Why a 2024 data broker breach still matters to your organization, your staff, and the people you serve.

Most data breaches have a shelf life. A password gets stolen, you change it, and the stolen copy becomes worthless. A credit card number leaks, the bank reissues the card, and the fraudster is left holding sixteen useless digits.

The National Public Data (NPD) breach is not that kind of breach.

The information exposed in this incident — Social Security numbers, dates of birth, decades of address history — cannot be reset, reissued, or rotated. It is permanent. That is why we are still writing about a 2024 incident in 2026, and why we still bring it up in client security reviews. The data is out, it is free, and criminals are still working through it.

What National Public Data was

National Public Data was a background-check and people-search service operated by a Florida company called Jerico Pictures, Inc. It was a data broker: it compiled personal records scraped from public records and purchased from other data aggregators, then resold access to employers, landlords, and anyone else running background checks.

The critical detail for most people reading this: you never signed up for it. You had no account, no terms of service, and no opportunity to opt out. NPD collected and monetized your information without your knowledge, and then failed to protect it.

What happened

The timeline, as it has been pieced together from company statements, court filings, and congressional inquiry:

  • December 2023 — A threat actor gained unauthorized access to NPD’s systems.
  • April 2024 — An actor using the handle “USDoD” listed the stolen database for sale on a criminal forum for $3.5 million.
  • Summer 2024 — Portions of the data began circulating, then the full archive — roughly 277 GB — was posted publicly and mirrored via torrents. At that point it stopped being a commodity sold to a handful of criminals and became a free download available to anyone.
  • August 2024 — NPD publicly acknowledged the breach, months after the data was already in circulation.
  • October 2024 — Facing roughly twenty class-action lawsuits, Jerico Pictures filed for Chapter 11 bankruptcy protection.

A separate failure compounded the damage: a sister site operated by the same company, recordscheck.net, left an archive on its own homepage containing plaintext usernames and passwords for the back end of the site. The company that was supposed to be safeguarding hundreds of millions of Social Security numbers was publishing its own credentials.

What data was made available to fraudsters

Reported figures vary, and some of the headline numbers are inflated by duplicate records — the widely cited “2.9 billion records” is a count of rows, not people. Independent analyses put the number of unique individuals at roughly 270 million across the United States, United Kingdom, and Canada. In practical terms, if you are an adult in the U.S., you should assume you are in it.

The exposed fields include:

  • Full names, including maiden names, aliases, and name variants
  • Social Security numbers, stored without encryption
  • Dates of birth
  • Current and historical mailing addresses, in many cases going back thirty years or more
  • Telephone numbers
  • Relatives and known associates, linking family members and household members to one another
  • Email addresses, in certain related and partial datasets that surfaced alongside the main corpus

That last category — the relational data — is the part that gets underestimated. A criminal does not just get your SSN. They get your mother’s maiden name, your previous street addresses, your sibling’s phone number, and the name of the town you lived in when you were nineteen. Those are exactly the “security questions” that banks, carriers, and help desks have used for decades to prove you are who you say you are.

How criminals actually use this data

New account fraud. Name, SSN, date of birth, and address history is the complete package required to open a credit card, take out a personal loan, apply for a mortgage, or open a bank account in someone else’s name.

Defeating knowledge-based authentication. When a caller can recite your prior address, your birthdate, and the last four of your SSN, the traditional phone verification script collapses. This drives SIM-swap attacks, account takeovers at banks and brokerages, and fraudulent password resets.

Tax refund fraud. A criminal files a return in your name early in the filing season and collects the refund. The victim usually finds out when their own legitimate return is rejected as a duplicate.

Employment and synthetic identity fraud. A stolen SSN gets used to obtain employment, generating wage records the real owner never earned and IRS notices they cannot explain. Fraudsters also blend a real SSN with a fabricated name and birthdate to create a “synthetic” identity that builds its own credit history.

High-credibility phishing and vishing. This is the piece that hits organizations hardest. A phishing email or phone call that references your actual home address, your actual employer, and the last four digits of your actual SSN is dramatically more convincing than the generic spam your users have been trained to spot.

Business email compromise pretexting. The same data lets an attacker build a believable profile of your bookkeeper, your treasurer, or your executive director before ever sending the first message.

What individuals should do

These steps are free. None of them require a subscription to a credit-monitoring service, and all of them are more effective than one.

1. Freeze your credit at all three bureaus

A security freeze at Equifax, Experian, and TransUnion prevents lenders from pulling your file, which prevents new accounts from being opened in your name. Federal law requires that freezing and unfreezing be free. You can lift a freeze temporarily when you actually need credit. This is the single highest-value action on this list.

