Part II · Chapter 18
The Profiling Engine
Total control begins with total knowledge: before any campaign runs, it builds a file — and that file has a supply chain that can be traced in both directions.
The premise runs quietly underneath every device examined so far: watch history, search history, financial records, location data, fitness-tracker sleep patterns — none of it is collected for its own sake. It becomes a blueprint. A perpetrator who knows what a target fears, what she’s researching in private, when she’s alone, tired, or afraid, is not guessing at how to control her. He is working from a map.
A fully assembled campaign is worth setting out in one piece — but flagged first, as a composite: built from separately documented components, not any one case observed start to finish. The map follows a fairly consistent logic across the documented and closely-analogous cases. Data collection comes first — watch history revealing which stories a person identifies with, search history what she’s quietly researching (an exit, a lawyer, a diagnosis, a way to leave), communication patterns how she argues and who she confides in, financial records what she can and can’t afford to do, location data her routines and her safe places, biometric data from a fitness tracker her sleep and stress down to the day. From this raw material, a psychological analysis identifies specific vulnerabilities: her core fears, what makes her defensive versus ashamed versus afraid, what she craves, what she’ll sacrifice for her values and what she won’t. A campaign then gets built to exploit those points — a primary narrative tailored to her specific fears rather than generic accusation, secondary narratives reinforcing it from different angles, a sequence of triggers designed, in order, to produce shame, then helplessness, then doubt, then collapse. It runs online and offline at once, through whichever channel carries the most credibility for that vulnerability — an algorithmic feed, a trusted family member, a community member primed on exactly what will land. And it adapts in real time: whatever produces the most visible distress gets escalated, whatever she resists gets varied until something works, timing calibrated to the windows the profiling identified as her weakest.
Several of its components, though, are not synthesis at all. When Harvey Weinstein hired the Israeli private-intelligence firm Black Cube to surveil the journalist Ronan Farrow while he investigated Weinstein’s assault allegations, agents staked out Farrow’s apartment and followed him to his own employers; leaked files later showed Black Cube had built psychological dossiers on Weinstein’s accusers, including Rose McGowan, paired with material specifically intended to undercut their accounts.1 This is precisely the mechanism this chapter describes (professional profiling to discredit specific named women), not composite, not hypothetical but a real operation with named targets and a documented contractor. Its analog-era ancestor runs even further back: after Ralph Nader’s 1965 book Unsafe at Any Speed criticized General Motors’ Corvair, GM hired private investigators to dig into Nader’s personal history, including surveillance and inquiries into his private life, to find material that would discredit him — a campaign serious enough that GM’s own president was compelled to apologize to Nader before a Senate subcommittee.2 And at the largest documented scale, Cambridge Analytica built psychographic personality profiles on more than a hundred million registered American voters using the “Big Five” OCEAN model, sourced through Facebook personality-quiz apps and harvested friend-network data, then delivered individually tailored political advertising built around each profile — voters scoring high on neuroticism, for instance, shown ads emphasizing danger and the need for “strong, stable leaders.”3 Each of these three cases documents one piece of the full pipeline; none covers the whole thing end to end. Held together, they establish that every component of the mechanism is real, even where the complete assembly remains closer to a coherent argument than a single proven case.
The trap this produces for anyone living inside it is the same one this book has named before, in a different key. Describing a coordinated profiling campaign out loud — they know my vulnerabilities, they’re timing this, my own therapist is part of it — sounds, to an untrained listener, like textbook paranoia; the more precisely a person describes the coordination, the more implausible it sounds. And the mechanism this chapter documents is historically proven at state and organized-crime scale, so the individual case sits exactly where this book’s contested zone always sits: real in the aggregate, sounding delusional in the particular, with no proof available in real time because the entire design goal is invisibility until it’s too late for proof to matter.
