Roughly four months after a notorious hacking group claimed to have infiltrated a major data broker and stolen an immense cache of sensitive personal information, a member of the group has reportedly released the majority of the stolen data for free on an online marketplace dedicated to trading in illicit personal data.
The breach, which includes Social Security numbers and other highly sensitive details, poses significant risks of identity theft, fraud, and other criminal activities, according to Teresa Murray, the consumer watchdog director at the U.S. Public Interest Research Group.
“If this really is the full dossier on most of us, it’s far more alarming than previous breaches,” Murray commented in an interview. “And if people weren’t already taking precautions, this should be a serious wake-up call.”
A class-action lawsuit filed in U.S. District Court in Fort Lauderdale, Florida, revealed that in April, the hacking group USDoD claimed to have stolen the personal records of 2.9 billion individuals from National Public Data, a company that provides personal information to employers, private investigators, staffing agencies, and others conducting background checks. The group allegedly attempted to sell the data, which included records from the U.S., Canada, and the U.K., for $3.5 million on a hacker forum, according to a cybersecurity expert who posted about the incident on X.
Bloomberg Law was the first to report on the lawsuit.
Recently, an alleged USDoD member known as Felice announced on the same hacker forum that they were now offering “the full NPD database,” according to a screenshot shared by BleepingComputer. The leaked data is said to contain approximately 2.7 billion records, each including a person’s full name, address, date of birth, Social Security number, phone number, alternate names, and birth dates, Felice claimed.
National Public Data has not responded to requests for comment and has yet to formally notify those affected by the alleged breach. However, in response to inquiries via email, the company stated that it is “aware of certain third-party claims regarding consumer data and is investigating these matters.”
The company also mentioned in its email that it had “purged the entire database, as a whole, of any and all entries, effectively opting everyone out.” As a result, the company claimed to have deleted any “non-public personal information” it held, though it noted that it might be required to retain certain records to comply with legal obligations.
Several cybersecurity news outlets have examined portions of the data offered by Felice and have reported that it appears to contain real individuals’ information. If the leaked data is genuine, the potential risks are significant, and it’s important to take steps to protect yourself.
The Danger of Identity Theft
The leaked data supposedly includes much of the information that banks, insurance companies, and service providers require when creating accounts or resetting passwords.
However, some crucial pieces of information, such as email addresses—which many people use to log into services—and driver’s license or passport photos, appear to be missing from the stolen data.
Still, Murray warned that the leaked information could be used in various ways by criminals, with the most concerning possibility being account takeovers. This could involve everything from bank accounts and investment portfolios to insurance policies and email accounts. With details like your name, Social Security number, date of birth, and mailing address, a fraudster could open new accounts in your name or convince someone to reset the password on one of your existing accounts.
“For someone skilled in this, the possibilities are really endless,” Murray said.
Additionally, criminals could potentially combine the leaked data with information from previous breaches to create even more complete profiles, including email addresses. With that combination, Murray noted, “You can cause all kinds of chaos, commit various crimes, and steal significant amounts of money.”
Steps to Safeguard Yourself
Given how common data breaches have become, some security experts suggest that sensitive information about you is almost certainly already available on the dark web. VPNRanks, a site that rates virtual private network services, estimates that around 5 million people access the dark web daily through the anonymizing TOR browser, although only a portion of them engage in illegal activities.
If you suspect that your Social Security number or other crucial identifying information has been compromised, experts advise freezing your credit files with the three major credit bureaus: Experian, Equifax, and TransUnion. This can be done for free and will prevent criminals from taking out loans, signing up for credit cards, or opening financial accounts in your name. However, remember that you’ll need to temporarily lift the freeze if you are applying for credit or other services that require a credit check.
Freezing your credit can be done online or over the phone with each credit bureau individually. PIRG strongly cautions against responding to unsolicited emails or texts claiming to be from a credit bureau, as these are likely scams designed to steal your personal information.
For more information, PIRG offers a detailed guide on how to freeze your credit.
You might also consider signing up for a service that monitors your accounts and the dark web for signs of identity theft, typically for a fee. Often, the company whose system was breached will offer this service for free for a year or more if your data is compromised.
If you want to check whether your information has been leaked, several websites and service providers, such as Google and Experian, offer tools to scan the dark web. While these services aren’t specific to the National Public Data breach, the cybersecurity company Pentester provides a free tool that allows you to search for your information in the leaked National Public Data files. They also offer links to sites where you can freeze your credit reports.
While these measures can help prevent new accounts from being opened in your name, they don’t offer much protection for your existing accounts. Surprisingly, accounts without online access are particularly vulnerable to identity thieves, as it’s easier for them to create a login and password pretending to be you than to crack an existing login.
To protect yourself, experts recommend using strong, unique passwords for each service and changing them regularly. Password manager apps can simplify this process by securely storing all your passwords in the cloud, requiring you to remember just one master password. These apps are available for free, like Apple’s iCloud Keychain, or for a fee.
In addition to strong passwords, enabling two-factor authentication is crucial. This adds an extra layer of security on top of your login and password, usually involving something sent to your phone, such as a text message. A more secure option is to use an authenticator app, which provides protection even if your phone number is compromised.
To guard against phone number hijacking through SIM swaps or port-out fraud, which can lead to identity theft nightmares, some carriers offer additional protections. AT&T allows customers to set up a passcode to restrict access to their accounts, T-Mobile offers optional protection against unauthorized number transfers, and Verizon automatically blocks SIM swaps by freezing both the new device and the existing one until the account holder confirms the action.
You Might Be Your Own Worst Enemy
More than just relying on hacked data, scammers often trick people into willingly giving up sensitive information. A common tactic is to impersonate a bank, employer, phone company, or another service provider and lure you in with a seemingly urgent text or email message.
Banks, for instance, frequently remind customers that they will never ask for account information over the phone. Despite this, scammers have successfully posed as bank security officers and convinced victims to divulge account numbers, logins, and passwords by claiming they are preventing unauthorized withdrawals or other fictitious threats.
There’s even a risk of receiving official-looking emails supposedly from National Public Data, offering assistance with the reported breach. But as Murray pointed out, “It’s not going to be NPD trying to help—it’s going to be some bad guy overseas trying to con you out of sensitive information.”
As a general rule, never click on a link or call a number provided in an unsolicited text or email. If the message mentions potential fraud and you’re concerned, look up the fraud department’s phone number yourself (you can find it on the back of your debit or credit card) and contact them directly.
“These scammers do this for a living,” Murray said. “They might send out tens of thousands of phishing attempts and only get one response, but that one response could net them $10,000 from an unsuspecting victim. For them, $10,000 in a single day from just one person is an excellent return on investment. That’s what drives them.”



