2024 National Public Data (Jerico Pictures) — ~2.8B-row corpus; SSNs and address history exposed
Data compromised
Social Security numbers, names, current and historical home addresses, dates of birth, phone numbers, and other background-check fields per NPD disclosures, HIBP, and criminal-forum redistribution reporting
Technical writeup
National Public Data LLC—linked in litigation and Senate correspondence to Jerico Pictures Inc.—operated a people-search and background-data business whose repository suffered unauthorized access characterized as one of the largest U.S. consumer-data events of 2024. Trade press and security researchers described roughly 2.7–2.9 billion rows circulating on criminal forums, including Social Security numbers, names, current and historical addresses, dates of birth, and allied background-check fields—often framed as exposing nearly every American's SSN and prior residences when rows are aggregated across decades of broker data. NPD published a breach notice acknowledging the incident; Have I Been Pwned indexed the corpus. The event is widely framed as security-lapse exposure and data-broker aggregation rather than classic ransomware encryption; class actions and regulators focused on notice timing and data minimization. BreachHistory uses 2.8 billion as the commonly cited round figure from 2026 reporting; unique living-person counts differ from raw row totals.
Root cause
Unauthorized access to consumer data warehouse / inadequate access controls (per company and class-action narratives)
References
- https://www.bleepingcomputer.com/news/security/national-public-data-confirms-breach-exposing-social-security-numbers/
- https://www.bleepingcomputer.com/news/security/hackers-leak-27-billion-data-records-with-social-security-numbers/
- https://haveibeenpwned.com/Breach/NationalPublicData
- https://www.ibm.com/think/news/national-public-data-breach-publishes-private-data-billions-us-citizens
- https://nationalpublicdata.com/Breach.html