found that several registered data brokers were deliberately hiding their opt-out pages from search engines. A Joint Economic Committee report from February 2026 called the pattern what it is: an “opt-out obstacle course” built for attrition, not compliance. Multiply that loop across the hundreds of brokers reselling the same record, and exercising a basic privacy right becomes an unpaid, full-time job with no guaranteed payoff at the end.
Impersonation at Platform Scale
LinkedIn is a good illustration of how big this has gotten. Its most recent Community Report, covering the first half of 2025, put automated fake-account removals at roughly 83.8 million. The same report logged more than 117 million spam or scam incidents in that six-month window. Attackers build fake executive profiles out of scraped photos, job titles, and mutual connections, then use them to request wire transfers or credentials from employees who have no reason to doubt a message that looks like it came from their CEO. Why would they? The FTC recorded job-scam losses climbing from $90 million in 2020 to $501 million in 2024.
When victims report incidents, PEN America’s “Shouting Into the Void” research found reporting systems built to process complaints in bulk, not evaluate individual harm. Most have no way to weigh a pattern of repeated or coordinated abuse. Every report gets treated like it’s the first and only one, even when it’s the fiftieth.
Moderation as a Liability Shield
Platforms frame AI moderation as a scale necessity, and given the volume of content involved, that argument isn’t entirely wrong. But automation also functions as a liability shield. Users can’t appeal to it. It doesn’t recognize context. And it gives management something to point to when someone asks why a coordinated harassment or impersonation campaign went unaddressed for months. Research on moderation accessibility across Facebook and X found these gaps hit already-targeted and marginalized users hardest, which tracks. The Twitter Trust and Safety cuts after 2022 make the point well: human review capacity dropped, harassment rose, and people left.
The Agentic Internet Changes the Threat Model
The industry has a name for where this is heading: the “agentic internet,” where autonomous AI systems act on users’ behalf with little human oversight at each step. Gartner projects 40% of enterprise applications will integrate task-specific AI agents by the end of 2026.
There’s a governance problem sitting underneath all of this too. The IAPP has pointed out that agentic systems blur the line between data controller and data processor, so it’s often genuinely unclear who’s responsible when an automated system wrongly denies an opt-out or dismisses an impersonation report. That’s exactly the kind of accountability gap attackers are learning to work inside.
The Takeaway for Security Teams
Things like the data broker ecosystem, impersonation, automated content moderation and all the AI agents being deployed across the internet all have the same root problem: each one strips human accountability out of a process that carries real security consequences, for individuals and for the companies whose executives and workforce get impersonated at scale. The loops that wear down legitimate users run on the same logic that gives attackers room to operate. Both depend on nobody getting a human to actually look.
What all of this points to is a new kind of attack surface, one made of people instead of endpoints. The people stuck in these systems aren’t abstractions in a report. They’re the survivor whose address stays findable because a broker’s appeal process loops back on itself. The professional whose name gets used to scam their own clients while the platform tells them no violation was found. The employee who wires money to a fake executive because nothing flagged the impersonation. Attackers don’t need to breach a firewall when when the agentic internet provides the path of least resistance.
Join our LinkedIn group Information Security Community!