Part of why the individual case sounds so implausible has a documented psychological explanation older than any of this chapter’s technology. Bertram Forer’s 1948 experiment gave a class of students an identical, deliberately vague personality description assembled from horoscope-style language, then asked each to rate how accurately it described them; the average rating was high, because unspecific language reads as uncannily precise the moment a person does the work of finding themselves in it.4 Stage cold readers exploit the same finding deliberately, offering high-probability, unspecific statements and refining each guess from the target’s own reaction, producing an escalating illusion of impossible insight built from nothing but attentive guessing.5 Real profiling infrastructure has already produced this exact reaction without any cold-reading intent: repeated investigations into the popular belief that phones listen through their microphones to target ads — including a study called “Panoptispy” that monitored network traffic during staged test conversations — found no evidence of audio being captured for advertising, and traced the “impossibly accurate” ads users reported instead to ordinary cross-device and location-based profiling.6 Popular astrology and compatibility apps have been separately reported to harvest precise location and contact data in exchange for delivering exactly the kind of vague-but-personal-feeling content Forer’s experiment explains.7 The connection between these pieces sits at the same synthesis tier as the rest of this chapter’s opening argument: cold reading and profiling are each independently real and documented; a deliberate manipulator combining mined data with cold-reading’s suggestive, vague-sounding delivery — rather than a blunt, obviously personalized statement — is a reasoned construction from real components, not a single proven case of someone doing exactly that.
None of this profiling works without raw material, and the raw material has a supply chain — one legal, one illegal, both feeding the identical downstream use.
The legal side runs through the data-broker industry, almost entirely a matter of settled public record rather than contested interpretation. The FTC’s 2014 study of nine data brokers found one alone held records on 1.4 billion consumer transactions and seven hundred billion data elements; another added three billion new data points a month, gathered from purchase histories, social media activity, warranty registrations, and religious and political affiliation, largely without consumers ever being told. The FTC recommended, over a decade ago, that Congress require a centralized portal letting consumers see what’s held on them. No federal law has ever done this.8 The buyers are not confined to advertisers. ACLU public-records requests revealed that DHS, ICE, and CBP purchased commercial location data for “pattern of life” analysis, bypassing the warrant a court would otherwise require.9 An EFF investigation uncovered Fog Data Science, a broker selling raw location data on more than two hundred fifty million devices through a point-and-click tool called Fog Reveal, with documented customers including state police in Maryland, Indiana, and New Jersey, highway patrol in California and Missouri, the NYPD, Houston PD, and departments as small as Lawrence, Kansas — all for under ten thousand dollars a year, no warrant required.10 The FTC’s 2022 complaint against the broker Kochava, whose geolocation data covered sixty-one million devices, named the risk in its own language: this data could reveal individual visits to reproductive health clinics, places of worship, and domestic-violence shelters, exposing people to “stigma, stalking, discrimination, job loss, and even physical violence.”11 At the far end of this same pipeline sit people-search sites like Spokeo and Whitepages, which aggregate public records into searchable profiles including current and past addresses and named relatives, sold to anyone with no verification of purpose at all.12 A victim who follows the standard advice to go stay with family can still be found, because the same infrastructure that serves federal agencies and state police serves an abusive ex-partner with a credit card, at a lower price and with no institutional customer required.
