National Public Data Breach | What Happened, Who’s Affected & How to Check Your SSN 

Knowledge Hub
National Public Data Breach

The National Public Data breach was a 2024 cyberattack on background-check company National Public Data (NPD) that exposed roughly 2.9 billion records, including Social Security numbers, names, addresses, and phone numbers for an estimated 272 million people across the US, UK, and Canada.

The breach was first traced to unauthorized access in December 2023, though the stolen data wasn’t offered for sale on hacking forums until April 2024, when a threat actor known as USDoD listed it for $3.5 million. By August 2024, the full dataset, over 277GB of records, had leaked publicly, making it one of the largest exposures of Social Security numbers in US history, with around 272 million unique individuals affected and virtually all US and Canadian SSNs exposed. National Public Data has since confirmed the incident, faced over a dozen class-action lawsuits, and filed for Chapter 11 bankruptcy.

If you’ve searched for your name, email, or SSN and want to know whether you were part of the leak, this guide covers what happened, who’s affected, how to check your own exposure, and the steps to take next.

What Is the National Public Data Breach?

The National Public Data breach is a 2024 cybersecurity incident in which hackers stole and leaked billions of personal records, including Social Security numbers, from the background-check company National Public Data, exposing sensitive data belonging to hundreds of millions of people across the US, UK, and Canada.

Who Is National Public Data (NPD)?

National Public Data is a Florida-based data broker that aggregates public records to power background-check services. Like many data brokers, NPD’s business model relies on compiling large volumes of personal information, names, addresses, phone numbers, and Social Security numbers, pulled from public and semi-public sources, then reselling access to that data for background screening. That business model is precisely what made the breach so severe: NPD wasn’t holding data on its own customers, but on hundreds of millions of everyday people who had no direct relationship with the company at all.

National Public Data

Timeline: When Did the Breach Happen?

National Public Data confirmed that the breach originated from an intrusion attempt beginning in December 2023, with the actual theft of data occurring from April 2024 onward. A hacker using the alias USDoD first advertised the stolen dataset for sale on a hacking forum that April, asking $3.5 million for the trove of 2.9 billion records. The situation escalated over the summer: by early August 2024, a second actor released a partial dataset publicly, and within days, a more complete version, roughly 277GB and covering billions of rows, was posted in full on a hacking forum, making the data freely accessible rather than sold privately.

Is the National Public Data Breach Real?

Yes, the breach is confirmed, not a hoax or rumor. National Public Data itself acknowledged the incident and filed an official breach notification confirming that 2.9 billion records were obtained. The company has faced legal consequences as a result: at least three class-action lawsuits and over a dozen federal complaints were filed against NPD within weeks of the disclosure. The scale of the confirmed damage was severe enough that the company later filed for Chapter 11 bankruptcy, underscoring that this was a real, verified security failure rather than speculation.

What Caused the Breach

The National Public Data breach was caused by hackers gaining unauthorized access to NPD’s systems in late 2023 and quietly extracting billions of records months before the theft became public, exploiting the company’s role as a data aggregator with minimal external scrutiny of its security practices.

National Public Data breach was caused by hackers gaining unauthorized

How Hackers Accessed NPD’s Systems

National Public Data confirmed that an unknown party began attempting to breach its systems in December 2023, with actual data theft occurring in April 2024 and continuing over the following months. The company has publicly disclosed the exact technical method NPD used to gain entry. Still, the pattern matches a common weakness among data brokers: they hold enormous volumes of sensitive information while investing comparatively little in the security infrastructure typically required of financial institutions or healthcare providers. Once inside, the attacker, operating under the alias USDoD, was able to extract the company’s core database largely undetected, a failure that let the intrusion go unnoticed for months before NPD became aware of it.

What Was Leaked on the Dark Web / Torrents

The stolen data didn’t stay in one hacker’s hands for long. In April 2024, USDoD first listed the dataset for sale on a hacking forum for $3.5 million, but by summer the data had spread far beyond a single buyer. A hacker known as Petrovic released an initial 80GB partial file, and by early August a second actor, Fenice, published the complete dataset publicly, a 277GB file containing roughly 2.69 billion lines of data. Once posted on hacking forums, the file was rapidly mirrored and shared through torrents, meaning the information was no longer confined to a single leak site but freely downloadable by anyone, which is what transformed a private theft into a mass public exposure.

Who Was Affected

The National Public Data breach affected an estimated 272 million people across the US, UK, and Canada, exposing highly sensitive personal information including Social Security numbers, names, and addresses. However, the exact number of victims has been disputed as investigators and NPD itself have released conflicting figures.

