177: National Public Data

21 Jul 2026 · 48 min · 20 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Identity theft and data brokerage gone catastrophic: a decades-long identity takeover (William Woods vs. Matthew Kearins) and a later breach/black-market sale of massive personal-data troves tied to “National Public Data” and the hacker “USDOD” (Luan Barbosa).

Guests (as presented)

No named podcast guests appear in the transcript. The episode is narrated by Jack Rees Sider and centers on real people described in the story: William Woods, Matthew Kearins, USDOD/Luan Barbosa, and Salvatore “Sal” Verrini Jr. (founder of National Public Data/Records Check).

Key claims

Data brokers scrape/buy sensitive records and can be breached; stolen identity data enables long-term fraud; victims can be misidentified by courts until DNA evidence proves otherwise; Congress’s proposed opt-out privacy law was weakened by lobbying.

Notable examples

1988 wallet theft leading to 31 years of identity use; 2019 bank dispute and wrongful conviction/mental hospitalization; 2022–2023 “National Public Data” leak (2.9 billion records) sold for $3.5M; InfraGard/FBI infiltration via impersonation; identity theft horror stories (loans, credit cards, checks, SIM-swap risks).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Hot Dog Stand Incident

0:45 to 3:03

Exploring how Matthew Kearins stole William Woods' identity.

“he stole William Woods' wallet, the homeless guy that was also working there.”

Living Under a Stolen Identity

3:03 to 5:27

Matthew successfully builds a life using William's identity.

“He was an off the grade kind of guy, so he wasn't filing his taxes or opening bank accounts himself.”

Identity Crisis and Legal Trouble

5:27 to 8:13

William confronts identity fraud but faces legal challenges.

“W-2s, electricity bills, library cards, credit cards, a marriage certificate.”

The Truth Uncovered

8:13 to 9:38

William's truth emerges after years of suffering due to Matthew's fraud.

“and after a year and a half, he served his complete sentence and was able to get out.”

The Truth Uncovered

11:36 to 12:31

William's truth emerges after years of suffering due to Matthew's fraud.

“This year, with AI agents writing code, they're on pace for$14 billion.”

Encountering the Hacker APT

12:36 to 14:01

Exploring a relationship with a mysterious hacker known as USDOD.

“A few years ago, a friend messaged me and said, look out, an APT just followed you on Twitter.”

The Disappearance of USDOD's Love

14:01 to 25:40

Learn about the hacker USDOD's troubled past and how a personal tragedy fueled his hacking spree.

“And I think a year went by, and I just watched him do more and more crazy stuff, and it was hard to tell what was real and what wasn't.”

Salvatore Verrini Jr.'s Rise

25:51 to 28:00

Explore the story of Salvatore Verrini Jr. and his attempts to break into the entertainment industry.

“He wanted to get into the entertainment business and decided to produce and star in his own TV shows.”

Sal's Aspirations and Failures

28:00 to 28:30

Explore Sal's journey from aspiring actor to deputy and his setbacks.

“Sal's personal IMDb page lists his other shows and movies.”

The Rise of Data Brokers

28:30 to 31:00

Learn how Sal leveraged social media data to create a data brokerage.

“If his shows don't have any audiences, how has he got that big house and all the money to run a film studio?”
Show all 20 chapters

Sal's Data Collection Methods

31:00 to 33:48

Discover how Sal collected vast amounts of personal data without consent.

“The Fourth Amendment says we should have a reasonable expectation of privacy.”

The Massive Data Breach

33:48 to 36:58

Understand the implications of Sal's data breach and its impact on millions.

“In 2022, Sal made$750 ,000 from selling our data.”

Consequences of Data Exploitation

36:58 to 41:49

Examine the severe ramifications of data breaches on individuals.

“If you're listening to this and you're American, chances are you were likely in this database.”

A Personal Stance on Privacy

41:49 to 42:01

Hear the host's perspective on privacy in the data-driven world.

“And I know there's nothing I could do once they get it.”

The Dangers of Data Brokers

42:01 to 42:54

Learn about the personal risks posed by data brokers and protective measures.

“please delete all my data and stop spying on me.”

Luan's Data Breach Incident

42:55 to 44:48

Explore the consequences faced by Luan after his data breach and doxing.

“Most companies won't protect your privacy, even if they say they do.”

Congressional Response to Data Privacy

44:49 to 47:18

Understand Congress's failed attempt to enact a nationwide privacy law.

“But if you visit nationalpublicdata.com, it's still there.”

Steps to Protect Your Privacy

47:19 to 48:36

Discover actionable steps to enhance your online privacy and security.

“No one is going to protect your privacy.”

Luan's Fate and Future Implications

48:37 to 49:08

Reflect on Luan's imprisonment and its implications for data privacy.

“You might be okay with who's in charge now in the world, but that's going to change one day, and whoever inherits your data next might decide that you're a criminal.”

Luan's Fate and Future Implications

49:25 to 50:13

Reflect on Luan's imprisonment and its implications for data privacy.

“Listen, I'm certain that you've bought a book or paid to go see a movie before you knew if that book or movie was any good.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00So back in 1988, there was this identity theft incident that happened, which when I read it, it infuriated me so badly. And now I want to infuriate you. So check this story out. This all started in Albuquerque, New Mexico, like I said, 1988. And there was a hot dog stand there, which seemed to hire people who were really down and out. Like, if you had a past criminal record, that's fine. You hired a homeless. Okay, here's a job, buddy. Get yourself together. William Woods was the homeless guy working there, and then they hired Matthew Kearins. Matthew had a long criminal record and was trying to separate himself from that past.

