Team Cymru (the company the article is about) has a response to the coverage:
https://www.team-cymru.com/post/team-cymru-myth-vs-factIn short, they claim that:
- The "PCAP" data, email addresses, etc that they sell comes from them running malware samples on their own infrastructure. It's not based on captured Internet data.
- The web page addresses etc that they sell are the results of automated vulnerability scans and honeypots, not captured Internet data.
- The netflow data they sell is captured from real ISP traffic, but it is a small sample (only 1 in 10,000 netflows is captured), and it can't identify individual websites if they use a CDN or shared hosting infrastructure (which most websites do).
I have no clue how true these claims are, but those are the claims.