Today, I received my 47th data breach notification letter. At this point, it's like getting a postcard from an old friend. Here's how it read:
NOTICE OF DATA BREACH
Dear Valued Customer,
We are writing to inform you of a recent security incident at the Department of the Treasury. This notification is sent pursuant to the Federal Information Security Modernization Act (FISMA).
What Happened?
On January 31, 2025, DOGE operatives gained access to the federal payment system, allowing them to monitor and control financial transactions.
What Information Was Involved?
The information involved may include your name, Social Security number, date of birth, and other personal details.
What We Are Doing
While our systems remain insecure, we are pleased to offer you a complimentary one-year subscription to X Credit Monitoring Service. We also encourage you to take comfort in the knowledge that this breach affects millions, ensuring a shared experience of compromised security.
What You Can Do
Not a damn thing.
We apologize for any inconvenience this may cause.
Sincerely,
Scott Bessent
Secretary of the Treasury
So it turns out that Elon Musk’s grand experiment with the Department of Government Efficiency (DOGE) isn’t just about firing bureaucrats and setting up meme stock portfolios. His people have reportedly locked government workers out of their own computer systems, installed unauthorized hardware, and rewritten software that handles everything from federal payments to citizen records. You’d think this would be a scandal. You’d think there would be bipartisan outrage, emergency hearings, possibly even some protest signs.
Instead, we got… nothing.
The few journalists still employed sounded the alarm, but the American public collectively shrugged and went back to doomscrolling. Maybe they were busy watching Tesla stock implode. Maybe they just assumed their data was already in Musk’s hands. After all, wasn’t it?
Shut up and take my privacy!
If you’re old enough to remember a world before the internet, you might recall a time when privacy mattered. There was a whole cultural debate about the Patriot Act and government surveillance. People were upset about data mining, warrantless wiretapping, and corporate tracking.
That didn’t last.
By the early 2010s, we had collectively sold our personal data for the privilege of sharing cat pictures and harvesting digital crops in Farmville. Facebook, Google, Twitter (remember Twitter?)—these companies didn’t just offer free services. They offered convenience, entertainment, a sense of connection. And in exchange, we handed over everything.
Where we lived. What we bought. Who we talked to. What we liked.
But social media was just the opening act. The real show was surveillance capitalism—a business model where companies don’t just collect data for their own use; they collect it to sell, refine, and weaponize. The moment corporations realized that your personal information was more valuable than your business, privacy as a concept started circling the drain.
And while most people understand that Google and Meta track their every move, FinTech has been blowing up in the background, quietly embedding itself into every financial transaction you make. Your mortgage, your credit card transactions, your medical bills—your financial data doesn’t just pass between you and the bank anymore. It travels through an expanding ecosystem of third-party processors, data brokers, and AI-driven risk assessment firms you’ve never heard of.
Think you’re just giving your insurance company your medical history? That data is being processed by subcontractors, shared with analytics firms, and possibly sold to hedge funds betting on long-term healthcare trends. Every time you tap your phone to pay for groceries or set up autopay for your rent, that transaction isn’t just between you and your bank—it’s passing through a web of intermediaries, each scraping off a little data for their own purposes.
But hey, I write less than a half dozen paper checks a year and I can meet most of my basic needs—even the ones I didn’t know I had until the ad placement algorithms figured me out—without leaving my house.
Then came the breaches.
That’s a real nice identity. It’d be a shame if someone were to… steal it.
At some point, getting a letter informing you that your personal data had been compromised became as routine as getting junk mail. Between 2020 and 2024 alone, data breaches exposed billions of records. In 2022, the US saw 1,802 breaches, compromising 422 million records. (source) The year before, it was 1,862 breaches and 298 million records. The numbers go up, the numbers go down, but the trend stays the same: data breaches happen, and nobody does a damn thing about it.
For the average American, the response to these breaches is a resigned sigh and a free year of credit monitoring.
But how many breaches is that per person? Let’s do some back-of-the-envelope math.
The total US population is about 330 million. Over four years, the number of breached records has exceeded one billion. Assuming some overlap (because let’s be real, it’s the same people getting screwed over and over again), we can conservatively estimate that each American has had their data compromised at least four to five times in the last four years.
And each breach notification comes with—what else?—a year of free credit monitoring.
Which means, in theory, every American should now have at least four to five years of free identity theft protection lined up.
Now, I hate to be the bearer of bad news, but identity theft protection isn’t real protection. It’s more like hiring a security guard who only tells you after your house has been robbed. The entire industry is a brilliantly executed scam. They offer you a “free” year of monitoring, which is really just an introductory offer. The moment it expires, they start charging you $15–$30 a month, because who wants to cancel security?