National Public Data breach affected an estimated 272 million people across the US, UK, and Canada

How Many People Were Impacted

Estimates of the breach’s scope have shifted significantly since it first came to light. Early reporting, based on the leaked 2.9 billion-record dataset, suggested the incident could touch nearly every US and Canadian Social Security number in circulation, with around 272 million unique individuals affected. That figure includes a large share of duplicate entries and deceased individuals, since NPD’s database spanned decades of public records rather than a single current customer list. Notably, National Public Data’s own official filing with the Maine Attorney General’s Office later stated that “just” 1.3 million people were confirmed affected, a dramatic gap from the earlier estimates that reflects how difficult it has been to verify the true scale of a leak this large. Because of this discrepancy, most security researchers treat the higher figure as the realistic worst-case exposure and the lower figure as NPD’s confirmed, verified minimum.

What Personal Data Was Exposed (SSNs, Addresses, etc.)

The exposed dataset was unusually complete compared to most breaches, which is part of what made it so dangerous. The compromised information included Social Security numbers, full names, email addresses, phone numbers, and mailing addresses, and in many records, current and previous addresses were both present, giving identity thieves a detailed profile rather than a single isolated data point. Some versions of the leaked files also included dates of birth and family relationship details, such as the names of parents and siblings, which can be used to bypass identity-verification questions that rely on personal history. Because Social Security numbers rarely change, this category of exposure carries long-term risk: unlike a leaked password, an exposed SSN can’t simply be reset.

How to Check If You Were Affected

You can check whether you were affected by the National Public Data breach using free lookup tools that scan leaked databases for your email address or personal details, without needing to download the raw leaked data yourself.

How to Check If You Were Affected

Free National Public Data Breach Lookup Tools

The simplest way to check your exposure is through a dedicated scanner rather than searching the leaked files directly. DeXpose’s Free Dark Web Report checks your details against known dark web markets, malware logs, and public breach dumps, including data tied to the National Public Data incident, and returns an instant exposure summary. If you specifically want to check an email address, the Email Data Breach Scan cross-references it against breach databases to confirm whether it surfaced in this leak or any other known incident. Other established breach-lookup services, such as Have I Been Pwned, also index parts of the NPD dataset and can be used as a secondary check.

How to Search the Leaked Database Safely

Searching for your information safely means using a tool that queries the data on your behalf rather than downloading the leaked files yourself. The raw National Public Data breach dataset, a 277GB file containing roughly 2.69 billion lines of records, circulates on hacking forums and torrent trackers, and downloading it directly exposes you to malware, legal risk, and the mishandling of other victims’ sensitive data. A breach-lookup tool avoids all of that: you submit only your own email or identifying details, and the tool checks them against an indexed, sanitized copy of the leak rather than handing you the full file. This is the same reason security professionals recommend against manually searching torrents even out of curiosity; the risk to your own device and the legal exposure of possessing stolen PII outweigh any benefit.

What to Do If You’re Affected

If you were affected by the National Public Data breach, the most urgent steps are freezing your credit, actively monitoring for signs of identity theft, and reporting any fraud immediately, since exposed Social Security numbers can be used to open accounts in your name long after the initial leak.

What to Do If You're Affected

Freeze Your Credit

A credit freeze is the single most effective protection against the exposed data, because it blocks lenders from accessing your credit report at all, meaning no one can open a new loan, credit card, or line of credit in your name, even with your SSN in hand. Freezing your credit is free and must be done separately with each of the three major bureaus: Equifax, Experian, and TransUnion. Unlike a fraud alert, a freeze doesn’t expire after a set period and stays in place until you actively lift it, which makes it a stronger long-term safeguard given that a leaked SSN can’t be changed or reissued the way a password can.

Monitor for Identity Theft

Beyond freezing your credit, ongoing monitoring helps you catch fraud that a freeze alone won’t stop, such as misuse of your existing accounts or attempts to file fraudulent tax returns or unemployment claims in your name. Check your bank and credit card statements regularly for unfamiliar charges, and pull your free credit reports from each bureau to look for accounts you don’t recognize. Because the National Public Data leak included addresses and dates of birth alongside SSNs, it also gave attackers enough detail to pass basic identity-verification questions, so it’s worth watching for signs like unexpected mail from unfamiliar creditors or a sudden drop in your credit score with no clear cause.

Report Fraud If It Occurs

If you do find evidence of fraud, report it immediately rather than waiting to see if it resolves on its own. File a report with the FTC at IdentityTheft.gov, which generates a personalized recovery plan and an official identity theft report you can use when disputing fraudulent accounts. You should also contact the affected bank or creditor directly to flag the fraudulent activity, and consider filing a police report if the fraud involves significant financial loss; some banks and creditors require one before they’ll reverse unauthorized charges.

Can You Sue National Public Data?

Multiple lawsuits have already been filed against National Public Data. Still, as of 2026, there is no approved settlement and no legitimate claim form, meaning affected individuals cannot currently file for compensation, despite what some third-party websites may claim.

Class Action Lawsuit Status

The National Public Data breach spawned roughly 20 class action lawsuits, consolidated in the Southern District of Florida against Jerico Pictures, Inc., the legal entity operating as National Public Data. These complaints allege the company failed to secure the personal data it collected, though it’s worth noting the allegations remain legally unproven; NPD has not been found liable in court. The case became significantly more complicated when the company filed for Chapter 11 bankruptcy protection in October 2024; that filing was later dismissed, but the litigation continues to move through the courts alongside questions about whether NPD has any meaningful assets left to pay a judgment.

Class Action Lawsuit Status

Eligibility and Settlement Details

Here’s the part many searchers get wrong: no approved settlement currently exists for the National Public Data breach, and there is no official claim form to submit. Court filings show the company holds only around $44,000 in assets, a figure that makes a meaningful payout to the hundreds of millions of potentially affected individuals highly unlikely even if a settlement is eventually reached. Because this case has generated so much attention, several third-party sites have appeared promising fast payouts or requesting personal information to “process” a claim; these are not connected to any court-approved settlement, and providing your data to them risks exposing you to a second identity theft attempt on top of the original breach. The most reliable move right now is to monitor official channels, such as updates from the consolidated federal case or your state Attorney General’s office, rather than filing anything through an unverified third-party site.

Latest Updates & News Coverage

Investigative reporting on the National Public Data breach has continued well past the initial 2024 disclosure, with security journalist Brian Krebs uncovering additional failures at the company and NPD itself issuing a formal statement confirming the incident.

Krebs on Security & Investigative Reporting

Brian Krebs, the security researcher behind KrebsOnSecurity, broke much of the reporting that turned NPD from an obscure data broker into a national story. Krebs first revealed that a great many readers had received alerts that their Social Security number, name, address, and other personal information were exposed in the breach, prompting his outlet to dig into how a little-known background-check company had ended up holding such a vast trove of consumer data. His investigation didn’t stop at the initial leak: Krebs later discovered that a related NPD data broker had inadvertently published the passwords to its own back-end database in a file freely downloadable from its homepage, a second failure that compounded the original breach. A follow-up investigation also found a near-identical NPD-affiliated site, RecordsCheck.net, hosting an archive with plaintext logins and source code for the company’s internal tools, evidence that the security gaps extended well beyond a single system.

Official Statements From National Public Data

National Public Data confirmed the breach publicly on August 12, 2024, roughly a month after the leaked data began circulating. In its statement, the company said the incident “appears to have involved a third-party bad actor that was trying to hack into data in late December 2023, with potential leaks of certain data in April 2024 and summer 2024.” It confirmed that the exposed information included names, email addresses, phone numbers, Social Security numbers, and mailing addresses. NPD said it had cooperated with law enforcement and implemented additional security measures to prevent a repeat incident, though it offered no technical explanation for how the intrusion originally occurred. The company has since stopped selling personal information through its services, though that offers little comfort to those whose data is now permanently circulating on the dark web.

Frequently Asked Questions (FAQ’s)

Was there a national public data breach?

Yes. National Public Data confirmed on August 12, 2024, that hackers accessed its systems starting in December 2023, exposing billions of records including Social Security numbers.

How do I know if my SSN was leaked?

Use a free breach-lookup tool like DeXpose’s Dark Web Report to check your email or details against the leaked NPD dataset instantly.

Is National Public Data legit?

It was a real, operating background-check company, but its legitimacy is now in question after the breach and its subsequent Chapter 11 bankruptcy filing.

How many people were affected?

Estimates range from around 272 million people based on the leaked dataset to just 1.3 million confirmed in NPD’s official filing; the gap remains unresolved.

What should I do right now?

Freeze your credit with all three bureaus, monitor your accounts closely, and report any fraud to the FTC at IdentityTheft.gov.

Free Dark Web Report

Keep reading

No results found.