Researchers Invented People Who Don't Exist. Brokers Sold Them Anyway.
In 2026, a team of researchers submitted fake identities to health insurance quote forms, then went and bought that same data back from broker marketplaces, sometimes for a few dollars a lead, with almost no verification that they were the actual buyer. The study, hosted by the FTC and set to appear at a major security conference, is one of the clearest real world demonstrations of how an ordinary web form turns into a spam problem in your inbox.
It does not prove that every spam email you get came from a data broker. It proves something narrower and still useful: that a single form submission can be resold with almost no friction, and that the people buying leads often have no way to confirm who they are actually contacting.
What did the researchers actually find?
The researchers created controlled profiles and submitted them to health insurance lead generation sites, then tracked what happened next. About 21 percent of those seeded profiles received marketing email. Roughly 18 percent of the sites they tested had no working unsubscribe mechanism described in their privacy terms, and 16 percent had no working opt out contact at all. Then, to test the marketplace side, the researchers bought 400 leads from three different broker exchanges, and were able to purchase their own seeded lead back, with little or no check on who was doing the buying.
That last part is the detail worth sitting with. A lead marketplace is supposed to connect real buyers, like insurance agents, with real prospects. This study showed that almost anyone with a few dollars could buy a stranger's contact information with no meaningful verification that they had a legitimate reason to have it.
Is spam actually getting worse in 2026?
The trend lines are mixed depending on what you measure. The Anti Phishing Working Group reported 971,181 unique phishing attacks in the first quarter of 2026, up 13.8 percent from the previous quarter. Microsoft separately reported detecting around 7.6 billion email based phishing threats across its own systems in the second quarter of 2026, though that number declined month over month, partly credited to the takedown of a phishing toolkit called Tycoon2FA. Google says Gmail blocks more than 99.9 percent of spam, phishing, and malware before it ever reaches your inbox, which is reassuring, though it is also a number from the company doing the blocking, not an independent audit.
None of these numbers, on their own, prove that data brokers are the reason your specific inbox is full. Spam and phishing are usually not one problem with one cause. Your email can end up in these pipelines through breaches, scraping, direct collection, or a lead form you filled out for a quote, and brokers are one amplifier among several, not the sole source.
Does that mean data removal will fix your inbox?
No, and we would rather tell you that plainly than let you assume it. Removing your listings from people search and broker sites can reduce how much of your information is available for future collection and resale. It cannot recall copies of your email address that have already been sold, retract data pulled during a breach, or stop a phishing email sent to a randomly generated address that has nothing to do with any broker at all. If your specific problem is phishing, the fix that actually helps is filtering, reporting, and account security, not just an opt out.
If a quote form is where your email started leaking, that is exactly the kind of exposure we can chip away at.
Privoria removes your listings from people search and broker sites, using real people who monitor and refile, not a one time automated sweep. It will not touch your existing spam filter or delete a breach that already happened, but it does shrink the pool of current data available for the next round of lead selling.
Run my free scan Start free trialWhat actually reduces spam, starting today?
Start with the free options before spending anything.
- Use a separate alias or masked address for quote forms, sweepstakes, trials, and comparison shopping sites, and keep your real address for banking, healthcare, and account recovery.
- If a surge of mail starts hitting one alias, you now know exactly which merchant or form was the source, without guessing.
- Only unsubscribe from senders you recognize as legitimate. Under the CAN SPAM Act, a real commercial sender has to honor an opt out request within 10 business days.
- Never click unsubscribe on a message you do not recognize. That link can confirm your address is active or lead to a phishing page. Mark it as spam instead.
- Report phishing to reportphishing@apwg.org or through the FTC's ReportFraud site, then delete it.
- Turn on two factor authentication so a phishing email that does get through cannot take over your account even if you click something you should not have.
Why do quote and comparison sites leak so easily?
Lead generation sites make money by selling your submitted information to buyers, and that is often disclosed somewhere in a privacy policy you never read. The FTC has documented this business model going back over a decade, including a case against a broker called LeapLab, which the FTC alleged bought payday loan applications and resold them to marketers and, in some cases, to fraudulent online merchants. The 2026 study builds directly on that pattern, showing it is still active in the insurance quote space specifically. Before filling out a free quote or comparison form, it is worth asking whether the convenience is worth the resale.
Related reading
Does removal actually reduce future spam risk?
According to research cited by Consumer Reports, people who tried clearing their own broker listings by hand or with automated tools only managed to get about 27 percent of exposed listings taken down, while ongoing removal handled by real people who monitor and refile reached closer to 70 percent. That gap is the whole argument for using a service instead of doing it once yourself: brokers relist old data constantly, and a one time cleanup does not stay clean.
Frequently asked questions
Can I tell if my spam came from a data broker specifically?
Usually not with certainty. Your address can enter marketing pipelines through breaches, scraping, direct signup, or broker resale, and there is rarely a clean way to trace one email back to one source unless you used a unique alias for that specific form.
Is it safe to click unsubscribe on marketing email?
Only from senders you recognize and trust. On an unfamiliar or suspicious message, skip the unsubscribe link entirely and mark it as spam or junk instead, since a fake unsubscribe link can lead to a phishing page.
Will using an email alias actually reduce spam?
It will not prevent spam outright, but it isolates the damage. If one alias starts getting flooded, you can shut that single alias down without losing your main inbox, and you learn exactly which sign up caused it.
Can Privoria stop phishing emails from reaching me?
No. Removal reduces how much of your information is publicly available for future collection, but it does not filter your inbox or block delivery. Spam filtering, two factor authentication, and careful clicking habits are what stop the emails themselves.