0:37And he was new in town, just needed like a little cash to probably just get him to the next town or something. But as soon as Matthew started working at this hot dog stand, he stole William Woods' wallet, the homeless guy that was also working there. William found out that Matthew stole his wallet and confronted him, and he threatened him, and he got the wallet back. But jeez, what kind of jerk steals someone's wallet like that? Neither of them lasted long at this hot dog stand. William, the homeless guy, actually left town to find a new job. He went over to Texas for a while. He did some day labor jobs there.

1:07Then went over to Las Vegas and worked in a laundromat. And eventually he ended up in Los Angeles, scavenging for gems and metals. But little did he know, while he was struggling to get his life together, Matthew had started calling himself William Woods. See, since Matthew didn't have a house, he carried all his important documents with him. So when Matthew stole his wallet, his birth certificate and social security card was in his wallet. So Matthew copied those things down and then moved to another state and then started to register stuff in that name. He asked for an official birth certificate from the state and a social security card for William Woods and got them.

1:46And he got a driver's license with William Woods' name on it, but it had Matthew's picture on it. And he got a job as William Woods. Because remember, Matthew had a criminal past and he was eager to leave that behind. A fresh start was really great for him. But he didn't stop there. Matthew opened a bank account as William Woods too. By 1994, six years after stealing Williams' wallet, Matthew had completely took on this new identity. And William had no idea. Matthew even got married to a woman who thought his name was William Woods. And then they had kids and they called themselves the Woods family.

2:26Matthew wanted to know more about William, to have a solid backstory, and went on Ancestry.com and convinced them that he's William Woods and he learned all about his childhood and his family. And actually, this all had a huge payoff for Matthew. This was great for him because he had a criminal past, but that was essentially erased. And now he got a$100 ,000 a year IT job at the University of Iowa and a car and even took out a loan for a house under his assumed identity. This fresh start was looking great for him. The real William still had no clue and was busy scavenging for gems and minerals in California.

3:03He was an off the grade kind of guy, so he wasn't filing his taxes or opening bank accounts himself. And he only used cash wherever he went and kept a pretty quiet life. And because of that, Matthew was able to use William Woods' name for decades without anyone knowing. In 2019, the real William started getting a hunch that someone might be using his identity. And talked to someone about it, and they gave him some money to do a credit check. And that's when William discovered there's loans out at a bank under his name. So he goes in the bank, identifies himself as William Woods, shows them his California ID, and they're like, okay, how can we help you?

3:42And he's like, well, I don't have an account here. Someone else is using my social security number or name or whatever because that account is not mine. The assistant branch manager walks over and he looks at William's account and there are some security questions associated with it and a PIN. William cannot answer any of the security questions and doesn't know the PIN, obviously. So the manager's like, okay, well, there's a phone number here. And William's like, that's not my phone number. So the manager's like, well, let's see what happens when I call it. So he calls the number, and Matthew picks up over in Iowa.

4:15But Matthew abandoned that name, Matthew, long ago. He's like, yeah, I'm William Woods. What's the problem? And they asked him the security questions, and he got it right. So now the bank has two people who have authenticated themselves to be the owner of this account, and they have to figure out who's the real owner. The manager is still on the phone with Matthew, And since he knows all the answers to the security questions, and the real William looks like some homeless guy, he's more convinced that the guy on the phone is the true account holder. So he tells Matthew, well, there's someone here in the bank claiming to be you.

4:50And Matthew's like, in California? I'm in Iowa. Nobody in California should be accessing my account. So William's standing there, and the manager's looking at him, and the manager starts thinking, this guy in the bank must be faking his identity to get into this guy's account. So he calls the cops on William for identity fraud. The cops call Matthew and they ask for proof that he's actually William Woods. And Matthew just sends him his driver's license, social security card, birth certificate. At this point, Matthew had been using Williams' identity for 31 years. Which means he has tons of supporting evidence to prove he's really William.

5:33What do you want? W-2s, electricity bills, library cards, credit cards, a marriage certificate. I can give you supporting documents for days. I am the real William Woods. And in the meantime, the real William Woods has very little to show that he's actually who he says he is. He has an ID from the state of California, but that's about it. He just didn't have much documentation to prove he was actually William. But that's just the beginning. Get this. Matthew must have known what was going on because when Williams went to court in California, he was tried under the name Matthew Kearans. So that must mean that Matthew told the cops that William is probably this guy, Matthew Kearans, which is so messed up and backwards.

6:14Now, William is going out of his mind. He is disgruntled. He is furious. He's confused and absolutely angry with the cops and the court. I mean, I would be too, but it's not helping his situation at all. He seems wild and crazy, which makes everyone in the court think he's actually nuts. Even his lawyer doubted the story. He got so wild and furious with everyone that they really did think he was having a psychotic breakdown and decided that he's not fit for court and sent him away to a mental hospital without even having a trial. So poor William got thrown in the mental ward. And not only that, but they forced him to take psychiatric drugs the whole time.

7:01They were calling him Matthew, and he's like, no, I'm not Matthew. Matthew stole my identity. I'm William Woods. And he was forced to stay in the mental hospital for five months. And when he finally calmed down, they said, okay, now we can have your trial. And the judge looked at the case and found him guilty for trying to steal William Woods' identity. So they sent him to jail. Not only that, but they charged him$118 ,000 fee for his hospital bill. This is the stuff that makes me furious. I mean, like, absolutely furious that the victim gets treated like this and the actual identity thief got away with it.

