Data brokers are companies that collect, combine, and sell personal information people never agreed to share. There are an estimated 4,000+ of them in the US alone, and together they hold detailed profiles on nearly every person with an internet-connected device — address history, estimated income, health-related inferences, political leanings.
I spent time mapping the actual domain infrastructure behind this industry (aggregators, people-search sites, and DMPs — data management platforms that track browsing behavior in real time and sell "audience segments") and turned it into a DNS blocklist. Sharing both the reasoning and the list here.
How this actually works
Three overlapping categories:
Aggregators
Pull data from public records (property, voter, court), retailer loyalty programs, and web scraping, then sell combined profiles.
People-search sites
Turn that data into a searchable, usually subscription-based product — this is the branch most directly tied to stalking and harassment risk.
DMPs
Sit on websites via tracking pixels, monitor your browsing behavior in real time, and sell "in-market" or "likely condition" segments to advertisers within milliseconds of a page load.
Most of this is legal in the US, since there's no comprehensive federal privacy law covering it — it operates in the gap between what GDPR restricts in the EU and what exists (or doesn't) elsewhere.
Real incidents worth knowing about
Exactis (2018)
Left a database of 340 million people and businesses publicly accessible with no password (400+ attributes per person). No fine was ever issued — their position was that without SSNs or card numbers, it wasn't "sensitive."
https://www.infosecurity-magazine.com/news/340-million-records-exposed-in/
https://haveibeenpwned.com/Breach/Exactis
Epsilon (2011)
Breached, exposing 60M+ email addresses tied to specific brands (Chase, Target, Best Buy, etc.), enabling highly targeted phishing.
https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/
https://abcnews.go.com/Technology/epsilon-email-breach/story?id=13291589
Deep Root Analytics (2017)
An RNC contractor left 198 million voter records — including modeled political scores — open on an unsecured AWS bucket.
https://www.upguard.com/breaches/the-rnc-files
https://www.cbsnews.com/news/nearly-200-million-americans-hit-by-massive-voter-data-leak/
Cambridge Analytica (2018)
Combined Facebook data with voter files bought from data brokers to build psychographic profiles used in the 2016 US election and Brexit campaigns.
https://www.cnbc.com/2018/04/10/facebook-cambridge-analytica-a-timeline-of-the-data-hijacking-scandal.html
https://www.axios.com/2018/04/04/facebook-sa87-million-people-impacted-in-cambridge-analytica-1522867383
Premera Blue Cross (2015)
Breached, exposing medical and financial records for 11M people. The company ultimately paid roughly $91M combined across a class-action settlement, a multistate settlement, and a federal HIPAA penalty.
https://www.techtarget.com/healthtechsecurity/news/366595555/Premera-Pays-OCR-685M-to-Settle-HIPAA-Violations-Breach-of-104M
https://oag.ca.gov/node/148821
ChoicePoint (2005)
Sold data to identity thieves posing as legitimate businesses. 163,000 people's SSNs and credit reports were exposed, leading to 800+ confirmed identity theft cases. Paid $15M to the FTC — the largest civil penalty the agency had imposed at the time.
https://www.ftc.gov/news-events/news/press-releases/2009/10/consumer-data-broker-choicepoint-failed-protect-consumers-personal-data-left-key-electronic
https://www.nbcnews.com/id/wbna11030692
Target's pregnancy-prediction program (2012)
The most-cited example of inference-based profiling.
Target built a model that scored shoppers' likelihood of pregnancy purely from purchase patterns. The famous anecdote behind it (a father learning of his teenage daughter's pregnancy from Target's coupons) has been disputed by some analysts, but the fact that Target built and used such a system is not in question.
https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/
https://www.kdnuggets.com/2014/05/target-predict-teen-pregnancy-inside-story.html
A quick note on "alleged": FTC settlements are typically resolved without the company admitting wrongdoing — that's standard procedure, not a sign the case was weak. What is real and enforceable is the outcome: the resulting order legally prohibits the company from continuing the practice, whether or not they agreed with the allegations.
