ICE Is Buying Your Credit Card Application. The Broker Layer Is the Real Story.
ICE Is Buying Your Credit Card Application. The Broker Layer Is the Real Story.
Bruce Schneier's August Crypto-Gram had one line in it I can't stop thinking about:
"Through data brokers, ICE is buying the information you provided to open a credit card."
That's from the August 15, 2026 issue, and it's a short item — a paragraph, really. But if you work anywhere near enterprise privacy, it should ruin your weekend.
Think about what actually gets handed over when someone applies for a credit card. Legal name, date of birth, current address and every prior address the underwriter cares about, employer, income, phone, email, some fragment of the SSN, and — depending on the product — the household members you added as authorized users. That's not marketing exhaust. That's the file a fraud investigator would build if they were trying to impersonate you.
And according to the reporting Schneier is citing, ICE is buying it. Not subpoenaing the issuer. Not asking a judge. Buying it, from a broker, the same way a marketing team would buy a lookalike audience.
We've spent a lot of time at Priwall arguing that the data-broker layer is an attack surface. Usually we're talking about criminal actors — the phishing crews, the swatting kids, the identity-theft rings. Schneier's own August issue has a first-person identity theft piece a few sections later where the punchline is that most account security ultimately rests on the security of the associated email, and the pretexting that gets you to the email always, always starts with a broker profile.
Same fuel. Different attacker.
The reason the ICE story matters more than another rogue-cop-with-a-Clearview headline is that it collapses a distinction the law has been leaning on for forty years. The third-party doctrine says you don't have a reasonable expectation of privacy in records you voluntarily handed to a bank. Fine. That was arguably defensible when "the bank" meant a specific institution that would receive a specific subpoena from a specific prosecutor. It's a different thing entirely when the bank's underwriting file has been resold to a data aggregator and the aggregator's price list is open to any federal customer with a purchase order. That's not the third-party doctrine anymore. That's a warrantless commercial channel that happens to route around the Fourth Amendment. The Supreme Court gestured at this problem in Carpenter, and the Chatrie geofence line is chewing on the same bone right now.
Here's the part that should get regulators' attention. In the same Crypto-Gram, Schneier endorses Daniel Solove's argument in the Wall Street Journal that individual notice-and-consent as a privacy strategy is finished. Solove wants data minimization, fiduciary duties, and liability — the food-and-drug model, not the click-through model. And the ICE credit-card story is exactly why he's right. Nobody clicked a consent box that said "I agree that ICE may purchase this application from a broker in 2026." Nobody would. Notice-and-choice can't govern a market where the buyers are trade secrets and the resale happens years after the original disclosure.
So what do you do about it if you're the person responsible for privacy at a real company, right now, in August 2026?
You stop waiting for federal law. You shrink the record.
Assume every one of your employees' credit applications is already sitting in a broker's file. It is. Treat that as a workforce security problem, not a personal-life nicety somebody handles on their own time. Move to authorized-agent removal at the workforce level — individual opt-outs don't scale, and the consumer-grade removal services don't sustain removal against re-population. Instrument the re-population, because brokers re-list; the number that matters is the day-90 curve, not the number of envelopes you mailed in month one. And extend the coverage to household members, because the credit application record includes co-applicants and authorized users and your executive protection scope is nonsense if it stops at the executive.
None of that fixes the policy problem. The policy problem is going to take a decade. But the operational problem — the specific fact that a federal enforcement agency can currently buy your employees' credit-card paperwork from a commercial broker — is solvable this quarter. You just have to decide it's yours to solve.
If you want to see what's currently sitting in the broker layer on your executive team, we'll run a coverage report. That's what priwall.io does.
Sources:
Bruce Schneier, "ICE Is Buying Access to Credit Card Records," Crypto-Gram, August 15, 2026.
Bruce Schneier, "Protecting Privacy in an AI Era," Crypto-Gram, August 15, 2026, summarizing Daniel Solove in the Wall Street Journal.
Bruce Schneier, "First-Person Identity Theft Story," Crypto-Gram, August 15, 2026.
Ready to try Priwall by mePrism yourself?
If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.
Sign up for Priwall by mePrism coverage.Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across 700+ U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.