7:45I'm sure William must have thought he was crazy at times. And it's no fun when you start doubting your own reality and don't even know who you are anymore because the court forced him to call himself Matthew. He was admitted to jail as Matthew. The guards called him Matthew, and they made him call himself Matthew. So poor William just had to serve his jail time. He didn't have any resources to fight this. So months go by in jail, a year goes by, and after a year and a half, he served his complete sentence and was able to get out. And when he gets out, he is mad. So mad at Matthew for putting him through all this that he calls Matthew's work, University of Iowa, to report him.

8:29And this makes its rounds to some people at the University of Iowa. And someone decided to do their own little investigation. They thought, what if William is right and Matthew did actually steal his identity instead of the other way around? And surprisingly, at this point, no one had done a DNA test on either man. So the person from the University of Iowa figured out who William Woods' real father was, which wasn't easy, and was able to get a DNA sample from the father. And then he went to California and took a DNA sample from William Woods, and bingo, there was a clear match. The investigator called Matthew and asked him what his father's name was, but Matthew had no idea.

9:09So after a year and a half in jail and five months drugged in a mental hospital, everyone finally realized that William was telling the truth the whole time. Ugh! The courts apologized. They exonerated him of all wrongdoing. And they even canceled out his$118 ,000 medical fee that they charged him with. Like, oops, sorry, that was our mistake. And he was free to go on calling himself William once again. But then the cops turned towards Matthew in Iowa and were like, Bro, you lied to us. You lied under oath in court. And you made a poor man suffer for years because of this? not to mention you conducted identity theft, so they arrested Matthew and sentenced him to 12 years in federal prison.

9:59His expected release date is 2037.

10:06These are true stories from the dark side of the Internet.

10:13I'm Jack Recider. This is Darknet Diaries.

10:34This episode is sponsored by ThreatLocker. The weird part about modern cyber attacks is how normal they look. The attacker logs in from Chrome, uses PowerShell, runs a remote admin tool your IT team already trusts. There is no custom malware, no dramatic movie hacker moment, just normal tools used in the wrong way. That's part of why ThreatLocker exists. ThreatLocker helps organizations control what software can run, what it can do, and how systems communicate. If attackers get credentials or land on a machine, they'll have a much harder time moving through the environment. Because security teams are realizing something important.

11:10The problem isn't always unknown software anymore. Sometimes it's trusted software being used by the wrong person. If you want to see how ThreatLocker works, go to ThreatLocker.com slash Darknet and book a demo today. That's ThreatLocker.com slash Darknet to book a demo.

11:32This episode is sponsored by my friends over at Maze. GitHub saw nearly a billion commits last year. This year, with AI agents writing code, they're on pace for$14 billion. Code is shipping faster than ever, and its vulnerabilities are piling up just as quickly. Legacy SCA and SAST tools weren't built for this kind of scale. That's why Maze just launched Maze Code. They're using AI agents to investigate every vulnerability in your dependencies and in the code your team writes. The agents use context from your code and cloud to prove what's really exploitable in your environment, not just theoretically risky.

12:12Then they go further, catching the business logic flaws other tools miss. And when something's exploitable, they find the fix and send it straight to the right developer or your coding agent. Check out Maze at mazehq.com slash darknet. That's Maze, spelled M-A-Z-E. Maze, H-Q, dot com, slash, darknet. A few years ago, a friend messaged me and said, look out, an APT just followed you on Twitter. And I'm like, what? He's like, yeah, the U.S. government is classifying this account as an APT, an active persistent threat to the U.S. government. I'm like, whoa, which account is this? He said, oh, the account name is USDOD.

12:55USDOD, as in Department of Defense? and they're an APT and they're following me. No, no, that's just their hacker name. Could be a group, could be a solo person, but they're calling themselves USDOD to be funny, edgy, and confusing. So this began my relationship with the APT known as USDOD. He was active in the hacking scene. He would post what he's doing right there on Twitter. And I started commenting on his post, and he started commenting on mine, and we laughed and we giggled. And we started forming some kind of weird parasocial relationship through Twitter. I always had a hard time getting a good read on him.

13:29He contradicted himself a lot. He seemed a bit young in the way he was talking. It was really hard to figure out if what he was saying was true or just something he exaggerated or even made up. I think a few times I caught him talking to himself even, like, you know, just some weird gibberish that probably only he understood. I asked him for an interview. He said, okay. But then I realized his story is just beginning. if I interview him now, I'm sure there's going to be much more that comes. So I just held off, waiting for the story to ripen more. And I think a year went by, and I just watched him do more and more crazy stuff, and it was hard to tell what was real and what wasn't.

14:07But then he suddenly disappeared. The account was banned, and I never heard from him again. Turns out his story is much more crazier than I realized. Are you ready?

14:24So let me give you an example of how strange he is. A few years ago, the reporters at databreaches.net did in fact interview him. And this interview is all over the place. Like, here, check out this one story he told them. Back in 2012, the hacker known as USDOD was living in Brazil and said he went to New York for cancer treatment. During his time there, he fell in love with one of the hospital employees. They became deeply involved with each other. They started talking about how corrupt the hospital is. So him being the little hacker that he was, he decided to hack the hospital and expose the corruption.

15:00She said she would help him. And with an insider, well, it's super easy to hack into a hospital. So she helped him get into the network, and he took incriminating evidence that proved the hospital was corrupt. He said he was going to take this to the media and tell reporters and expose the whole hospital. and together they were going to make a big deal of this. But the day before he was going to meet with the media, she suddenly disappeared. His attention shifted entirely to find her. He became frantic, depressed, emotional. To go from a deeply involved relationship with her to hacking into the hospital together to suddenly being alone in New York, he was distraught.

