TempMail Ninja
//

National Public Data Breach Exposes 2.9 Billion Records and PII

6 min read
TempMail Ninja
National Public Data Breach Exposes 2.9 Billion Records and PII

In one of the most alarming cybersecurity debacles in modern history, the background check aggregator National Public Data suffered an unprecedented data breach that exposed billions of records belonging to hundreds of millions of citizens. Operated by Florida-based Jerico Pictures, Inc., the data broker quietly harvested, aggregated, and indexed public records, non-public filings, and government registries over decades. When malicious actors compromised its infrastructure, approximately 2.9 billion rows of highly sensitive personal information—including unencrypted Social Security numbers (SSNs), residential histories, and full legal names—spilled onto illicit dark web forums. The sheer magnitude of the compromise underscores systemic vulnerabilities in the data brokerage industry, where consumer information is systematically gathered, monetized, and inadequately secured without the knowledge or consent of the individuals involved.

Anatomy of the Breach: Chronology and Threat Actors

The timeline of the intrusion reveals extensive dwell time and severe lapses in threat detection. While widespread public awareness erupted in August 2024, digital forensics and investigative disclosures traced initial unauthorized intrusions back to late December 2023. For months, adversaries maintained persistent access to internal systems without triggering defensive countermeasures.

The monetization phase escalated rapidly across high-profile cybercrime platforms:

  • April 2024 (The USDoD Auction): A prominent cybercriminal operating under the alias USDoD—notorious for targeting law enforcement databases and critical infrastructure—listed the compromised database on the revived BreachForums hacking platform. The threat actor demanded $3.5 million for exclusive rights to 2.9 billion records, claiming comprehensive coverage of populations across the United States, Canada, and the United Kingdom.
  • Summer 2024 (Private Distribution): Subsets of the exfiltrated dataset circulated among private threat syndicates and data brokers, facilitating targeted phishing and credential stuffing campaigns.
  • August 2024 (The Fenice Dump): A distinct threat actor known as Fenice bypassed private monetization channels entirely, releasing the massive dataset freely onto dark web hacking forums. This unencrypted distribution stripped any remaining barriers to access, delivering sensitive identity records directly into the hands of global criminal enterprises.

Technical Autopsy: Inside the Exposed National Public Data Repository

Security researchers and breach monitoring organizations, including Have I Been Pwned and KrebsOnSecurity, performed extensive technical evaluations of the published archives. The core data release comprised two massive uncompressed text files spanning roughly 277 gigabytes. Within these archives lay an estimated 2.7 to 2.9 billion plaintext records that cataloged the life histories of real individuals, both living and deceased.

Data Structure and Sensitive Attributes

Unlike credential breaches consisting merely of legacy email-password pairs, the database aggregated comprehensive personal identity profiles. Each row in the database linked multiple disparate verification data points, creating a rich graph of personal intelligence:

  • Government Identification: Full, unmasked Social Security numbers (SSNs) for U.S. citizens, alongside Social Insurance Numbers (SINs) and National Insurance Numbers (NINs) for Canadian and British residents.
  • Identity Demographics: Full legal names, documented aliases, maiden names, and verified dates of birth.
  • Longitudinal Geospatial Records: Physical address histories spanning up to three decades, detailing prior residences, utility links, and real property records.
  • Digital Contact Channels: Telephone numbers and more than 134 million unique email addresses verified across multiple iterations of the dataset.
  • Relational Lineage: Linkages between immediate family members, cohabitants, parents, and siblings derived from municipal and vital statistics scraping.

Root Causes and Egregious Security Failures

Technical post-mortems identified catastrophic operational security failures within the web environment operated by Jerico Pictures, Inc.. Independent security researchers uncovered that a sister domain, RecordCheck.net, maintained exposed, unauthenticated backup archives—such as a file labeled members.zip—hosted directly on a publicly reachable web directory.

When decompiled, the archive revealed internal source code and configuration files containing hardcoded, plaintext database credentials and administrative passwords. This structural negligence granted external actors direct read-access to master database instances without requiring complex zero-day exploitation, bypassing basic access control paradigms and web application firewalls (WAFs).

The breach of National Public Data highlights the pervasive risks inherent in the data brokerage business model. Data brokers operate in a regulatory gray area, gathering public records, real estate transfers, voter rolls, and court registries to assemble intricate consumer dossiers.

Crucially, because data brokers do not maintain direct consumer-facing relationships, virtually none of the compromised individuals opted into data collection or ever conducted business with Jerico Pictures, Inc.. Victims were entirely unaware that their most sensitive identity tokens were being harvested, stored unencrypted at rest, and exposed to the public Internet.

The public revelation of the intrusion triggered immediate legal and regulatory backlash against Jerico Pictures, Inc. and its executive leadership. Multiple class-action lawsuits were consolidated in federal courts, including the U.S. District Court for the Southern District of Florida.

The primary legal claims center on clear breaches of statutory and common law duty:

  1. Failure to Implement Reasonable Security: Plaintiffs assert that the company failed to follow industry-standard frameworks, such as NIST SP 800-53 or ISO/IEC 27001, by maintaining unencrypted Social Security numbers at rest and publishing plaintext credentials in web-accessible directories.
  2. Unreasonable Delay in Disclosure: Despite identifying unauthorized access as early as December 2023 and witnessing public auctions in April 2024, the parent entity delayed formal notifications to affected individuals and regulatory bodies until August 2024—violating state data breach notification statutes.
  3. Unjust Enrichment: Allegations demonstrate that the aggregator profited commercially from scraping and reselling consumer data while cutting costs on necessary security defenses, encryption, and penetration testing.

Congressional leaders and state attorneys general launched investigative inquiries. Lawmakers emphasized that the weaponization of 2.9 billion aggregated records represents a profound national security concern, elevating the risk of foreign espionage, synthetic identity fraud, and automated credential stuffing against federal systems.

Systemic Remediation and Identity Protection Protocols

Because static identifiers like Social Security numbers and dates of birth cannot be easily revoked or rotated like standard passwords, the exposure created by the National Public Data leak poses a persistent, lifelong risk. Mitigating the blast radius requires decisive technical and defensive action from both consumers and enterprise security teams.

Consumer-Facing Defense Strategies

  • Credit Freezes Across Major Bureaus: Individuals must place formal security freezes on their files with Equifax, Experian, TransUnion, and Innovis. Unlike simple credit monitoring or fraud alerts, a credit freeze prevents lenders from accessing credit files, effectively blocking the creation of fraudulent lines of credit or loans.
  • IRS Identity Protection PIN (IP PIN): Opting into the Internal Revenue Service IP PIN program prevents threat actors from submitting fraudulent tax filings using stolen SSNs to claim unauthorized tax refunds.
  • Multi-Factor Authentication (MFA) Hardening: Consumers must replace SMS-based MFA with hardware security keys (FIDO2/WebAuthn) or time-based one-time password (TOTP) authenticator apps, mitigating automated SIM-swapping attacks enabled by leaked phone and address records.

Enterprise and Policy Imperatives

From an enterprise risk standpoint, organizations must immediately deprecate knowledge-based authentication (KBA). Relying on past addresses, previous phone numbers, or partial SSNs to verify customer identities is obsolete when comprehensive 277GB datasets are indexed and queryable across underground cybercrime networks.

Ultimately, the catastrophic failure at National Public Data stands as a definitive turning point. It exposes the perils of unchecked data aggregation and underscores the urgent necessity for federal privacy legislation that mandates rigorous data minimization, uncompromised encryption at rest, strict credential lifecycle governance, and substantial liability for non-consensual data brokers.

TN

Written by

TempMail Ninja

Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.