Search for a personal loan on a Tuesday. By Thursday, a call comes in from a number you do not recognize, and the person on the line already seems to know you are in the market for one. It does not feel like a coincidence, and it usually is not.
The path between those two moments runs through an industry most people never see: browser cookies and invisible tracking pixels feed profiles into data-broker marketplaces, and those profiles get bought and sold, sometimes for legitimate advertising, and sometimes by lead generators whose downstream buyers turn out to be telemarketers and fraudsters.
This is not speculation.
The Federal Trade Commission has brought and settled a string of cases against companies that built exactly this pipeline, and the enforcement record names the companies, the data, and the money involved.
This article walks through what tracking technology actually collects, how that collection becomes a sellable product, what the regulatory record shows about where it has ended up, and the concrete steps that reduce how much of your own data enters that pipeline in the first place.
What Cookies, Pixels, and Fingerprints Actually Collect
The FTC's own consumer guidance lays out the mechanics in plain terms: websites and apps use cookies and pixels to identify you across visits, device fingerprinting to recognize your browser's unique configuration even without a stored file, and advertising identifiers on smartphones to track you across apps. Cross-device tracking then links your laptop, phone, and tablet into a single profile, on the theory that the same person is behind all three.
First-Party Versus Third-Party Tracking
Not all tracking is equal. First-party tracking is a site remembering its own visitor, the way a retailer remembers your cart. Third-party tracking is different in kind: an outside ad-tech company embedded on thousands of unrelated sites can watch you move between them, building a browsing-history profile used, in the FTC's own words, to serve "personalized ads based on your browsing history or your location." The site you are on did not do this to you; a company you have never heard of, sitting behind an invisible script, did.
Device Fingerprinting and Cross-Device Profiles
Fingerprinting exists precisely because cookies can be deleted. Your browser's screen resolution, installed fonts, time zone, and dozens of other settings combine into a signature that is often unique enough to re-identify you even with no cookie present. Paired with an advertising identifier from your phone, that signature lets a tracker stitch your desktop research session to the ad you see later on your phone, which is how a search you thought was contained to one device follows you onto another.
The Real-Time Bidding Pipeline That Broadcasts Your Data
Every time a webpage with an ad slot loads, an automated auction fires: a broadcast describing the visitor, location, device identifiers, inferred interests, goes out to hundreds of ad-tech bidders in milliseconds, and the winner's ad appears before the page finishes loading. This is real-time bidding, and it is the mechanism that makes granular targeting technically possible at the scale it happens today.
The FTC's case against Mobilewalla, announced December 3, 2024, is the clearest proof that this data does not stay contained to the auction. The FTC alleged Mobilewalla scraped more than 500 million unique advertising identifiers paired with precise location data between January 2018 and June 2020, largely from real-time bidding exchanges never designed to let a bystander harvest and keep the data flowing through them. It then built and sold audience segments tracking people at health clinics, religious sites, military installations, pregnancy centers, and protests, including segments organized by race.
Then-FTC Chair Lina Khan put it directly: "Mobilewalla exploited vulnerabilities in digital ad markets to harvest this data at a stunning scale." The settlement, approved on a 4-1 vote, bans Mobilewalla from selling sensitive-location data tied to health facilities, religious sites, military bases, and similar categories, and requires it to verify that its data suppliers actually obtained consent. A companion case against Gravy Analytics and its Venntel subsidiary, announced the same day, alleged the same underlying practice.
How Your Browsing History Becomes a Data Broker's Product
Mobilewalla is not an isolated case. It sits alongside a run of FTC actions against companies that collected data through ordinary-looking apps, websites, or health tools and then sold or shared it well outside what a user would have expected.
Read across the row, the pattern repeats: data collected for one stated purpose, an app working, a discount code loading, an ad slot filling, ends up as inventory in a marketplace the person who generated it never agreed to and, in most of these cases, never knew existed.
From Data Point to Phone Call: The Lead-Generation Pipeline
The step that turns a browsing profile into an actual scam contact runs through what the industry calls lead generation, and the FTC has pursued this piece of the chain separately from the location-data cases.
The FTC's own framing of the MediaAlpha case is worth quoting directly: "Lead generators should tell the truth when they collect consumers' information. It's illegal to make false or misleading claims about your identity and affiliations, how a consumer's information will be used, or what consumers will get if they provide their information." That is the exact gap these three cases exploited, at a combined scale of hundreds of millions of consumer records.
This is also where a search for a specific bank or lender can turn into a targeted approach: a related pattern, documented in how scammers fake bank documents with ordinary design tools, shows what a fraudster does once they know which institution you already use or were researching.
Why Targeted Data Makes Fraud More Convincing
None of the cases above prove that a specific scam call traces back to a specific search. What they prove is the mechanism: a form you filled out, or a session an ad-tech company silently profiled, can legally and illegally end up sold to a buyer who was never disclosed to you. Cybersecurity researchers and consumer-advocacy groups such as the National Cybersecurity Alliance describe scammers separately buying access to inexpensive people-search sites, the same kind of consumer data-broker product, to assemble a target's name, address history, relatives, and rough income tier before making contact. That reporting is credible and widely corroborated, but it is secondary-source description of a pattern rather than a single regulator's documented case, and it is presented here on that basis.
What the FTC's own record does establish is that income-tiered and interest-specific targeting is exactly what these data products are built to do. A profile assembled from loan searches, insurance quotes, and browsing history is not generic; it is sorted by the same categories a legitimate advertiser would pay to target, which is precisely what makes a scam pitch built from it feel personal instead of like a random cold call.
Pig Butchering and the Long Con
The scam type most dependent on this kind of profile-building is "pig butchering," a long-con crypto investment fraud named for the practice of fattening a target before the loss. The Financial Crimes Enforcement Network issued a formal alert on the pattern, and the FBI runs Operation Level Up, launched in January 2024, to proactively identify and contact likely victims before they lose money, a step that only makes sense for a scam built around sustained, personalized contact rather than a single call. The mechanics of the con itself are covered in more depth in this site's explainer on how pig butchering drains life savings.
According to the FBI's 2025 Internet Crime Report, investment fraud, much of it crypto-related, accounted for $8.6 billion in reported losses across all victims, and $3.52 billion among victims aged 60 and older specifically, the single costliest category for that age group.
The Scale of Fraud Losses, in the Regulators' Own Numbers
The two federal agencies that track this closest, the FTC and the FBI, count differently and should not be added together, but each on its own shows a fast-growing problem. The FTC's Consumer Sentinel Network Data Book for 2024 put total reported fraud losses at $12.5 billion, up 25% from 2023, across 2.6 million fraud reports. The share of people who reported losing money jumped from 27% in 2023 to 38% in 2024.
FTC Bureau of Consumer Protection Director Christopher Mufarrige summarized the trend plainly: "The data we're releasing today shows that scammers' tactics are constantly evolving." Scammers' top three contact methods, per the same report, are email, then phone calls, then text messages, and consumers lost more to bank transfers and cryptocurrency combined than to every other payment method combined.
IC3, the FBI's fraud-reporting clearinghouse, put 2025's total reported losses at $20.9 billion — a 26% jump over 2024. Adults 60 and older accounted for $7.7 billion of that, roughly a 59% increase from 2024, across more than 201,000 complaints, with the average loss per older victim exceeding $38,000 and at least 12,400 victims losing $100,000 or more. Cryptocurrency-related fraud broadly was IC3's single largest category at $11.3 billion. IC3 also tracked AI-enabled fraud as a formal category for the first time in 2025: more than 22,000 complaints and roughly $893 million in losses agency-wide, including over 3,100 complaints and $352 million in losses among seniors specifically.
Your Legal Rights, and a Regulatory Gap That Still Exists
There is no dedicated federal statute regulating data brokers. Every case described above was brought under the FTC's general Section 5 authority to police unfair or deceptive practices, applied one company at a time rather than through a broker-specific rulebook.
The Data Broker Rule That Was Proposed, Then Withdrawn
That gap almost narrowed. On December 3, 2024, the Consumer Financial Protection Bureau proposed a rule that would have brought data brokers under the Fair Credit Reporting Act, giving consumers FCRA-style rights, access, accuracy disputes, and purpose restrictions, over broker-held data, including data tied to financial behavior such as loan and insurance searches. After an extended comment period, the CFPB withdrew the rule on May 15, 2025, stating in the Federal Register notice that the rulemaking was "not necessary or appropriate at this time." A rule that would have directly addressed the "your loan search becomes a broker's product" scenario this article describes was proposed and then set aside, which leaves consumers relying on state law and case-by-case FTC action for now.
California has built the most concrete infrastructure to fill part of that gap. Under the Delete Act, data brokers must register annually with the California Privacy Protection Agency, and as of January 1, 2026, residents can submit a single deletion request to every registered broker through the state's DROP platform; brokers must begin actually processing those deletions by August 1, 2026. Enforcement is real: the CPPA fined S&P Global $62,600 in January 2026 for failing to register as a data broker in the first place. Separately, under the CCPA, California consumers can opt out of the sale or sharing of their personal information, and businesses must honor that request within 15 business days.
The clearest evidence that an opt-out signal has real teeth is the California Attorney General's $1.2 million settlement with Sephora, announced August 24, 2022. It was the state's first CCPA enforcement action, brought because Sephora failed to honor Global Privacy Control signals and did not disclose that letting ad-tech read shoppers' browsing through tracking pixels counted as a "sale" of their data under the law.
The European Union's GDPR offers a useful point of comparison, even though it does not directly govern a US reader's own rights. Its Article 17 "right to erasure" applies regardless of how the data was collected, whether provided directly, gathered through cookies and tracking, or purchased from a broker, and requires a controller to erase it without undue delay, defined as within one month.
No comparable single right exists yet under US federal law.
How to Reduce What Trackers and Brokers Can Collect on You
None of this is fixed by default settings, so the practical steps below are still manual.
Third-party cookies are still fully active in the browser most people use. Google announced in July 2024 that it would keep third-party cookies in Chrome rather than phase them out as originally planned, scaled back the replacement consent prompt by April 2025, and retired the alternative Privacy Sandbox tracking tools in October 2025 for low adoption. Blocking third-party cookies, using private browsing, and reviewing app permissions for location, contacts, and photos, all steps the FTC itself recommends, currently require going into browser and device settings directly rather than waiting for a platform default to change.
A short, concrete checklist: block third-party cookies in your browser's privacy settings; turn off ad personalization in your phone's OS-level ad settings; opt out through the Digital Advertising Alliance's WebChoices tool at optout.aboutads.info; and file a prescreened-offer opt-out at OptOutPrescreen.com, the official site jointly run by Equifax, Experian, Innovis, and TransUnion under federal law, either online or by calling 1-888-5-OPT-OUT.
One formerly common tool is now dead and should be removed from any bookmark list: the Network Advertising Initiative's opt-out registry ceased operating on September 15, 2025. Readers who previously used optout.networkadvertising.org should switch to the DAA's WebChoices tool for desktop and youradchoices.com/appchoices for mobile.
If You Live in California
California residents have the most direct path available anywhere in the country: file one request through the state's DROP platform to reach every registered data broker at once, and set a Global Privacy Control signal in a supporting browser or extension, which state regulators have already treated as a legally binding opt-out request in the Sephora case above. Some people pay third-party removal services to file these kinds of requests on their behalf; verify any such service's current coverage and pricing directly with the company before signing up, since those details are self-reported and change often.
None of these steps close the pipeline entirely, cross-device fingerprinting in particular is hard for an individual to fully block, but each one removes a real data point from circulation, and removing several at once is the difference between being an easy, cheaply built profile and an expensive one that fewer buyers bother with. The same underlying profile data is also what makes phone-based identity theft like the tactics covered in SIM swap fraud easier to pull off, since a scammer who already has your name, carrier, and account details from a broker has a head start on impersonating you to a support agent.
The Bottom Line
The scenario at the top of this article, a search followed by a suspiciously well-informed call, is not paranoia. The FTC's own enforcement record shows the pipeline it depends on is real: tracking cookies and pixels feed profiles into data-broker marketplaces, lead-generation companies have been caught selling loan and insurance data "without regard for how the information would be used," and the resulting targeting supports fraud categories, investment scams above all, that cost Americans tens of billions of dollars a year. A related version of the same targeting logic shows up in fake investment ads built with ordinary digital-marketing tools, which rely on the same audience-targeting systems described here rather than on broken cookies. Closing the federal regulatory gap is not something an individual reader controls. Blocking third-party cookies, opting out through the working tools that remain, and filing a California DROP or GPC request where available, are.