One of The Biggest Data Breaches Ever Leaks 2.9 Billion Records - Here’s What You Need to Know!
A new class action lawsuit alleges that up to 2.9 billion personal records belonging to U.S. residents may have been exposed following a data breach at a background check company. The lawsuit was filed against Jerico Pictures Inc., operating as National Public Data (NPD), which provides access to public records sourced from various databases and repositories across the country.
The complaint, filed in Florida, claims that NPD illegally "scrapes" personal information from non-public sources without individuals' consent. The plaintiff in the case, Christopher Hofmann, reportedly received a notification from his identity theft protection service
Hofmann asserts that he never authorized NPD to access his personal information. The lawsuit argues that NPD assured those undergoing background checks that their information would be kept "safe," "confidential," and used only for as long as necessary. However, the attorneys claim that NPD failed to properly secure and protect the personally identifiable information it collected.
The lawsuit acknowledges that NPD has yet to officially disclose the specifics of the breach, including when it occurred and how it happened, and that those affected have not been formally notified. Instead, the lawsuit references findings from VX-Underground, a website focused on malware and cybersecurity. According to VX-Underground, in early April 2024, a threat actor using the alias "USDoD" offered a massive database titled "National Public Data" for sale on a site called Breached. The database allegedly contained 2.9 billion records of U.S. citizens and was priced at $3.5 million.
VX-Underground claims it received an advanced copy of the 277.1GB database and verified its authenticity. The database reportedly includes names, addresses (some dating back over three decades), Social Security numbers, and enough information to identify relatives of those who did not use a data opt-out service.
The lawsuit accuses NPD of failing to protect the personal information of those affected and not providing timely notification of the breach. While the breach allegedly impacted billions of records, it remains unclear how many individuals were actually affected, as the U.S. population is well below 1 billion.
If the breach is confirmed to have impacted billions, it could rank among the largest in history, rivaling Yahoo’s 2013 data breach that compromised all 3 billion of its user accounts.
领英推荐
Measures to Safeguard Your Identity After a Data Breach
Experiencing a data breach doesn't automatically mean your identity will be stolen, but it does increase the risk of being targeted by bad actors who now have more detailed information about you. Fortunately, there are several steps you can take to protect your identity
Update Your Passwords As soon as you learn that your data has been compromised, your first priority should be changing the password
Stay Vigilant Against Phishing and Smishing Scams
Consider Identity Theft Protection Services If you're particularly worried about your identity being stolen, signing up for identity theft protection services might be a good option.
Account Manager @ SmartCrypto | Cryptography, Sales, Strategy, Relationship management
7 个月I am finding that there is apathy in the masses now… There are too many data breaches happening that consumers seem to be ‘accepting’ & businesses seem to have the same lacklustre approach… am I wrong here??
Playing Long-term Games With Long-term People | Co-Founder and Chief Strategy Officer @ Atlas Privacy
7 个月we set up this resource so anyone could see if they've been affected by the breach, feel free to search for yourself - https://npdbreach.com/
Senior Security Architect | {Security Business Analyst} | (Risk Management) | Cybersecurity
7 个月It's becoming increasingly frustrating to see the same advice continually given to consumers—change their passwords, invest in identity protection software, and so on—especially when they are the innocent victims of a company's data breach. It's high time we stopped placing the burden of responsibility on consumers. This may sound radical, but perhaps we should consider discarding the entire social security number system and the current credit system. We could then devise something new, reengineered to align with the modern digital landscape. What about a physical FIDO2 key for our identities, with no crackable information stored online? While I don't claim to have all the answers, it's clear that our current system is flawed. It's time to discard it and start anew with a fresh approach.
The frustrating thing is that affordable full-stack #cybersecurity solutions exist! They even cover legacy systems. Invoke the power of #CyberCloak, for example. https://blueridgenetworks.com/
Cybersecurity Professional | Multi-disciplinary Team Leader | AI & Technology Enthusiast
7 个月Assuming every US SSN has been leaked, not only from this breach, but from every known breach in history, does that mean SSN's are no longer private?