15:41He hired a private investigator to try to track her down, but even the PI couldn't find her. She vanished like a ghost. So with no reason to stay in the U.S., he returned to Brazil and never blew the whistle on the hospital. And this made him extremely bitter with the U.S. It's not entirely clear why he's mad at the U.S. government over this, but says this was the thing that made him upset at the U.S. government. Maybe he thinks they made her disappear somehow or kept them apart. I don't know. But this is what I mean. What a wild story to start with, right? He came to the U.S., fell in love with a hospital worker, found corruption in the hospital, hacked a hospital, went to expose it, but then she vanished.

16:25And he was left holding the smoking evidence that could ruin the hospital, but decided not to publish it due to a heartbreak? It sounds like a movie plot, and who knows how much of that is true, since it was just a story he told reporters. Anyway, he says her disappearance gave him a personal vendetta against the U.S. And this is what started his decade-long campaign to attack the U.S. He says it wasn't politics, which is just wild because you decided to become an APT because you were heartbroken. Okay, I've heard stranger things on this show. Let's go. Let's see where this goes. He joined dark web communities, met criminals from far-off places, Russians, Iranians, North Koreans, and learn more about hacking techniques from them.

17:13He trained up by breaking into small companies that made easy targets. He started making a name for himself among the hackers in the hacker community. Unknown to the rest of the world, though, until one day when he was approached by an associate, a Russian who claimed to be developing some kind of AI platform named Tulip. The Russian needed help. Asked DOD, hey, can you help us collect military data? It would be useful for Tulip. And I want to clarify, whenever I say USDOD in this story, I'm always talking about this hacker from Brazil. That's the name he was going by. So USDOD accepted the job.

17:50And over the next six months, some Russian folks he partnered with were able to build an exploit for an unknown vulnerability in the U.S. Army IT platform called the Program Executive Office Enterprise Information System, PEO. While the Russians did that, USDOD discovered that a way into this network could be to impersonate one of the developers who made it. So he discovered who developed PEO and started working on getting closer to them. He tried getting access through the developer, using social engineering techniques, and this strategy worked. Humans are always the weakest link. And it was a pincher move, attacking the system from two sides.

18:29Together, the Russian hackers and USDOD were able to steal source code and get different databases from agencies that use PEO, agencies like the Department of Defense's Strategic Command, Central Command, Special Operations Command, and Defense Technical Information Center, and Army Specialist Operations Center. The defense contractor, Lockheed Martin, too. The Russians took what they wanted from the deal, and USDOD got to take credit for the breach. In three days, in February 2022, he leaked lists of full military emails and passwords to the dark web. And that is how he got the hacker name USDOD, by breaching the Department of Defense and publishing tons of military emails.

19:10Talk about an entrance onto the hacker scene. And it was here when the U.S. considered him a threat. You don't attack the military like that and expect them to ignore you. They were working hard to figure out who USDOD was. USDOD didn't stop there. He went on a roll after that. His next target was InfraGuard. This is basically the tip line to the FBI. If you have an important business, you can register for an account in InfraGard, and then you can report incidents to the FBI directly and fast. Think critical infrastructure companies like gas companies, dams, water treatment facilities, or banks that might need to contact the FBI quick to take action on an incident.

19:46That's what InfraGard is. And that was the site that USDOD was trying to attack. It's normal for companies to apply to join InfraGard. So USDOD figured, why not try to apply himself? But his plan was to steal someone's identity who would qualify to be accepted and submit them to join. So first, he looked around for a finance company that would qualify. Then he looked up the CEO's name, got his personal information, probably just bought it off the dark web. And USDOD filled out an application on their behalf, put in the CEO's information that he knew, and just faked the rest. InfraGard replied back, there's some errors on your forms, these parts need fixing.

20:28So he's like, okay. And so DOD fixed him and sent it back again. And a few weeks later, he got another reply. His application was accepted. And just like that, he was in the InfraGard system. Not quite hacking his way in, but faking his way in. He tricked the FBI that he was someone else. And once there, he saw that he could talk to other members. So he started chatting them up, and they thought he was a genuine CEO. But then he started poking around the site, trying to test the database or servers to see if there's something weak here. And he found that the site has an API, which is basically a way to query the database, but he uses a different authentication mechanism.

21:06And while he was examining the API, he discovered that you can ask it for all the members' contact information, and it would give it to you, like a big phone book, basically. But you had to be a member to see everyone else's details. Nobody knew about this huge vulnerability, maybe because nobody who belonged to InfraGard would ever think to attack the site like this. It was a perfect opportunity. USDOD asked a friend to write him a Python script to grab the data. Then he used it to steal every InfraGard member's contact information. 80 ,000 CEOs, executives, and security officers. And again, he posted it all for sale on the internet.

21:46And it was around here when he started following me on Twitter. So you can see why they thought of him as an APT. He was advanced enough to sneak into FBI's InfraGuard and persistent to attack the U.S. government again and again, and definitely a threat. Advanced persistent threat title acquired, which means the U.S. government would be actively investigating him more now than ever. And I'm not sure how they figured it out, but they figured out his name. And his name was Luan Barbosa. He's from a small city in Brazil. But Brazil doesn't extradite their own citizens, so I think the U.S. government had a hard time figuring out a way to take him down.

22:28But despite being actively investigated by the feds, his vendetta was just getting started. He thought he was untouchable, taunting the feds and anyone else. I mean, his Twitter photo was just a picture of the cutest kitty you ever saw. He found a certain formula for hacking, which was working surprisingly well for him. Step one, search through data dumps on the dark web for someone he can impersonate to help him reach his target. Step two, impersonate that target or use their account to get in. Step three, profit. Using this formula, USDOD or Luan broke into Cybersecurity Defense Center at NATO and a Washington, D.C.

23:11club for politicians and the aerospace company Airbus and their 3 ,000 vendors. In two or three years, Luan breached so many U.S. government and government-related organizations that he was planning on building a business out of it. A full-on company selling military intelligence. He had some pretty wild access and information, and he knew that people around the world would want to have this or buy it from him. So why not make a business out of stealing this and selling it? To get his business off the ground, though, he needed a steady supply of people to impersonate. people with military connections and enough of their information to do it right.

23:50He was buying identities from places on the dark web, but this process had friction. I think what he was doing was looking to see who worked in a U.S. military place and then tried to search for their names on the dark web so that he could get their data and impersonate them. But time after time, the people he looked for weren't listed. That data wasn't available. So he thought, what if I just had a big list of people's identities and then figured out who on that list worked in the military or intelligence and then I could just go impersonate them. But he didn't have such a list. He knew lists like that existed, though, and went on a hunt to find one that he could have full access to.

Read the full transcript

24:28We're going to take a quick ad break here, but come back because this story is about to take a whole new turn.

24:43in all kinds of ways. Crashes, slowdowns, regressions, the stuff you only see once real users hit it. Sentry, that's S-E-N-T-R-Y, catches all of it. You get traces, replays, errors, profiles, and the details around them like stack traces, commits, releases, and the developers who broke it, all in one connected view. So you're not jumping between tools trying to figure out what happened. Sentry shows you how the request moved, what ran, what slowed down, and what the user saw seer centuries ai debugging agent takes it from there it uses all of that century context to tell you the root cause suggest a fix and can open a pr it also reviews the prs for you and flags breaking changes with a fix ready try century and seer free at century.io they have a free dev plan and listeners of the show can use the code darknet for 100 in century credits when you go to Sentry.io that's spelled S-E-N-T-R-Y go to Sentry.io and tell them I sent you by using code Darknet for$100 in Sentry credits.

25:50There's a new character who comes into our story now. His name is Salvatore Verrini Jr. but I'm just going to call him Sal. He wanted to get into the entertainment business and decided to produce and star in his own TV shows. and he was swimming in it. He owned a mini mansion near Miami with palm trees and a three-car garage, had a hot red 57 Chevy Bel Air and a hot wife. He was a successful guy. But I went and watched his biggest show, which is called Country Days with a Z. It streams on Amazon Prime. It's a staged reality show starring him and his friends. Here's a clip from two minutes into the first episode.

26:29See what you think. Hey, everyone. I'm Sal, the CEO of Everything Country. You know the best part about owning your own business? You get to hire all your friends. Yeah, baby. That'll look good. Hey, what's up, Sal? What's going on, Big Mike? Ah, nothing, Mouss, man. What are you up to? Ah, nothing. What are you doing? Ah, nothing. Hey, man, I gotta tell you something. I got a video. I got 100 % proof the Earth is flat. You gotta take a look at this. Okay, so a little backstory on Mike. Mike is what they call a flat earther. And, well, they think that the Earth is actually flat. I mean, like really?

27:05Dude, again with this. I'm telling you. It's round. It ain't round. Mike. Just take a look. No. I'm going to lose five minutes of my life watching this again. You'll probably gain five minutes. Oh, dude, come on. I'm telling you. I promise you, you will. Copernicus, it's round. Copernicus is the guy that, that guy. You can't even say it. Whatever. That guy's all over in his grave. He's the guy who thinks it's round. I'm the guy who knows it's flat. Okay, I have to stop there because they just keep going on and on like this for a long time, like way longer than they need to. But I played this clip for you to give you a sense of what Sal is like.

27:41And I think Sal is not only the star of the show, but also the writer, the director, the producer, the editor. He did it all. I was curious, so I checked. Turns out nobody watches this show. If you go on IMDb, reality shows usually have like five, maybe 10 ,000 reviews. Country Days has 11 reviews. Nobody's watching it. Sal's personal IMDb page lists his other shows and movies. Some of them don't even exist. There's a few pictures of him in an action movie, except if you go on his Instagram, he admits that those pictures were just taken in a photo shoot that he paid for. Which, when I think about it, I admit I did that once too.

28:20In high school, I somehow faked my way into the picture with the football team. So if you open up the yearbook that year, it looked like I made the football team, but I was never on the team. So who even is this Sal guy, though? Where is all this money coming from? If his shows don't have any audiences, how has he got that big house and all the money to run a film studio? Well, here's the truth. He always wanted to be an actor. He was in school plays and got on a Burt Reynolds show as an extra. He studied theater in college, but it didn't work out for him at all. But his dad, Sal Sr., is a prominent lawyer in Florida.

28:52And when Sal crashed out as an actor, Sal Sr. probably hooked him up with his next gig in a sheriff's office as a deputy. Yeah, Sal became a cop. And it was a huge setback for his dream. But Sal didn't give up. He believed in himself, and he hatched a new plan to rekindle his Hollywood dreams. And I think it was here, while working in the sheriff's office, that he noticed something which gave him an idea to make money to pursue his dreams again. Years ago, if you wanted to get someone's photo or know their daily routine or who they're in a relationship with or get their phone number, stuff like that, you'd have to hire a private investigator who would tail the person and gather what they can.

29:34But today, everyone is posting their own private data voluntarily online, especially social media. We see photos of people's kids, their accomplishments, their vacation photos. We see them with their new lover or their new home renovation. Sometimes you just see people post their whole day on social media. We don't need a private investigator or to get information about where people are and what they're doing and what they look like or any of that stuff anymore. It's just all there on social media. And so there are companies that go on social media and scrape all that data to provide it to cops.

30:12Like I remember a few years ago, there was a whole controversy about a company called Clearview AI and they were raiding major social media websites. They'd take Facebook, for example, grab every picture and bit of information they could off of everyone's account and then add it to a file that was created about them. Then they'd repeat for Twitter and LinkedIn and wherever, automatically. Of course, the social media companies got mad. They're like, hey, that's our data. You're profiting off our data. Then they sent Clearview AI a cease and desist letter. But even those megacorporations couldn't stop it.

30:42If anything, Clearview is bigger today than they've ever been before. I just saw that they signed a$10 million contract with ICE. So keep that in mind. Your social media posts are likely scraped and processed through AI and are easily accessible by ICE agents, even if you deleted your post. And for the record, I don't think this is right. The Fourth Amendment says we should have a reasonable expectation of privacy. It says the government has to have a warrant to conduct a search. Yet ICE is able to get tons of data about us without a warrant. And the loophole they found is that they're allowed to just buy data from data brokers.

31:19It's the data broker loophole. And the thing I hate most about this is we never gave them permission to exploit this loophole. We never voted on this. We never collectively agreed that data brokers are cool and it's totally fine for the government to buy data from them and get around having to have a warrant to conduct a search. This was all decided without our input or support. And the government hides all this from us. They hide how much they pay data brokers to get information on us. I'm disgusted by how much the government spies on us without a warrant. when it's clearly a violation of the Fourth Amendment.

31:53The thing is, this business model is very profitable for data brokers. They are incentivized to gather as much private data about us as they can since the more they have, the more the government will spend on it. They are in the business of brokering your personal data. And I think Sal saw how important these data brokers are to law enforcement. and maybe he even caught a glimpse of how much the contract was with one of these. And he might have been like, whoa, I'm in the wrong business. So Sal quit his job as deputy and decided to start his own data broker service. He created three almost identical websites, Records Check, Criminal Screen, and the flagship site, National Public Data.

32:39He hired some cheap programmers in Bangladesh to code the initial website for him. Then he started collecting everyone's data. You can think of the data he collected in two buckets. There's what the government publicly posts about us, such as bankruptcy filings, court records, motor vehicle records, death records. You'd be surprised how big this bucket is. You ever buy property? Yeah, you're in a public database. You got married? Yep, that's public data too. Registered to vote? In some states, you're in a public database. Then there's bucket two, the dirty work. Scraping it, sneaking it, stealing it, buying it.

33:12I'm not sure what the rules are here, but it seems like data brokers treat rules more like guidelines than actual rules because they'll go to great lengths to get private data from people. Sal either bought or scraped data from other data brokers, subscription and marketing lists, loyalty and rewards programs, social media, and other apps. Some brokers even collected the data leaked by hackers like USDOD. Eventually, Sal had collected not thousands, not hundreds of thousands, not millions, but hundreds of millions of Americans' personal data records. Then he packaged it into individual profiles and sold access to law enforcement or whoever wanted to do people search.

33:52And it worked unbelievably well. In 2022, Sal made$750 ,000 from selling our data. And in 2023, he made$1.15 million. And he almost instantly turned around and used the money to make his own TV shows. Here's what he spent his money on. I'm telling you. It's round. It ain't round. Mike. Just take a look. No. You ever watch those NASA videos? CGI, bro. No, please. CGI. They're sitting there flying over to Earth. You see the Earth below. You see the Aurora Borealis. You see it cruising around. Green screen. Green screen. It's all fake. They green screen the Aurora Borealis. They proved it on here.

34:29Would you just take a look at it? Trust me on this. I'm getting dumber by the minute. I'm looking at Sal's financial records now. And there's something telling about the way he spent his money. The data broker company's total cash in the bank is$563. Insurance expense,$1 ,327. Cybersecurity budget, zero. Salaries? Yeah, there were no salaries. He ran it all by himself with two desktops, a laptop, and file servers in his home office. To me, the way I see it, Sal's data broker business was only set up for him to make as much money as possible and didn't spend a lot of effort protecting this data or securing it.

35:13So now that you know what Sal was cooking up, let's go back and focus on Luan, a.k.a. USDOD. By this point in 2023, Luan was trying to get his military intelligence business set up and needed a lot of military identities to impersonate to get more data and decided to hunt around for vulnerable data brokers. He found Sal's data broker site called Records Check. Records Check advertised instant background checks, social security number traces, and more. Perfect. Luan was now laser-focused on this site, locked in, trying to look behind the curtain to see everything the site had on people. He used a tool to try to scour the site and see every file and image that was publicly viewable on this site.

35:59And one file stood out, members.zip. What is this file, and why is it just in the open for anyone to grab and look at? He grabbed it and looked at it. Members.zip had Sal's site's source code, and buried inside the code were admin credentials. Luan just got the email and password to access any corner of this site and all the data in it. So Luan logged in to Records Check as Sal, but then discovered the site was connected to two other sites. And guess what? Sal reused passwords, which allowed Luan to log in to National Public Data, which gave Luan access to the biggest set of data that Sal had.

36:48And Luan took everything. 2.9 billion lines of data. 277 gigabytes worth. Personal information about hundreds of millions of people. If you're listening to this and you're American, chances are you were likely in this database. Then Luan does what Luan does. and he posted it for sale online as USDOD with the cute little kitty picture, and he put the data up for sale for$3.5 million. TikTok was outraged. This is a public service announcement to remind you to check your credit files. I just received an alert from my credit card and also from my credit reporting agency about my data being leaked online.

