In one of the most significant data breaches ever recorded, the personal information of approximately 3 billion people has been compromised from National Public Data, a company specializing in background checks and fraud prevention.
This breach, which emerged following a class action lawsuit in Florida, has sent shockwaves through the cybersecurity field, igniting intense discussions about the state of data privacy and security. The stolen information encompasses extremely sensitive details, including full names, addresses from the past 30 years, Social Security Numbers, and family member information.
What makes this breach particularly troubling is that many of the affected individuals were likely unaware that National Public Data even possessed their information. Reports indicate that the company may have collected personally identifiable information (PII) from non-public sources without proper consent.
According to the lawsuit, a hacker group managed to infiltrate National Public Data’s systems and exfiltrate the extensive database. The stolen data was then reportedly put up for sale on the dark web for $3.5 million.
The court documents, shared by Bloomberg, detail how a hacker group operating under the alias “USDoD” listed a massive database for sale on a site called Breached, claiming it contained 2.9 billion records of U.S. citizens. The asking price for the data was set at $3,500,000.
The enormity of this breach is unprecedented, potentially impacting nearly 40% of the global population and rivaling the notorious Yahoo breach of 2013, which affected 3 billion accounts.
Christopher Hofmann, the lead plaintiff in the lawsuit, uncovered the breach through a notification from his identity theft protection service. The lawsuit alleges that National Public Data neglected to enforce sufficient security measures to safeguard the sensitive information it collected.
This incident underscores the critical flaws in data collection practices and the dangers of large-scale data aggregation. It highlights the urgent need for stringent cybersecurity protocols and clear data handling practices.
Experts recommend that those affected stay vigilant, closely monitor their financial accounts, and consider enrolling in identity theft protection services. As the investigation progresses, National Public Data could face severe legal and financial repercussions, along with a significant erosion of public trust.