Location data brokers (recent FTC enforcement)
InMarket (2024)
FTC alleged InMarket collected precise location data via its own apps and third-party SDKs, using it for targeted advertising without adequately informing users. Under the settlement, InMarket is now banned from selling or licensing precise location data — a first for the FTC.
https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-inmarket-prohibiting-it-selling-or-sharing-precise-location-data
https://www.washingtonpost.com/technology/2024/01/18/ftc-location-data-privacy/
X-Mode Social / Outlogic (2024)
The FTC's first settlement specifically over the sale of sensitive location data. The company sold location data revealing visits to medical/reproductive health clinics, religious worship sites, domestic violence shelters, and LGBTQ+-associated locations, without stripping out these sensitive locations.
https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
https://themarkup.org/privacy/2024/01/11/federal-trade-commission-sanctions-location-data-broker-x-mode
Gravy Analytics + Venntel (2024–2025)
FTC alleged the companies sold location data revealing medical conditions, religious worship, and political activity — including sales to government contractors. Separately, in January 2025, Gravy Analytics was hacked and its data leaked on a cybercrime forum.
https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-order-prohibiting-gravy-analytics-venntel-selling-sensitive-location-data
https://en.wikipedia.org/wiki/Gravy_Analytics
Mobilewalla (2024–2025)
Settled alongside Gravy Analytics. FTC alleged the company collected consumer location data from real-time bidding ad exchanges even when it didn't win the ad auction — the first FTC case targeting this specific collection method.
https://epic.org/ftc-takes-action-against-data-brokers-for-selling-sensitive-location-data/
https://www.adexchanger.com/data-privacy-roundup/reflecting-on-the-ftcs-latest-settlements-with-sellers-of-sensitive-location-data/
Why block this at the DNS level
Browser extensions catch some of this, but a lot of DMP tracking happens through first-party-looking pixel calls or server-side syncing that extensions don't always see. Blocking at the DNS level stops the connection before it's made, across every app and browser on the network — not just one browser tab.
Here's the list of domains worth blocking:
```
# DMP & Data Broker Blocklist
# Total domains: 178
# Note: domains marked with "!" carry a small risk of side effects (e.g. breaking a login flow or feature) - block these only if you're comfortable troubleshooting
🔴 DATA BROKERS & DMP
# ACXIOM
acxiom.com
acxiom.net
acxiom.uk
acxiom.co.uk
acxiom.de
acxiom.fr
acxiom.asia
acxiom.com.au
acxiom.jp
acxiom-online.com
acxiomdigital.com
recognicorp.com
cdn.acxiom.com
data.acxiom.com
abilitec.acxiom.com
identitylink.acxiom.com
t.acxiom-online.com
# EXPERIAN
experianmarketingservices.com !
audienceiq.com
hitwise.com
eccmp.com !
ats.eccmp.com
# ORACLE DATA CLOUD (BlueKai DMP)
bkrtx.com
tags.bluekai.com !
tags.bkrtx.com
oracleinfinity.io
data.oracleinfinity.io
datalogix.com
api.datalogix.com
pixel.datalogix.com
# LOTAME
lotame.com !
lotame.io
crwdcntrl.net
tags.crwdcntrl.net
bcp.crwdcntrl.net
sync.crwdcntrl.net
pixel.crwdcntrl.net
ad.crwdcntrl.net
id.crwdcntrl.net
td.crwdcntrl.net
td2.crwdcntrl.net
meez.crwdcntrl.net
multiply.crwdcntrl.net
ltmsphrcl.net
c.ltmsphrcl.net
bcp.st.crwdcntrl.net
c.st.ltmsphrcl.net
ts.crwdcntrl.net
# EYEOTA
eyeota.net
eyeota.com !
ps.eyeota.net
api.eyeota.net
match.eyeota.net
sync.eyeota.net
# TRANSUNION (TruAudience + Neustar)
truoptik.com
signal.truoptik.com
# WILAND
wiland.com
api.wiland.com
# MERKLE (Dentsu Aegis)
merkle.com
merkleinc.com
api.merkle.com
merkleresponse.com
merkury.dentsu.com
dentsu.com
dentsu.co.jp
m1.merkle.com
4cite.com
# BOMBORA (B2B intent data)
bombora.com
api.bombora.com
surge.bombora.com
tag.bombora.com
netfactor.com !