This is not a hypothetical risk. In 1999, a New Hampshire man named Liam Youens, who had become fixated on a woman named Amy Boyer after she rejected him in high school, paid an information broker called Docusearch forty-five dollars for her Social Security number and a hundred nine dollars for her work address. He obtained the latter when a Docusearch subcontractor placed a pretext call to Boyer herself, falsely claiming to need it to verify her insurance. Youens drove to that address on October 15, 1999, shot Boyer as she left work, and then killed himself. He had spent over two years documenting his stalking and his murder plans on a public website, which Docusearch never checked before selling him her information. Boyer’s family sued, and the New Hampshire Supreme Court’s resulting decision, Remsburg v. Docusearch, held that an information broker owes a duty of care to the person whose data it sells, not only to the customer buying it — an adjudicated case establishing the same mechanism the newer people-search industry now runs at far greater automated scale, and the direct impetus for a 2006 federal law restricting the sale of Social Security numbers.13
A third supply chain, larger than either of the first two, runs through the state’s own collection infrastructure, and unlike most of this book’s state-scale material, this one is not history — the government has never disputed that the underlying legal authority remains in active use. In June 2013, former NSA contractor Edward Snowden — whose own prosecution under the Espionage Act this book examines later — disclosed a program codenamed PRISM, under which the NSA obtained user data — emails, chats, photos, stored files, video calls — from major American technology companies including Google, Microsoft, Yahoo, Facebook, and Apple, compelled under Section 702 of the FISA Amendments Act through directives served on the companies rather than any direct tap of their servers — a “direct access to servers” framing the companies themselves publicly denied.14 A second program, XKeyscore, let analysts search a target’s browsing history, email content, and online chats without prior individualized authorization — leaked training materials described it as capable of capturing nearly everything a typical user does on the internet.15 A third disclosure — a Foreign Intelligence Surveillance Court order compelling Verizon to hand over the phone records of millions of Americans regardless of any suspicion attached to any of them — confirmed a program of bulk telephone metadata collection under Section 215 of the Patriot Act, a program Congress ended in 2015 specifically because the disclosure forced it to confront a scale of collection it had not believed its own legislation authorized.16 None of these three programs required breaking into anything or buying from a broker. They ran on legal authority a legislature had granted, interpreted by a secret court, at a scale no commercial broker in this chapter approaches — the same total-knowledge premise this chapter opened with, run by the actor with the largest budget and the least visibility of all.
The illegal twin of this pipeline runs through data breaches. Have I Been Pwned, the standard public aggregator of disclosed breach data, indexes more than nine hundred breached sites and upward of seventeen billion compromised account records, and in November 2025 alone added a single credential-stuffing list containing nearly two billion unique email addresses and one point three billion unique passwords — evidence that breached data doesn’t stay contained to the site it was stolen from; it gets re-aggregated into new lists built specifically for reuse elsewhere.17 Equifax’s 2017 breach exposed the Social Security numbers, names, addresses, and dates of birth of a hundred forty- seven million people through a vulnerability the company had been warned about and failed to patch for months, settling for up to seven hundred million dollars18 — and this is precisely the identity-verification data that underlies both account-recovery social engineering and SIM swapping, the technique that let an attacker steal roughly twenty-four million dollars in cryptocurrency from Michael Terpin by convincing an AT&T employee to port his phone number to a device the attacker controlled.19 Ashley Madison’s 2015 breach shows the same infrastructure serving a different function entirely: the leaked data was not infrastructure for a further attack but the coercive content itself, triggering extortion campaigns built directly from the leaked personal details, divorces, a chief executive’s resignation, and, according to Toronto police, unconfirmed reports of suicides associated with the leak.20 And because most people reuse passwords across multiple sites — eighty-one percent, by one measure — a breach anywhere supplies working credentials for accounts everywhere else, automated at industrial scale: Akamai recorded an estimated thirty billion credential-stuffing attempts in a single year, and PayPal alone disclosed roughly thirty-five thousand customer accounts compromised this way in a single three-day window.21
The same underlying logic connects every piece here, and how directly it holds depends on which leg you follow. Along one leg, the connection is not even analogy but a single commercial supply chain: the same location records, the same breached credentials, the same aggregated profiles move from a data broker down to a small-town sheriff’s department paying under ten thousand dollars a year and to an individual abuser paying twenty dollars to a people-search site, differing only in who is buying and what they can afford. That much is one literal pipeline, sold down a chain, ending in different hands that all use it the same way. State collection at the top of the scale — the NSA’s own bulk interception, PRISM’s compelled access to the tech platforms and the separate upstream collection that taps the carriers’ backbone directly, rather than buying from a broker — is not that same pipeline; it is built on the same premise, total knowledge as the precondition for control, through its own separate infrastructure. The distinction matters: a shared premise across the scales, a shared pipeline only along the commercial leg. Both are the fractal mechanism this book opened with; only one is literal.