37:352.9 billion records. One of the largest data breaches in recent time. Why is this one important? Because you're not a subscriber to this service. This is for running background checks and fraud prevention. And so they just randomly collect data about billions of people without your consent. We have to protect ourselves now. Although we're going to have a lawsuit against NPDs, they did not protect our data sufficiently. The problem is the data still got out into the public domain. The problem with the NPT data breach is that it is a scraping company that was designed to find out everything it can about you.

38:20Now, if they're a data brokerage company that has other information about you, a hacker can start to put together an identity profile on you. And then with that identity profile, breach your security. We all know that data breaches happen all the time. But the most recent one has been with national public data. It was over 3 million people's data was breached. That's from the UK, US, and Canada. At the beginning of this episode, I told you about how that guy Matthew Kieran stole William Woods' wallet and later his identity. And all it took was for him to get William's name, birth date, and social security number.

38:56And from there, it was enough to impersonate William for decades. National public data leaked full names, birthdays, social security numbers, home addresses, past addresses, email addresses, and phone numbers, all in plain text. A lot of it had errors, but most of it was accurate. The ramifications of a data broker having a data breach is huge. Catastrophic to some people listed in the breach. Researching this episode, I came across all kinds of horror stories of people who had their identity stolen after a data breach. Like a bunch of people in Oakland, California. After the city was attacked with ransomware, they interviewed one guy who was on the news and he said that criminals had impersonated his identity and they were taking tens of thousands of dollars in loans out and making purchases in his name and he was on the hook to pay it all back.

39:46And so you can imagine the huge nightmare that he had to try to convince the bank that he didn't spend any of this money. That hardly compares to this other girl I read about. She was in Florida, and she tried to sign up for her first credit card when she went to college. But she got denied because they told her that she already owes one and a half million dollars, and she's in huge debt. Apparently, someone had been using her identity since she was nine years old. Another crazy story happened to an LA Times reporter. After her wallet was stolen at a bar, she knew it was gone minutes after it happened, so she thought there was enough time to act before something bad happened.

40:21So she called the bank, she called the police, she called everyone. but it didn't matter. The thieves used her info from her wallet to get her social security number online and for a whole year, they opened dozens of credit cards in her name, they rented cars in her name, got new iPhones and wrote tons of checks, sometimes more than$10 ,000. And that's just a couple of things criminals can do if they get your information. We've already talked on the show about SIM swaps. If a scammer knows enough about you, they can convince the phone company to transfer them your phone number. Then they can log into your bank account or crypto accounts and steal all your money.

40:57I read about multiple people who have lost millions of dollars this way. So I'm sure the victims exposed in the national public data breach have faced a lot of similar nightmare scenarios. And despite victims being hit with this, they might not even have a clue that national public data is what leaked their data. It's really hard to know how a thief got your info, you know? And the worst part is Sal isn't going to be on the hook for any of the damage done to the victims because how can you prove that the criminals got their data from this data breach when these criminals hide in the shadows of the internet and are seldom caught?

41:33This is one reason why I despise data brokers. They mistreat our private data and don't care how negatively it impacts us. They're incredibly greedy for our data, and then it gets abused in the worst way possible. This is why I've become a privacy freak over the course of making this show. I know these data brokers exist and are trying so hard to get my information. And I know there's nothing I could do once they get it. I can't opt out or ask them to delete me. God, I would love to send a cease and desist letter to Equifax and tell them, please delete all my data and stop spying on me. But no.

42:04And I know it's just a matter of time before criminals get their hands on my data, either from a data breach or buying the data somehow. There's just no way to protect it. And since I know if someone gets my data, it could be catastrophic to my life. So that's why I take extreme steps to hide from these data brokers, even so much as wearing a disguise when I go in public sometimes. In fact, many of you even have met me in disguise and only know what I look like in my disguise. It's the only way that I feel like I can empower myself to stay safe in today's internet age. I use fake personas, burner phones, burner emails, even burner credit cards, and I'm super secretive about my personal life when I go online.

42:44Anyway, God, these episodes always get me ranting about privacy. Sorry, I know some of you don't care about your privacy, so I'm going to move on. But someday I hope to get through to you. I mean, I just want you to understand this one thing. Most companies won't protect your privacy, even if they say they do. They share it with data brokers, and they'll profit off of it, or they'll just lose it in a data breach. The only one who can protect you is you. A couple months after this leak, he taunted CrowdStrike, a cybersecurity company. claiming he hacked into them and he got all their threat actor lists and their indicators are compromised and he has it up for sale.

43:19Well, the thing is, CrowdStrike has some pretty impressive cybersecurity researchers and investigators. So they started looking to see who USDOD was. And they discovered he uses the same email address for GitHub, all the blogs and social media accounts he has everywhere. It turned out that for years, Luan only used one email for everything he did, hacking or non-hacking. So CrowdStrike was able to figure out his name, address, phone number, tax registration ID, and more. Basically, Luan got doxed, but privately. CrowdStrike, law enforcement, some news outlets had his details. And Luan admitted to what he had done, and the dox were true.

44:00But he wasn't done. I saw him tweet, this is not my end. And then he offered his services to the Brazilian government, but that didn't go well. Now that law enforcement knew his name and location, the Brazilian police swarmed in on him and arrested him and took him to jail. Sal was doxxed too by reporters, but he just lawyered up and went silent. It didn't go well for him. Congress wrote him a letter calling National Public Data's lack of transparency staggering. Now he's being sued for everything he's got, and then some. Multiple class action lawsuits are against him by people who are in the data set.

