-
Here is an interesting case that popped into my news feed this morning: a New Jersey woman, Judith Henry, was arrested in 2019 by Federal Marshals and held in the Essex County jail in Newark for a bit over 2 weeks, because a warrant had been issued for a different Pennsylvania woman who had the same name, and who had jumped bail in Pennsylvania 26 years ago. Ms. Henry was not released until she was transferred to a Pennsylvania jail where the officers took the 1 or 2 minutes required to compare her fingerprints to those of the actual criminal.
Ms. Henry sued pretty much everyone involved (there are some 30 defendants), claiming that she told them she was not the person they were looking for, and that if they had just taken a trivial amount of time to check her fingerprints (which they had on file in Newark), they would have confirmed that they got the wrong Judith Henry. Among other things, she claimed that because she was Black and Jamaican, the officers did not take her claim of innocence seriously.
In short: Ms. Henry was wrongly detained for reasons that could easily and quickly have been determined by any of 30 law enforcement officers. None of them bothered, including the Federal Marshals who served the arrest warrant. The six Marshals in the suit asked for the case to be dismissed against them on the grounds that they did their jobs as legally assigned and were therefore protected by “qualified immunity“; the initial judge didn’t dismiss it; so the Marshals took it to the Federal Appeals court which let them off, agreeing that they were just doing their jobs and were in fact entitled to qualified immunity. The rest of the case against the other 24 defendants and against Essex County still stands and will continue back where it started in Federal District Court.
This seems to be a case where the justice system was technically right, but justice was not served, in that no remedy is offered to Ms. Henry. Yet, anyway.
Note on how the news works: Most of the news stories imply that the entire case was dismissed in the ruling, which is not true. Dismissing the case when the police were clearly wrong is a much more compelling story than the real one. I know this because I read the actual opinion of the Federal Appeals Court judge. Where a story is more complicated than can be described in one or two simple sentences, you have to go to original sources to find out what happened. Most of us don’t have this kind of time. Oops. End of note on how the news works.

Here is a screenshot of the Fox News headline about this story, which pretty clearly implies that the whole case was thrown out by the judge over qualified immunity. It wasn’t. And it was not just Fox News, although Fox and the New York Post were the most egregious – and the most conservative. Regarding the text of the appeals court ruling – here it is, for reference: https://www2.ca3.uscourts.gov/opinarch/231987p.pdf. Legally, the key part of the ruling was “qualified immunity,” one of those concepts that are tagged as a “constitutional right” but actually was invented by the Supreme Court in 1967. It holds that law enforcement officers cannot be sued for doing their jobs. The Marshals who arrested and detained Ms. Henry had a legitimate and authorized warrant, including the wrong name, address, and picture. Since they were not the investigating officers in her case, they did not have an official obligation to do further detective work to confirm or deny the validity of the arrest. The judge notes that many defendants will claim to be innocent when they are not, and that it is not the job of the arresting Federal Marshals to ascertain whether those they arrest are lying.
Historically, this aspect of the law goes back to the post civil war reconstruction era of 1871 when white police officers would beat, lynch, and kill recently emancipated Blacks with impunity. (Mostly) Southern Whites could not stand to see former slaves being treated as humans, and the ranks of the police were not immune to these feelings. In response, Congress passed the Civil Rights Act of 1871, or 42 USC 1983. This law, for the first time, allowed private individuals to sue the police or other authorities if their constitutional rights were violated.