Companies like LifeLock, Norton, and Experian rake in billions annually by monetizing the fear of identity theft. (source) And why not? They don’t even have to create the problem they solve—cybercriminals do it for them!
And if you think about it, this is capitalism at its most elegant:
Corporations fail to protect your data.
Your information gets stolen.
Other corporations charge you money to watch your stolen information float around the dark web.
Those same corporations hope you forget to cancel their service.
This raises an interesting question: does identity theft even matter anymore?
Tag, you’re it. No tap-backs!
In the early days of credit cards, when processing a transaction required a hefty ka-chunk of a manual imprinter, the burden of fraud fell squarely on the individual. If your card was lost or stolen, you were often liable for unauthorized charges until you reported the loss. Companies had little incentive to invest in fraud prevention; the costs were externalized, borne by the consumer.
However, as credit card usage soared and fraud became more prevalent, the dynamics shifted. Legislation like the Fair Credit Billing Act of 1974 limited consumer liability for unauthorized charges to $50, transferring the financial risk to credit card issuers. This change, coupled with technological advancements, prompted companies to develop sophisticated fraud detection systems—not out of altruism, but to protect their bottom line.
Over time, credit card fraud has become a zero-cost risk for individuals, provided they promptly report unauthorized transactions and avoid using debit cards linked directly to their bank accounts. The financial institutions now absorb the costs, incentivizing them to continually enhance their security measures.
Identity theft, however, is a more recent phenomenon. Initially, the repercussions fell heavily on individuals, who faced the arduous task of clearing their names and restoring their credit. The credit bureaus and financial institutions had little motivation to address the issue, as the costs were externalized.
The surge in data breaches and ensuing public outcry led to consumer protection regulations, such as the Fair and Accurate Credit Transactions Act (FACTA) of 2003. FACTA requires financial institutions to develop and implement written identity theft prevention programs, shifting some responsibility back to corporations.
Recognizing a lucrative opportunity, the market responded with the emergence of the identity protection and credit monitoring industry. Companies now offer services to help consumers detect and prevent identity theft—essentially monetizing a problem that, in part, resulted from corporate negligence. It's a classic case of creating a solution and then selling it to those affected, turning a crisis into a profitable enterprise.
In this way, the costs associated with identity theft have been redistributed. Corporations invest in prevention programs to comply with regulations and protect their reputations, while consumers are encouraged to pay for monitoring services to safeguard their personal information. The market has adeptly transformed a liability into a revenue stream, ensuring that, in the end, everyone pays—one way or another.
Markets never miss an opportunity to make money out of problems they created. This one’s especially elegant because the solution is indistinguishable from the scam.
Not with a bang but a whimper.
And so, we arrive at the present. Musk’s team has allegedly installed hardware in government offices, rewritten software that processes payments, and taken control of critical government IT infrastructure. Some experts say this violates protocols, if not the law. The government appears to be scrambling for control.
But the public? Silent. Why would anyone care? We’ve already been conditioned to accept the inevitable:
Your data will be stolen.
Nobody will stop it.
You will get a letter in the mail.
You will do nothing.
This is where we are now: citizens no longer expect privacy, no longer expect security, no longer even expect accountability.
Because what difference does it make? If Tesla can build its own cell network, if SpaceX controls satellite internet, if Musk has access to payment systems and sensitive government databases, then it’s already too late.
So here we stand, at yet another crossroads. Option 1: People wake up and demand better protections. Congress passes sweeping regulations. Companies are forced to actually secure personal data. Breaches become rare. People regain control over their information. Option 2: Nothing happens. Data breaches continue. Governments hand over infrastructure to private billionaires. Identity theft protection companies make record profits. The public shrugs.
Be honest—which seems more likely? Spoiler alert: You don’t get a government that protects the common person by voting for anti-government candidates plastered with more corporate logos than a NASCAR ride.
When historians look back at this era, they might wonder how we let billionaires take control of our government infrastructure. They might be confused about why nobody fought back. But the truth is simple: we’ve been conditioned to accept it.
Musk’s government takeover is just another breach in a long series of breaches. And if nobody cared when their Social Security number got leaked the first six times, why would they care now?
Turns out the price of privacy isn’t vigilance. It’s indifference.
Creative Process Transparency: This article was collaboratively written using generative AI. The core framing, themes, and arguments were developed by me, while ChatGPT assisted in drafting, expansion, and structural refinements. The final narrative, humor, and rhetorical sharpness were fine-tuned by me. Based on our established attribution model, this article reflects an approximately 75/25 division of contributions. You can read the whole transcript here.



Wow. Conditioning works, not just a psychological theory. Where is Pavlov’s dog today?