National Public; National Public Data 2024 Data Breach

National Public Data Broker Breach (2024): SSN, DOB & Home Address of 134 Million Americans Exposed

Data Broker · Public records aggregation, people search, and background screening data · People-search and background data broker · USA

National Public Data Broker Breach (2024): SSN, DOB & Home Address of 134 Million Americans Exposed

Public-records and background-check data provider.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
62/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
134.0MRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
Gov IDGovernment ID
AddressPhysical address
Classification Tags
USDoDSocial EngineeringData & IdentityData BrokersThird Party2024

Breach Summary

National Public Data, a Florida-based background-check and people-search data broker operating under Jerico Pictures, Inc., suffered one of the largest identity data exposures in U.S. history when a threat actor known as USDoD offered a stolen dataset for sale on the dark web in April 2024. The attacker gained access through social engineering. The initial corpus reportedly contained billions of rows of personal records. Subsequent partial releases included 134 million unique email addresses. The origin and completeness of the data remains disputed, but the scale of the exposure drew widespread attention from security researchers and journalists. The exposed data included Social Security numbers, names, home addresses, phone numbers, dates of birth, email addresses, gender information, and government-issued IDs. Social Security numbers are the most critical element in this exposure. Combined with the other identity fields, the dataset provides everything needed to impersonate an individual, open fraudulent accounts, file false tax returns, or conduct targeted harassment. Because National Public Data aggregated records from public and quasi-public sources, many affected individuals had no prior relationship with the company and were unaware their data was held there. National Public Data filed for bankruptcy in late 2024 following the fallout from the breach. Multiple class action lawsuits were filed on behalf of affected individuals. Regulators and consumer advocates raised concerns about the data broker industry's collection practices, particularly the aggregation of sensitive records without meaningful consent. People whose information was exposed should assume their Social Security number and personal identifiers are in circulation among bad actors and take immediate steps to place a credit freeze with all three major credit bureaus.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

134.0M records analyzed

About National Public; National Public Data

National Public Data is a public-records and background-check data broker that says it provides access to people-finder records, criminal records, contact data, consumer profiles, and related lookup tools sourced from public and quasi-public databases. Its public-facing materials position it as a searchable identity and background information service used for fraud prevention, investigations, and general people-search workflows.

Why They Hold Your Data

People-search and background-data brokers aggregate identity, address, phone, public-record, relative, and screening-related data into searchable consumer profiles.

Recent Developments

National Public Data’s recent public profile has been defined by the fallout from the 2024 breach. Jerico Pictures, Inc., the original operator behind National Public Data, filed for Chapter 11 bankruptcy in October 2024, and the domain is now operated by a different people-search broker that states it has zero affiliation with Jerico Pictures while continuing to use the same nationalpublicdata.com address for a new public-records search business.

Data Points Exposed

8 verified field types
Date of Birth High
Email Address
Full Name
Gender
Government ID Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

The breach impact was severe because the exposed corpus was widely reported as containing Social Security numbers and other core identity elements at national scale. Public reporting described the incident as one of the largest recent identity-data exposures tied to a U.S. data broker, with billions of rows in the leaked corpus, later partial datasets containing 134 million unique email addresses, and broad concern that the records may have covered a very large share of Americans.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
U
Threat Actor: USDoDConfidence: High
Individual alias / data broker-hacker

Motivation: Financial, notoriety
A high-profile hacker persona linked to InfraGard and National Public Data breach claims. Brazilian police reportedly arrested the actor in Operation Data Breach.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation