← Case Files · The Breach Files

2024 · Data broker

National Public Data, 2024: a company you never used, holding everything about you

Case file · 4 min read · Published 14 September 2026

People affected
advertised as 2.9 billion rows; researchers identified about 134 million unique email addresses
When it happened
Late 2023 – April 2024
Made public
Offered for sale April 2024; published broadly in August 2024
How they got in
Never fully established publicly; a sister site was separately found publishing a plaintext password file
Attributed to
An actor using the handle USDoD advertised the data; it was later posted free
What it cost
The company filed for bankruptcy protection

What was exposed: Names · Current and historic addresses · Social Security numbers · Phone numbers · Relatives and associates

Every other case in this archive involves a company someone chose to deal with. This one does not. National Public Data was a background-check broker that compiled profiles on people who had never heard of it, never agreed to anything, and had no practical way to leave — and in 2024 the compilation went public.

What happened

In April 2024, an actor using the handle USDoD advertised a dataset said to contain 2.9 billion rows of personal data covering the United States, the United Kingdom and Canada, at an asking price of $3.5 million. Portions circulated through the summer, and in August large parts were published free on a criminal forum.

The records contained names, current and historical addresses, Social Security numbers, phone numbers, and in many cases lists of relatives and associates — the standard shape of a background-check profile.

Why "2.9 billion records" is not "2.9 billion people". Brokers store one row per observed combination of name and address. A person who has lived at eight addresses, used a middle initial sometimes, and shared a household with three others can generate dozens of rows. The file also contained deceased people and obviously stale entries. Researchers who worked through it found roughly 134 million unique email addresses. The gap between the advertised figure and the useful one is the single most important thing to understand about broker breaches.

The company compounded the story: researchers found that a sister site operated by the same business was publishing an archive containing plaintext credentials for its own administrative back end. Whatever the original route in, the operational standard on display did not suggest a well-defended organisation.

The consent problem

The uncomfortable centre of this case is that no one in the file did anything.

Brokers assemble profiles from public records — property filings, voter registrations, court records, licences — combined with marketing data, purchase histories and datasets bought from other brokers. The individual is neither a customer nor a user. They are inventory.

That produces three distinct harms:

  1. No notice. Most people in the file only learned it existed when it leaked.
  2. No control. Opt-out processes, where they exist, are per-broker, manual, and have to be repeated because the data gets re-acquired from other brokers.
  3. No accountability that matches the scale. The company filed for bankruptcy. The data remains in circulation permanently.

It is the argument for regulating the industry, made more persuasively by events than by any advocate.

What the data is actually good for

Being realistic about the risk matters more than being alarmed by the row count.

A Social Security number with a name and date of birth supports new-account fraud, which a credit freeze blocks. Historic addresses and relatives' names support knowledge-based identity verification — the "which of these streets have you lived on?" questions that banks and telecoms still use — which is why those questions have been quietly dying for years.

The most reliable use, though, is targeting. A caller who knows your previous address, your mother's name and the last four digits of your Social Security number sounds exactly like your bank. The data does not enable the fraud directly; it makes the person on the phone credible, and credibility is what the fraud actually needs.

The timeline

  1. Late 2023 – early 2024 — The data is obtained from National Public Data's systems.
  2. April 2024 — A dataset advertised at 2.9 billion rows is offered for sale.
  3. June–July 2024 — Portions circulate; class actions begin; researchers start analysing samples.
  4. August 2024 — Large portions are published free; the company confirms a breach; a sister site is found exposing plaintext credentials.
  5. October 2024 — The parent company files for Chapter 11 bankruptcy protection.

What it changed

Data brokers entered public consciousness. The industry had been a specialist concern. A leak that touched most American adults, from a company none of them could name, made "who else holds my file?" a mainstream question and strengthened the case for state-level deletion mechanisms.

Knowledge-based verification lost more ground. If everyone's address history is public, questions about address history verify nothing. The migration towards document verification, device binding and one-time codes accelerated.

Bankruptcy as a liability exit got noticed. A broker that profits from compiling data, loses it, and then dissolves leaves victims with a permanent exposure and no counterparty. It is now a live question in policy discussions about bonding and insurance requirements for data brokers.

What to actually do

  1. Freeze your credit at all three US bureaus. It is free and it is the control that matches this specific exposure.
  2. Opt out of the larger brokers directly, and repeat it periodically — listings come back as data is re-acquired. How the industry works and where the opt-outs are.
  3. Assume verification questions about you are answerable by strangers. Choose stronger authentication options wherever they are offered.
  4. Discount the headline number, not the risk. The row count was inflated; the Social Security numbers were real.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Were 2.9 billion people affected?

No. That was the advertised row count, not a population — there are only about 8 billion people alive. The file contained enormous duplication, with the same person appearing many times across different addresses and name spellings, plus records of deceased people. Researchers who examined it found roughly 134 million unique email addresses. Treat any headline row count as a file size, not a victim count.

How did they have my data if I never used them?

That is what a data broker is. National Public Data aggregated information from public records, marketing lists and other brokers into background-check profiles. There was no signup, no notice and, in most US states at the time, no way to opt out. You were in the file because you exist, not because you used anything.

Was the data accurate?

Partially. Analyses found stale addresses, mismatched fields and duplicated identities. That cuts both ways: it makes the file less reliable for fraud than the headline suggests, and it means errors in it can still cause harm when a background-check customer treats the profile as fact.

What happened to the company?

Its parent, Jerico Pictures, filed for Chapter 11 bankruptcy protection amid the resulting lawsuits. Separately, researchers found that a sister site operated by the same company had been publishing an archive containing plaintext credentials for its own back end — which did nothing for the argument that the data had been well looked after.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →