Most Americans have very little choice but to provide their personal information to credit bureaus. Hackers have found a way into that data supply chain, and are advertising access in group chats used by violent criminals who rob, assault, and shoot targets.
To be clear for people who haven't read the article: the credit bureaus themselves are not selling information directly to criminal organisations. They are selling to other companies, who in turn may provide that information to even more third parties, who then sell it to data brokers. An example given in the article of what this data journey may look like was:
Immigration and Customs Enforcement has used similar data that flowed from utility companies to Equifax, which then was sold to data brokers.
The tools and databases owned by these data brokers are then used by criminals to sell information to anyone.
I wonder, could this problem be solved by adding some 'junk' data to each access request? With that junk data being a unique identifier, so the authorities can setup a sting to catch whoever is selling access