In early April 2024, a massive data leak from National Public Data resulted in the personal information of billions of people being exposed on the dark web. Despite the severity of the breach, many affected individuals remain unaware, as the company has yet to notify them.
One victim recently initiated a class action lawsuit after being alerted to the breach by an identity theft protection service. This raises significant concerns for others whose data may have been unknowingly sold on the dark web.
National Public Data, a Florida-based background check firm owned by Jerico Pictures, Inc., collects data without the explicit consent of the individuals in its database. The lawsuit, filed by Christopher Hofmann, alleges that the cybercriminal group USDoD released a database containing the personal details of 2.9 billion U.S. citizens on the dark web. This data included full names, social security numbers, addresses, and even information about family members, some of whom had been deceased for decades. The database, spanning 277.1GB, was reportedly offered for sale at $3.5 million. VX-Underground, a cybersecurity-focused educational site, confirmed the authenticity of the information. Since National Public Data is not subject to CIRCIA’s 72-hour breach reporting requirements, it did not report the breach promptly.
The lawsuit accuses the company of negligence in failing to protect sensitive data, leading to its publication and sale on the dark web. The ongoing risk to victims is expected to last for their lifetimes. Notably, National Public Data has not issued a public statement about the breach. The Los Angeles Times reported that the company acknowledged awareness of third-party claims and is investigating but has not provided further details. The lawsuit highlights the company’s failure to notify those affected as a significant issue.
Hofmann’s lawsuit seeks monetary compensation and demands that National Public Data purge the compromised information, implement encryption, segment data, scan its databases, launch a threat management program, and undergo annual cybersecurity evaluations until 2034.
This breach is shaping up to be one of the largest in history, potentially second only to the 2013 Yahoo breach, which involved 3 billion accounts. The scale of the National Public Data breach could push other significant breaches down the rankings, such as the 2017 River City Media breach (1.37 billion records) and the 2018 Aadhaar breach (1.1 billion records).
As legal proceedings unfold, comparisons are being drawn to past cases, such as Yahoo’s 2019 settlement rejection by U.S. District Judge Lucy Koh, who cited inadequate disclosure and improper handling of claims. Consumers are urged to stay vigilant, monitor their credit reports, and be cautious of unsolicited account requests. Teresa Murray, Consumer Watchdog Director for the U.S. Public Information Research Group, warned that this breach could be more alarming than previous incidents and should serve as a wake-up call for increased vigilance.
For assistance with cybersecurity, including incident response and threat intelligence, IBM X-Force is available to help.