The Civil Rights Act of 1871 was known as the ‘Klu Klux Klan Act’ because the Klan was a primary target of the law, and included law enforcement officers. This law held firm until 1967, when it was essentially overturned by the Supreme Court. I guess the Justices thought it was now ok for the police to beat up Black people? I wasn’t there, so this is just speculation. The Supreme Court can be inscrutable at times. It was the height of the Black Panthers movement and, of course, hippies, electric guitars, the Beatles, and free love. Perhaps I will come back to this in a later post, but I was 17 and, well, I was 17. Let’s leave it there.
Qualified Immunity was the outcome of the decision in the Supreme Court case Bivens v Six Unknown Named Agents (1967). It held that law enforcement officers could only be subject to lawsuits if they violated certain specified constitutional rights of the plaintiffs, thus restricting the ability of private citizens to sue the police for false arrest, beatings, and whatnot. Federal Bureau of Narcotics agents raided Mr. Bivens’ home and arrested Mr. Bivens, even though they had no warrant authorizing the raid. Mr. Bivens sued, it was appealed to the Supreme Court, and this case let the Feds off the hook.
The Bivens ruling was clarified in Harlow v. Fitzgerald (1982), because the original ruling required that the state of mind of the police officer be considered, which was generally difficult to ascertain. Harlow ruled that the official would be liable in a civil suit only if a “reasonable person” in the same position would have known that the actions were not in accordance with the law. The judge in the Essex County case did not buy that the six Marshals acted outside the law, or that any other Marshals would have done anything differently.
The judge also dismissed Ms. Henry’s claim that, in effect, had she been white (or white and wealthy), the officers would have taken her plea of innocence more seriously, quickly checked her prints, and let her go right away. The judge ruled that Ms. Henry provided no evidence that racial bias was a factor in the 2 week delay.
How would anyone in these circumstances provide evidence of racial bias? Judith Henry could be right, but the judge is, in my opinion, asking for an impossible standard. Just because the Marshals didn’t say in their legal brief that “You were a Black woman, so we assumed that you were guilty,” doesn’t mean that it didn’t happen. No one in their position would ever admit to this. (Although in their defense, the Klu Klux Klax was pretty upfront about their goals and beliefs.)

The NJ Essex County Jail, where Ms. Henry was held for two weeks because the officers would not bother to do a quick check of her fingerprints (I took this photo from the New York Post) This story hits a personal note for me, because I became friends with an older man who spent 20 years as a guard at this very same Essex County jail. He recently passed away – he was in his 90s and life caught up with him. He had a senior position at the jail, responsible for training the newer guards. I asked him one day about the guilt or innocence of the prisoners at Essex County, and his reply (I am quoting him on this) was: “If the police arrest them, then they are guilty.” He was quite clear on this point, and probably represented the majority view of Essex County jail guards at the time he worked there.
This is, of course, not the view of our Constitution.
Obviously, my friend was not involved in the Judith Henry situation. But it sets a context for the facility she was held in, where no one would bother to take the one or two minutes required to check out her claim that they had arrested the wrong person. Stay tuned for further updates on this case.
-
This story began with what looked like yet another routine data breach, but became a lot more as I understood it better. Let’s start at the beginning.
My news feed last week included a story with this teaser: “The Social Security numbers and related data of 3 billion Americans was just stolen. Here’s what you need to know.”
What I needed to know was what drug those news editors were on, because I wanted some. There are only about 340 million people in the United States, not all of whom even have social security numbers. Here is a handy chart to illustrate the problem:

I love charts! You can see from this that there is something horribly wrong with the news. To find out what it might be, I went to Ground.News, a news aggregator that shows a neat list of each media organization that is running a particular story along with its evaluation of whether that organization is biased to the left, to the right, or is centrist. All of the 30 or so sources for this item were centrist (so far, good!) so I started scrolling through them. What I discovered was that there were 30 or so copies of the exact same text that had been reprinted by news outlets from all over the country. Ground.news’s AI bot had accurately summarized all of these stories, but unfortunately, they were all identical and therefore all equally preposterous.
Being the good citizen that I am, I sent a feedback note to the editors of Ground.News and received the most lovely letter in return. It said, in part: “Thank you for taking the time to report the error in the Ground Summary. We wanted to let you know that our team has seen your report and manually updated the summary with the correct information thanks to your help.” I will always treasure this letter, and I hope that it was written by a real person. After a few days, the news shifted to saying that the 3 billion was not the number of Americans, but rather the number of data records. I am going to take partial credit for making the world a more numerically literate place.
Let’s take a minor side trip and talk about why 30 news outlets would all repeat the same preposterously wrong information. Did someone substitute decaf coffee in the Starbucks daily orders for all of these people? Were they all at a convention of news editors, leaving the actual editing to their 10-year old kids? (I asked my 10-year old grandson to estimate the total number of Americans, and he was way off, despite being very smart, so I think that appointing our kids to edit the news would have some problems.) Were the news editors of all these publications going through emotionally messy divorces? I don’t think that we will ever know. Whatever it was, no one competent to edit the news was at the helm.
Going back to the story, the data breach was reported to come from a Ft Lauderdale company called “National Public Data,” or NPD. Here they are, as pictured on their own web site:

I wish I worked there! These people are loving their jobs. In the “About Us” section, it said that “Many different business use our services to obtain criminal records ….”
What? After reading this I am starting to be not so enthusiastic about working there- do they really help their clients to become criminals?
Of course not. I was joking. Actually, they are a data aggregator, aka data broker, or a company that collects massive amounts of private information about people and then sells it to anyone who pays them a very small fee, thereby rendering it not private anymore, and without the permission of the person whose information it is. I know that this sounds pretty unethical, but it is actually perfectly legal here in America! Who says America needs to be made Great Again? Only a country that is already great would allow this type of marketplace to thrive.
Being curious about why this job of un-privatizing our personal information would be so fun, I did a reverse image lookup on the four employees that are featured above on their web site, and discovered that the four happy young business people are actually an Adobe stock image titled “Group of Happy Young Business People”, who are models and have no connection with NPD. In other words, while NPD is happy to reveal your private information to anyone in the world, they are not revealing who they really are on their own web site.
NPD’s web site says that they specialize in background searches on individuals and on criminal records check. I quote them here: “All of our searches can be delivered in XML for you to embed into your applications or websites, which is perfect for those reselling public records.” This means that whatever information they might have is sold to people who then resell it. If your name pops up, there will not be any way to authenticate where the info came from, how trustworthy it is, or have any direct way to fix errors. What could possibly go wrong? (I apologize for not explaining XML; you will have to ask me about it outside of ‘Grandpa Blogs the News’. Sufficient to just say that it soups up the reselling.)
I tried to find out just how great the market for this stuff really is, and while I could not find a single authoritative source, there are multiple estimates that data brokers do more than $200 billion in sales annually, with likely growth to $500 billion in the next few years. To me, that is a lot of money, not to mention a lot of selling of people’s private information without their permission. Here is what EPIC, the non-profit Electronic Privacy Information Center, says about them: “As the data broker industry proliferates, companies have enormous financial incentives to collect consumers’ personal data, while data brokers have little financial incentive to protect consumer data.” They go on to clarify that we (Americans, that is) are the product and not the customers of this industry, giving us little recourse.

John Oliver did a segment on data brokers in April 2022. I know he is not to everyone’s taste, so please don’t watch if you are not a fan of his show. My feelings won’t be hurt. I am throwing this in as a bonus for Gen-X-ers or those who think like youngsters; you don’t have to watch to get the point of this blog entry. https://www.youtube.com/watch?v=wqn3gR1WTcA To bring us all up to date on the data breach, in April of this year, or about four months ago, a cybercriminal who calls himself “USDoD” claimed to have stolen the 3 billion social security numbers and related detailed information from NPD. In August, NPD admitted that this really happened, stating that it had “detected an intrusion” into its computers as early as December 2023. USDoD has evidently packaged this information and had started selling it on the “dark web.” (It is better left unsaid what the ‘dark web’ is, so I am not saying it.) USDoD was asking $3.5 million for the files. (This is about a tenth of a cent per data record – a relative bargain.)
The breach became more widely known when a second cybercriminal (I don’t know who this was or where he got the files from) made the same information available to anyone who knew where to look, but this time for free. Meanwhile, the expected legal dogpile has started. At least 14 complaints have been filed against NPD’s parent company Jerico Pictures Inc. and its owner Salvatore Verini, including a class-action lawsuit in Federal district court in Florida. It was the lawsuits that seem to have triggered most of the mainstream news about the event.
As far as I can tell, the lawsuits are alleging that NPD failed to adequately protect against unauthorized release of the private information. I am eager to find out what a Federal judge will make of this, since NPD is basically in the perfectly legal business of releasing unauthorized private information to anyone who is willing to pay a few cents per data record.
Let’s find out what we are talking about. It turns out that anyone (including you, the reader!) can query this stolen database to see what information it might have about you. If you go to ‘npd.pentester.com/breach’ you can enter a name, state of residence, and birth year, and get a listing of all entries that match those criteria. You don’t get all the data in the file because the people who run Pentester are just trying to let people know whether their info was stolen or not. To get a complete data set, you need to go directly to NPD and contract with them for a search. I have not tried this myself, but I think that anyone could do it (although they might be shutting down soon due to the bad publicity, the lawsuits, and all, so act quickly – this offer may expire soon).