That commercial character is also where the mechanism becomes reachable. Every step this chapter has traced — the broker that sold a location feed, the people-search site that returned an address, the breach that put a password into circulation — is a transaction, and transactions leave records. This is the reversal Remsburg v. Docusearch already established at law: once a broker owes a duty to the person whose data it sold, its own record of who bought what becomes something a court can reach. Have I Been Pwned lets a target see which of her credentials are already circulating and where they leaked from; a subpoena to a data broker or a people-search service can be made to name the buyer. The profiling operation depends on its target never seeing the file assembled against her — and a file assembled by purchase can, in principle, be walked back from the outcome to the hand that paid for it. In practice she has to know it exists before she can pull a single thread, and the whole design is built so that she never does.
Two properties of the profile deserve naming on their own, because they are what let it scale. The first is re-identification, the mosaic effect: data that is individually trivial and formally “anonymous” — a handful of location pings, a purchase history, a pattern of timings — recombines, across enough fragments, into a single named person, so that anonymity turns out not to be a wall that gets breached but an illusion that was never load-bearing to begin with. The second is identity resolution, of which facial recognition is now the sharpest instance: where the rest of this chapter keys on a person already known, facial recognition runs the operation in reverse, resolving an unknown face into a name and collapsing the anonymity of public space itself — the capability Kashmir Hill documented in the rise of Clearview AI, whose scraped-image search she showed resolving strangers’ faces into names, and whose US sales litigation has since restricted largely to government clients.22 A face captured once can, from that name onward, be fed through the rest of this chapter’s pipeline and end in a location and a file. Together the two mean the file need not begin with a name. It can end with one.
Notes
Harvey Weinstein hired Israeli private-intelligence firm Black Cube to surveil journalist Ronan Farrow while Farrow investigated Weinstein’s assault allegations; agents staked out Farrow’s apartment and tailed him to NBC and The New Yorker. Leaked files showed Black Cube built psychological dossiers on Weinstein’s accusers, including Rose McGowan, alongside material meant to undercut their accounts. Ronan Farrow, Catch and Kill: Lies, Spies, and a Conspiracy to Protect Predators (Little, Brown, 2019), his own account; https://www.hollywoodreporter.com/news/general-news/ronan-farrow-details-how-black-cube-spies-tracked-his-weinstein-investigation-1245811/↑
After Ralph Nader’s Unsafe at Any Speed (1965) criticized General Motors’ Corvair, GM hired private investigators to dig into Nader’s personal history — surveilling him and questioning his acquaintances — to find discrediting material; GM’s president was compelled to publicly apologize to Nader before a Senate subcommittee. GM president James Roche’s apology before Senator Abraham Ribicoff’s Senate subcommittee (March 22, 1966) is in the Congressional hearing record; Ralph Nader, Unsafe at Any Speed (Grossman, 1965).↑
Cambridge Analytica built personality profiles it marketed as covering a large share of the US electorate, using the “Big Five” OCEAN model (Openness, Conscientiousness, Extraversion, Agreeableness, Neuroticism), sourced via Facebook personality-quiz apps and harvested friend-network data, delivering individually tailored political advertising — e.g., ads emphasizing danger and “strong, stable leaders” targeted at voters scoring high on neuroticism. https://www.frontiersin.org/journals/communication/articles/10.3389/fcomm.2020.00067/full; https://theconversation.com/psychographics-the-behavioural-analysis-that-helped-cambridge-analytica-know-voters-minds-93675↑
Bertram Forer, “The Fallacy of Personal Validation: A Classroom Demonstration of Gullibility,” Journal of Abnormal and Social Psychology 44 (1949): 118–123 — students rated an identical, deliberately vague personality description as highly accurate for themselves personally, unaware every student received the same text.↑