44:37unless country days takes off this year, he will not be able to pay off even a fraction of that. And you would think after having a catastrophic incident like this, Sal would just shut down national public data and maybe go back to acting or something. But if you visit nationalpublicdata.com, it's still there. The site's still up, collecting our data and selling it. Sal tried to declare bankruptcy, to wipe out his debt to society, but the judge just saw right through that and did not accept his bankruptcy plea. So then Sal supposedly sold his data broker company to another company, which is ironically called Perfect Privacy LLC.

45:16But you won't find much about Perfect Privacy LLC online, but you'll find plenty about yourself if you search your name on their website. The revamped National Public Data advertises that. You can find pretty much anything you need from someone's contact information, location, age, and birthday, to workplace, relatives, and criminal records. Which has to be the craziest thing about this whole story. Like a data broker can have a total breach and then continue operating, scraping my data, storing it without my consent, like nothing happened. So what's the solution here? I don't think politicians are an ally here.

45:52They aren't going to enforce any kind of data privacy law since they're the customer for many of these data brokers themselves. I mean, the government is who mandates that Equifax must be allowed to collect data off of all U.S. citizens without their consent. And even if the government wasn't using data brokers, they'd claim that they need our data for national security reasons. So I think they are no help here. But then I was caught off guard when I read that 85 % of the members of Congress were also included in the national public data breach. And a lot of them seemed pretty upset about this breach and wanted to do something about it.

46:30So in April 2024, they did. Weeks after Luan put the 2.9 billion records up for sale, Congress and the Senate proposed a nationwide privacy law called the American Privacy Rights Act. It listed protections Americans should have, but also had a rule where anybody could file a form with the government to prevent data brokers from collecting their information. That is, submit a single form and all the American data brokers would have to delete your information if you want to opt out. Democrats and Republicans liked this bill. It went up for a vote. But then the day before they voted on it, it was sabotaged.

47:08Lobbiers came in and put pressure on politicians who then started watering down the bill until most of the useful privacy protections were gone. And after that, the whole thing died. So the American Privacy Rights Act never got off the ground. And this is what I mean. No one is going to save you. No one is going to protect your privacy. You have to do it. And lucky for you, there are easy steps that you can take to protect it. I mean, just thinking right off the bat, stop using text messages. Those things historically have been insecure, and they typically are end-to-end encrypted, and they can be monitored by phone companies.

47:41So a chat app like Signal takes extreme steps to never be able to see chats. Even if someone pointed a gun to their head, they would not be able to read your messages. And the same goes for end-to-end encrypted email providers like Proton or Tuda. They cannot see what's in your emails. Compare that to something like Google, who looks through all your emails to provide ads for you. I also highly recommend a web browser that cares about your privacy. Google Chrome is the worst on the list. Every character you type into the address bar gets keylogged and sent to Google. They want to know everything about you.

48:14So I use the Brave browser, which makes enormous effort to not collect anything from me. So those are three quick and easy wins. Use Signal, use an encrypted email provider, and use a privacy-focused browser. because it's not just about stopping Sal or Luan from grabbing at your data and exposing you. You want to future-proof yourself from tyrannical regimes that are also trying to hoard your data. You might be okay with who's in charge now in the world, but that's going to change one day, and whoever inherits your data next might decide that you're a criminal. Then it's too late for you to do something about your privacy.

48:53In the end, Luan, a.k.a. U.S. DOD, is still in a jail in Brazil. Since Brazil doesn't extradite their citizens to the U.S., he'll probably just serve his jail time in Brazil and is likely never going to go to the U.S. And one newspaper speculated that he's facing about four years in prison, but we don't quite know what his prison sentence was.

49:24Are you a premium subscriber of Dark Knight Diaries? If not, why not? Listen, I'm certain that you've bought a book or paid to go see a movie before you knew if that book or movie was any good. I don't want to do that to you. I want to give you this show for free in order to prove its value to you and show you that I'm worth pitching a few bucks at. Have I done that? Does this show bring you value? you? Do you learn from it? Do you get entertained? Does it help you get through a long car ride without being too bored? If so, I want to ask you to become a premium subscriber to show your thanks. And hey, if you do, you'll get ad-free episodes and bonus episodes.

50:07There's actually 12 episodes in the premium feed that don't exist anywhere else. So please consider signing up. Go to plus.darknetdiaries.com. I really appreciate it. This show is made by me, the pasta pwner, Jack Rees Sider. This episode was written by the DDoS attack dog, Nate Nelson's sound design by the VHS vandal, Garrett Tiedemann. And this episode was assembled by the cruise controller, Tristan Ledger. Mixing by Proximity Sound, our theme music is by the mysterious Breakmaster Cylinder. My data has been in many data breaches. And once a hacker messaged me saying, I have everything, bro.

50:44I have your name, your password. I'm like, no way. Oh, my God. Thank you, I've been looking for that password for years. This is Darknet Diaries.

From the publisher

This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.

Sponsors

Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com.

This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what’s actually exploitable, not just what’s theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.

This show is sponsored by Sentry.IO. Sentry wants to help you monitor your environment for problems. They do error tracking, stack tracing, debugging, all so that your developers can diagnose, fix, and optimize the performance of their code. This makes it so developers ship more reliable code faster. Learn more at sentry.io.

View all active sponsors.

Sources

Full list of sources on the show page: https://darknetdiaries.com/episode/177/

More from Darknet Diaries

All 50 episodes
177: National Public DataDarknet Diaries · 48 min
Listen in VO