I did a search on Joseph Biden, Delaware, DOB 1942. This gives you a feel for what you get from Pentester.com, although the real stolen data contains much more. I figured that Biden’s information is already public, so no beans are being spilled. Public info says that the Barley Mill Rd address is where he currently resides; his birthday is November 20, so these elements seem to be correct. His dad was also named Joe, so some of these could be his father. I found 17 entries that had my personal information, including date of birth, my address, my social security number, my phone number, and whatever else what not shown by Pentester. Most of these had at least one item missing, and most were old. For example, there were entries for ’34’ instead of ‘134’ for my street address; this changed within a year or two of my moving into the house. Also, there were entries for my former home in Summit, NJ which I moved away from in 1969. A couple of them showed everything correct except for Tinton Falls, NJ, which I have never lived in. Some of them were blank in the Social Security number field, but not all, and the ones with an SSN looked correct. Ditto for my date of birth. The ones that had a phone number were all for my landline which is still active but unused, and which receives several spam calls every day. Maybe this is why.
When I put in Connecticut for the state, there was an entry for the address that my daughter lived in when she was in graduate school. This is because I co-signed a car loan while she was there. When I then changed the state to Florida, two entries came back with my mom’s address because I was listed for a time as a co-principal on one of my Mom’s credit cards. This was to help her purchase things after her eyesight started failing and ordering on the Internet was difficult for her.
This was getting to be fun, so I put in my Dad’s name and NJ. He died in 1996. Up popped 5 entries! These were all accurate, reflecting his addresses after about 1950. The addresses looked correct, although the dates of birth were wrong. I didn’t double check the social security numbers.
At this point you are probably asking yourself: “Why do I think that I have been hacked, sort of?” It is because the private information that is now available for free to criminals to use was already available to them, but just in a slightly different form, and from a perfectly legal company that would have been happy to sell it to anyone for a very small price per item.
Looking at what information was in this breach, it became evident to me that the data likely originated from one of the credit reporting agencies (“CRAs”). The three big ones are Equifax, Experian, and TransUnion, but there are others. When I compared the information on my credit reports to that of the data breach, I saw that they were nearly an exact match. The same addresses and information that are maintained by the CRAs showed up in the NPD data set. Voila!

In 2017 Equifax, one of the ‘Big Three’ US Credit Reporting Agencies, lost control of 147,000,000 personal records of Americans including sufficient information that would allow criminals to steal from you. They were found by the courts to have not taken data security practices seriously. What are these CRAs? As a reminder, the CRAs provide a service to banks and other lending organizations that streamlines the time needed by a bank to decide whether you are eligible to receive a loan or not. Without these CRAs, the loan officer would have to undertake lengthy research to find out whether you paid all your bills on time, had an excessive debt balance, and so forth, and this information is distributed across many, many financial entities. The CRAs have an agreement with pretty much all banks whereby the bank tells the CRAs about every financial transaction you incur, including account balances and debts owed, and in return, the CRAs sell this information back to the bank when it wants to decide on loan eligibility. Believe it or not, you and I have already agreed to this “un-privatization process” as part of the fine print we sign when we open any bank account. Other organizations can use this service, like car dealers when they want to issue a car loan, and the CRAs also sell your financial information to businesses for other applications.
There is no way to opt out of this arrangement unless you don’t want to ever have a bank account. Being un-banked would prevent most Americans from holding a job, buying goods and services, renting or owning a home or apartment, owning a car, and so on. So, un-privatization starts with CRAs, and then gets amplified by data aggregators. When any of these has a data breach, the un-privatization gets worse, but this data breach appears to rest on a foundation of CRAs sitting on private information for virtually every American.
Arrgghhhh!!! Sorry this blog has turned dark! I wish I didn’t know any of this! You probably are too! Here’s what you can do:
- Contact the CRAs and ask them to freeze (not lock, freeze) your credit account;
- Tell your members of Congress that the US should have some sort of data privacy law, at least allowing you to opt out, and hopefully making the organizations more accountable for protecting your private information;
- Take out a cybercrime insurance policy, providing reimbursement and help in the event someone uses your information inappropriately;
- Pay closer attention to what sources of news you believe;
- Make sure your kids and grandkids know how many people live in America; and
- Go back to step 1. I don’t think that you have done it yet. I put it first for a reason.
And don’t panic! You are going to be ok.
Leave a comment