Cold reading — the documented technique of offering high-probability, unspecific statements and refining subsequent guesses from a target’s own reactions, used by stage psychics and mentalists. Ray Hyman, “‘Cold Reading’: How to Convince Strangers That You Know All About Them,” The Zetetic (Skeptical Inquirer) 1, no. 2 (1977): 18–37.↑
Pan, Elleen, et al., “Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications” (Privacy Enhancing Technologies Symposium, 2018), and related academic and journalistic investigations into the popular belief that smartphones use microphone data to target advertising, which found no evidence of audio being captured or transmitted for that purpose and traced reported “impossibly accurate” ads to ordinary cross-device and location-based profiling instead. https://petsymposium.org/popets/2018/popets-2018-0030.pdf↑
Popular astrology and compatibility apps (e.g., Co-Star) have been reported to request extensive location and contact-list data in exchange for personalized readings. See reporting on astrology-app data practices (e.g., The Outline, 2019) and Co-Star’s own published privacy policy (costarastrology.com/privacy).↑
FTC, “Data Brokers: A Call for Transparency and Accountability” (May 2014), a study of nine data brokers: one broker held data on 1.4 billion consumer transactions and 700 billion data elements; another added 3 billion new data points every month, gathered from purchase histories, social media activity, warranty registrations, and religious/political affiliation, largely without consumers’ knowledge. The FTC recommended a centralized consumer-access portal; no federal law has implemented one. https://www.ftc.gov/system/files/documents/reports/data-brokers-call-transparency-accountability-report-federal-trade-commission-may-2014/140527databrokerreport.pdf↑
ACLU FOIA records showing DHS, ICE, and CBP purchased commercial location data (via vendors including Venntel and Babel Street) explicitly for “pattern of life” analysis, bypassing the warrant requirement.↑
EFF investigation (built on public-records requests to dozens of state/local agencies) documenting Fog Data Science’s “Fog Reveal” tool, selling raw location data on 250 million+ devices, with customer agencies including state police in Maryland, Indiana, and New Jersey, highway patrol in California and Missouri, the Tennessee Bureau of Investigation, NYPD, Houston PD, Broward County (FL) Sheriff, and Lawrence, KS — cost under $10,000/year, no warrant required. https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police; https://www.eff.org/deeplinks/2022/08/fog-revealed-guided-tour-how-cops-can-browse-your-location-data↑
FTC v. Kochava, Inc. (filed Aug. 2022; settled 2026): the FTC’s complaint alleged Kochava’s geolocation data, from 61+ million devices, could reveal visits to reproductive health clinics, places of worship, homeless and domestic-violence shelters, and addiction-recovery facilities, exposing people to “stigma, stalking, discrimination, job loss, and even physical violence.” https://www.ftc.gov/news-events/news/press-releases/2022/08/ftc-sues-kochava-selling-data-tracks-people-reproductive-health-clinics-places-worship-other↑
Spokeo and Whitepages aggregate public records, marketing databases, and social media into searchable profiles — current/past addresses and named relatives — sold to anyone with no verification of purpose. https://www.securityhero.io/is-spokeo-safe/; https://www.lawfaremedia.org/article/people-search-data-brokers-stalking-and-publicly-available-information-carve-outs↑
Liam Youens’s 1999 murder of Amy Boyer, following Docusearch’s $45/$109 sale of her Social Security number and work address, and the resulting Remsburg v. Docusearch, 149 N.H. 148 (2003) — the New Hampshire Supreme Court’s holding that an information broker owes a duty of care to the person whose data it sells.↑
PRISM, disclosed by Edward Snowden in June 2013: NSA access to user data (emails, chats, photos, stored files, video calls) from major US technology companies, compelled via Section 702 directives under the FISA Amendments Act — the “direct access to servers” characterization was publicly denied by the companies. (PRISM compels data from the platforms; the separate NSA “Upstream” program taps the internet backbone with the compelled assistance of carriers such as AT&T and Verizon.) Barton Gellman and Laura Poitras, “U.S., British intelligence mining data from nine U.S. Internet companies in broad secret program,” The Washington Post, June 6, 2013.↑
