Nearly 2.7 billion personal records of U.S. residents were leaked on a hacking forum, exposing names, Social Security numbers, physical addresses, and potential aliases.
The data reportedly originates from National Public Data, a company that collects and sells personal data for background checks, obtaining criminal records, and private investigations.
National Public Data allegedly scrapes this information from public sources to create individual profiles for people in the U.S. and other countries.
In April, a threat actor known as USDoD claimed to be selling 2.9 billion records containing personal data of people from the U.S., UK, and Canada, allegedly stolen from National Public Data. USDoD attempted to sell the data for $3.5 million, claiming it contained records for every individual in the three countries. USDoD had previously attempted to sell InfraGard's user database in December 2023 for $50,000.
At that time, BleepingComputer reached out to National Public Data but received no response.
### Recent Developments
Since then, various threat actors have released partial copies of the data. On August 6th, a threat actor named "Fenice" leaked the most complete version of the stolen data for free on the Breached hacking forum, though Fenice attributed the breach to another actor, "SXUL," rather than USDoD.
The leaked data, consisting of two text
files totaling 277GB, contains nearly 2.7 billion plaintext records, down from the 2.9 billion records initially claimed by USDoD. While BleepingComputer cannot confirm if this leak includes data for every U.S. resident, numerous individuals have verified that it includes their and their family members' legitimate information, including data of deceased individuals.
Each record includes a person's name, mailing addresses, and Social Security number, with some records featuring additional information such as associated aliases. None of the data is encrypted.
The breach has led to multiple class-action lawsuits against Jerico Pictures, believed to be doing business as National Public Data, for failing to protect personal data adequately.
If you live in the U.S., it is highly likely that some of your personal information was exposed in this breach. Given the inclusion of millions of Social Security numbers, it is recommended to monitor your credit report for fraudulent activity and report any issues to the credit bureaus. Additionally, due to previously leaked samples containing email addresses and phone numbers, be vigilant against phishing attempts and scam texts.
This data breach highlights the critical need for stringent data protection measures and the potential consequences of inadequate data security. The exposure of such vast amounts of personal information poses significant risks to affected individuals and underscores the importance of monitoring and protecting personal data.

0 Comments