2. Freeze with ChexSystems too

Credit bureau freezes do not stop someone from opening a checking account in your name — most banks screen deposit-account applications through ChexSystems instead. A separate freeze there closes a gap that most identity-theft checklists skip. (chexsystems.com)

3. Get an IRS Identity Protection PIN

The IP PIN is a six-digit number known only to you and the IRS, and a federal return filed under your SSN without it will be rejected. It is available to any taxpayer who can verify their identity, and it is the most direct defense against tax refund fraud. Request one through your IRS Online Account at irs.gov/ippin. A new PIN is issued each January, so plan on retrieving it annually. If you cannot verify online and your AGI is under the published threshold, Form 15227 is an alternative, as is an in-person appointment at a Taxpayer Assistance Center.

4. Restrict access to your Social Security record

Two separate, free options:

  • SSA electronic access block — call the Social Security Administration at 1-800-772-1213 and request a block on electronic and automated telephone access to your record. Be aware this is genuinely restrictive: it blocks you as well, and future changes require an in-person visit or another phone call.
  • E-Verify Self Lock — create a myE-Verify account at e-verify.gov and lock your SSN so it cannot be used to pass an employment eligibility check. Remember to unlock it before starting a new job with an E-Verify employer.

5. Freeze your children’s credit

Minors are prime targets precisely because nobody checks their credit for eighteen years. Parents and guardians can place a freeze on a minor’s file with each bureau at no cost.

6. Move off SMS-based two-factor authentication where you can

Given how effectively this data enables SIM swaps, text-message codes are the weakest form of MFA still in common use. Use an authenticator app or a hardware security key for email, banking, and anything that can reset other passwords.

7. Treat unsolicited contact as unverified, no matter what the caller knows

The new rule: knowing your personal details proves nothing. If your “bank” calls, hang up and dial the number printed on your card.

8. Ignore anyone promising an NPD settlement payout

As of this writing, there is no approved settlement and no official claim form in the NPD litigation, and the company’s bankruptcy makes meaningful compensation unlikely. Sites soliciting your SSN, banking details, or a filing fee to “process your NPD claim” are themselves a fraud. If a legitimate claims process is ever approved, it will be administered by a court-appointed administrator and announced through the court.

What organizations should do

If you run a business, a nonprofit, a church, or a municipal office, this breach changed your threat model whether or not you noticed.

Stop using knowledge-based verification at the help desk. If your password-reset or account-unlock procedure asks a caller to confirm their birthdate, address, or the last four of their SSN, that procedure is now security theater. Replace it with a callback to a phone number already on record, verification through an authenticated channel, manager approval for high-risk resets, or in-person confirmation. We can help you write and implement this policy — it is one of the cheapest, highest-impact controls available to a small organization.

Require out-of-band verification for any change to payment details. Direct deposit changes, vendor banking updates, wire instructions, and payroll modifications should require a voice confirmation to a known-good number that predates the request. Never use contact information supplied in the request itself.

Watch your payroll self-service portal. Direct-deposit diversion is a favorite attack against churches, schools, and nonprofits with small back-office teams. Enable change notifications, require MFA on the portal, and confirm that alerts route to someone who reads them.

Enforce MFA everywhere, and prefer phishing-resistant methods. For Microsoft 365 tenants especially, conditional access policies and number matching are no longer optional. If we manage your tenant, ask us where you currently stand.

Retain less. The best protection for personal data is not collecting it. Review what your donor database, volunteer background-check files, HR records, and old shared drives actually contain. If you are holding Social Security numbers you no longer need, dispose of them properly. If you need them, they belong encrypted and access-controlled, not in a spreadsheet on a file share.

Retrain your staff on the new baseline. The old advice — “be suspicious of messages with personal details, because a stranger shouldn’t know that” — is obsolete. Every one of your employees needs to understand that a caller reciting accurate personal information proves nothing at all.

Know your notification obligations before you need them. Missouri’s breach notification statute (§ 407.1500 RSMo) sets specific requirements when personal information is compromised. Deciding how you would respond is much cheaper in advance than at 11 p.m. on a Friday.

The uncomfortable summary

You cannot undo this breach. The data was aggregated without your consent, protected inadequately, leaked publicly, copied endlessly, and the company responsible went bankrupt. There is no remediation coming from NPD, and there is no version of “changing your password” that helps.

What you can do is make the data less useful. A frozen credit file, an IRS IP PIN, a locked SSN, strong MFA, and a help desk that no longer accepts a birthdate as proof of identity together neutralize most of what this data enables. Every one of those measures is free, and most take under an hour.


Katy Computer Systems has supported small businesses, nonprofits, and churches across the St. Louis area for over thirty years. If you would like help reviewing your organization’s identity verification procedures, payroll change controls, MFA posture, or data retention practices, get in touch — we are glad to walk through it with you.

Sources and further reading

Skip to content