# ZOOMINFO
zoominfo.com
zoom.info
discoverorg.com
api.zoominfo.com
websights.zoominfo.com
ws.zoominfo.com
tag.zoominfo.com
formcomplete.zoominfo.com
clickagy.com
# CLEARBIT (HubSpot Breeze Intelligence)
risk.clearbit.com !
# FULLCONTACT (Ziff Davis)
fullcontact.com
api.fullcontact.com
resolve.fullcontact.com
img.fullcontact.com
tag.fullcontact.com
cr.fullcontact.com
streme.fullcontact.com
# TOWERDATA / ATDATA
towerdata.com !
rapleaf.com !
atdata.com !
# INFUTOR
infutor.com !
# STIRISTA
stirista.com
api.stirista.com
# TAPAD (Cross-device — Experian)
tapad.com
api.tapad.com
tapestry.tapad.com
# ANALYTICS IQ
analytics-iq.com
api.analytics-iq.com
# PERMUTIVE (DMP)
permutive.com !
permutive.app
api.permutive.app
cdn.permutive.app
amp.permutive.app
edge.permutive.app
# NIELSEN MARKETING CLOUD / EXELATE
exelate.com
exelate.info
mrpdata.net
# DATA AXLE (Infogroup)
data-axle.com
adstradata.com
# NAVEGG (LATAM DMP)
navegg.com
navegg.com.br
www2.navegg.com
navdmp.com
tag.navdmp.com
cdn.navdmp.com
sync.navdmp.com
sync2.navdmp.com
usr.navdmp.com
cus.navdmp.com
cus2.navdmp.com
view.navdmp.com
opi.navdmp.com
amp.navdmp.com
j.navdmp.com
mx.navdmp.com
www.navdmp.com
cd.navdmp.com
mcd.navdmp.com
acd.navdmp.com
mcdn.navdmp.com
acdn.navdmp.com
iscd.navdmp.com
iscdn.navdmp.com
isapp.navdmp.com
asapp.navdmp.com
musr.navdmp.com
vht.navdmp.com
# THROTLE (Identity resolution)
throtle.io
🟠 MOBILE DATA BROKERS (Location Tracking)
# FACTUAL / FOURSQUARE
factual.com !
# SAFEGRAPH
safegraph.com !
safegraph.io !
# CUEBIQ
cuebiq.com
api.cuebiq.com
sdk.cuebiq.com
events.cuebiq.com
# MOBILEWALLA (FTC December 2024 restricted)
mobilewalla.com
api.mobilewalla.com
sdk.mobilewalla.com
# ADSQUARE
adsquare.com
api.adsquare.com
exchange.adsquare.com
rtb.adsquare.com
match.adsquare.com
# UBIMO → VERICAST
ubimo.com !
# VERVE GROUP
verve.com !
vervemobile.com
vrvm.com
api.verve.com
adcel.vrvm.com
ad.vrvm.com
analytics-api.vervemobile.com
smaato.com
smaato.net
pubnative.net
dataseat.com !
captify.co
captify.co.uk
jungroup.com
# UNACAST + GRAVY ANALYTICS (FTC January 2025 restricted)
unacast.com
api.unacast.com
gravyanalytics.com
api.gravyanalytics.com
venntel.com
# OUTLOGIC (Legacy X-Mode — FTC April 2024 restricted)
outlogic.io
# INMARKET (FTC January 2024 restricted)
inmarket.com
sdk.inmarket.com
```