XKeyscore, disclosed by Snowden in July 2013: an NSA system allowing analysts to search stored browsing history, email content, and online chat records without prior individualized authorization, described in leaked training materials as capable of capturing nearly everything a typical user does online. Glenn Greenwald, “XKeyscore: NSA tool collects ‘nearly everything a user does on the internet,’” The Guardian, July 31, 2013.↑
The FISA Court order compelling Verizon to disclose bulk telephone metadata for millions of American customers, first disclosed by Snowden via The Guardian in June 2013, confirmed a program of bulk collection under Section 215 of the USA PATRIOT Act; Congress ended the NSA’s bulk telephone metadata collection program via the USA FREEDOM Act in 2015. Glenn Greenwald, “NSA collecting phone records of millions of Verizon customers daily,” The Guardian, June 5, 2013; USA FREEDOM Act, Pub. L. 114–23 (2015).↑
Have I Been Pwned (Troy Hunt), the standard public aggregator of disclosed breach data, indexes 900+ breached sites and 17+ billion compromised account records; in November 2025 it added a single credential-stuffing list containing ~1.96 billion unique email addresses and 1.3 billion unique passwords. https://haveibeenpwned.com/About↑
Equifax’s 2017 breach, via an unpatched known vulnerability Equifax had been alerted to months earlier, exposed Social Security numbers, names, addresses, and dates of birth for 147 million people (145.5 million SSNs) plus 209,000 payment card numbers; settled for up to $700M ($575M initial) with the FTC, CFPB, and 48 states plus the District of Columbia and Puerto Rico (Indiana and Massachusetts brought separate actions). https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach↑
Terpin v. AT&T: Michael Terpin was SIM-swapped in 2017 and 2018; an attacker socially engineered an AT&T store employee into porting Terpin’s phone number to a device the attacker controlled, then used SMS-based 2FA codes to steal ~$24 million in cryptocurrency in the second incident. https://hodder.law/terpin-att-crypto-lawsuit/; https://www.courthousenews.com/ninth-circuit-allows-crypto-investor-to-pursue-claim-against-att-over-24-million-hack/↑
Ashley Madison’s 2015 breach: “The Impact Team” stole and published 32 million users’ names, addresses, and account details; documented consequences include extortion campaigns built from the leaked details, divorces, CEO Noel Biderman’s resignation, a $578M lawsuit, and, per Toronto police (August 2015), two unconfirmed suicides that authorities described as “associated with” the breach. https://krebsonsecurity.com/2022/07/a-retrospective-on-the-2015-ashley-madison-breach/↑
81% of users have reused a password across two or more sites (a commonly reported password-reuse estimate); Akamai recorded an estimated 30 billion credential-stuffing attempts in 2018 alone; PayPal disclosed ~35,000 customer accounts accessed via credential stuffing in a single three-day window (Dec. 6–8, 2022). Akamai, State of the Internet / Security (credential-stuffing report, 2019, for the ~30-billion-attempts figure); PayPal’s data-breach notification (January 2023), covering the 34,942 affected accounts.↑
Kashmir Hill, “The Secretive Company That Might End Privacy as We Know It,” New York Times, January 18, 2020, and Hill’s book-length account, Your Face Belongs to Us: A Secretive Startup’s Quest to End Privacy as We Know It (Random House, 2023), documenting Clearview AI’s scraping of billions of face images and its search tool’s use to identify strangers. Under the 2022 settlement of the ACLU’s Illinois Biometric Information Privacy Act suit (ACLU v. Clearview AI, Cook County), Clearview agreed to restrictions that largely confine its US sales to government and law-enforcement clients; the capability — face-to-identity resolution at scale — is what this paragraph describes, not the current commercial availability of any one vendor’s product.↑
From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections