2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed (2024)

2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed (1)

Regardless of how careful you are online, your personal data can still end up in the hands of hackers—and a new data breach that exposed the data of 2.9 billion people is the perfect example of this.

As reported by Bloomberg, news of this massive new data breach was revealed as part of a class action lawsuit that was filed at the beginning of this month. A complaint submitted to the US District Court for the Southern District of Florida claims the exposed personal data belongs to a public records data provider named National Public Data, which specializes in background checks and fraud prevention.

The personal data of 2.9 billion people, which includes full names, former and complete addresses going back 30 years, Social Security Numbers, and more, was stolen from National Public Data by a cybercriminal group that goes by the name USDoD. The complaint goes on to explain that the hackers then tried to sell this huge collection of personal data on the dark web to the tune of $3.5 million. It's worth noting that due to the sheer number of people affected, this data likely comes from both the U.S. and other countries around the world.

Here’s everything we know so far about this massive data breach along with some steps you can take to stay safe if your personal information was exposed online.

The result of overscraping

2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed (2)

So how does a firm like National Public Data obtain the personal data of almost 3 billion people? The answer is through scraping which is a technique used by companies to collect data from web sites and other sources online.

What makes the way National Public Data did this more concerning is that the firm scraped personally identifiable information (PII) of billions of people from non-public sources. As a result, many of the people who are now involved in the class action lawsuit did not provide their data to the company willingly.

According to the complaint, one of the plaintiffs who resides in California first found out about the breach because he was using one of the best identity theft protection services which notified him that his data was exposed and leaked on the dark web.

Sign up to get the BEST of Tom's Guide direct to your inbox.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

As part of the class action lawsuit, this plaintiff is asking the court to have National Public Data securely dispose of all the personal information it acquired through scraping. However, he also wants the firm to compensate him and the other victims financially while implementing stricter security measures going forward.

How to stay safe after a data breach

2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed (3)

With full names, addresses and Social Security Numbers in hand, there’s a lot that hackers can do with this information, especially when it was made available for sale on the dark web.

While we haven’t heard anything yet from National Public Data, the company will likely have to put out a data breach notification soon given the mess that scraping non-public sources for data has gotten it into. These data breach notifications will likely arrive in the mail, so you’re going to want to keep a close eye on your mailbox for the time being.

Normally after a breach of this size, the company responsible will offer free access to either identity theft protection or credit monitoring for up to two years. In the meantime though, you’re going to want to be careful when checking your inbox or even your messages as hackers often use this type of data to launch targeted phishing attacks. At the same time, you’re going to want to carefully monitor your bank accounts and other financial accounts for signs of fraud or suspicious activity.

Since this is almost as big of a data breach as the one that Yahoo! suffered back in 2013 which saw data on 3 billion people exposed online, this likely isn’t the last we’ll be hearing about it. Tom's Guide has reached out to National Public Data for more information on the matter and we'll update this piece if and when we hear back from them.

More from Tom's Guide

  • ADT suffers data breach — full names, addresses and phone numbers exposed
  • FBI issues warning over scammers impersonating banks to steal your debit card
  • This Android malware drains your bank accounts and completely wipes your device

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about online security

What is Proton Scribe?Will the CEO's arrest mean the end of Telegram? 3 alternatives to the secure messaging app

Latest

9 epic Labor Day laptop deals I recommend from $349
See more latest►

16 CommentsComment from the forums

  • Fox Tread3

    August 6, 2024 - First of all, I think the way National Public Data goes about getting data. Should be considered illegal, and stopped immediately. They are invading the privacy of BILLIONS of people without their knowledge. I think the Credit reporting companies ("agencies"🤨 😏) are far too powerful as it is. So why is it necessary for a company like National Public Data to exist in the first place? U.S. and foreign countries' regulatory agencies are all over companies like Google and Microsoft for invading the public's privacy and using the personal data they collect to sell to other companies. These companies get their data in a fairly "transparent" way. However, National Public Data gets the data it sells in complete secrecy, and I believe violates existing privacy laws. I fortunately can limit to some degree my exposure online, and the data collected by companies and services I deal with. However, I do not use options offered by companies and services to have "convenience" payments like Auto-pay etc. Companies and corporations of every stripe have proven that they are incapable of keeping the important data of their customers safe. I pay my ISP extra every month to get a bill in the mail, and to pay by check. Lastly, I think it is almost criminal for various services to demand that customers that want to use their services. Have to have a credit/debit cards that the company can automatically charge every payment date. There is no reason why, a customer cannot make a payment via card upon the request of the servicing or streaming company. This is an example of government regulators ignoring the egregious business models of many large companies and corporations.

    Reply

  • CyberHunk

    Fox Tread3 said:

    August 6, 2024 - First of all, I think the way National Public Data goes about getting data. Should be considered illegal, and stopped immediately. They are invading the privacy of BILLIONS of people without their knowledge. I think the Credit reporting companies ("agencies"🤨 😏) are far too powerful as it is. So why is it necessary for a company like National Public Data to exist in the first place? U.S. and foreign countries' regulatory agencies are all over companies like Google and Microsoft for invading the public's privacy and using the personal data they collect to sell to other companies. These companies get their data in a fairly "transparent" way. However, National Public Data gets the data it sells in complete secrecy, and I believe violates existing privacy laws. I fortunately can limit to some degree my exposure online, and the data collected by companies and services I deal with. However, I do not use options offered by companies and services to have "convenience" payments like Auto-pay etc. Companies and corporations of every stripe have proven that they are incapable of keeping the important data of their customers safe. I pay my ISP extra every month to get a bill in the mail, and to pay by check. Lastly, I think it is almost criminal for various services to demand that customers that want to use their services. Have to have a credit/debit cards that the company can automatically charge every payment date. There is no reason why, a customer cannot make a payment via card upon the request of the servicing or streaming company. This is an example of government regulators ignoring the egregious business models of many large companies and corporations.

    Exactly this. These companies are no different than the hackers who steal people's personal information.

    Reply

  • Big Willie!

    Until the penalties for allowing these hacks are severe, these data aggregators will never have the same care and concern for our data as we do. But, as always, business donors and lobbyists are the primary constituents of our elected leaders, and laws and regulations will always favor businesses over individuals.

    Reply

  • say what boy

    admin said:

    Class action lawsuit in Florida has revealed that hackers stole a database full of sensitive information on 2.9 billion people before they tried selling it on the dark web.

    2.9 billion hit in one of largest data breaches ever — full names, addresses and SSNs exposed : Read more

    Where do you come up with that number pull it out of rabbit's ass that would be the population of China and India and maybe another small country we only have 400 million in this country

    Reply

  • rgd1101

    if you read the article , it is from the source on bloomberglaw

    Reply

  • COLGeek

    say what boy said:

    Where do you come up with that number pull it out of rabbit's ass that would be the population of China and India and maybe another small country we only have 400 million in this country

    Explained in article..."The personal data of 2.9 billion people, which includes full names, former and complete addresses going back 30 years..."

    The big take away here is that internet connected entities, across the board, do not protect user data. Else, it wouldn't be so easily accessible for such aggregators.

    People leave a digital footprint, no matter how diligent they are, those we do business with are NOT. Scraping that exposed data has become almost trivial, unfortunately.

    Rules must change if this is going to improve.

    Reply

  • TheWerewolf

    COLGeek said:

    Explained in article..."The personal data of 2.9 billion people, which includes full names, former and complete addresses going back 30 years..."

    The big take away here is that internet connected entities, across the board, do not protect user data. Else, it wouldn't be so easily accessible for such aggregators.

    People leave a digital footprint, no matter how diligent they are, those we do business with are NOT. Scraping that exposed data has become almost trivial, unfortunately.

    Rules must change if this is going to improve.

    That's not actually an explanation relevant to his question.

    SSNs are unique to the US. Canada has SINs and the UK has NI numbers, for example. There are only 340M people in the US and so even taking into account 30 years of data, 2.9B is almost nine times the entire population of the US.

    If the article had said 2.9 billion distinct records, that would be possible, with multiple records per person (although, again nine records per person?).

    Alternatively, this is world data, but then why mention SSNs repeatedly when that's not relevant for most of the records (ie: 2.5B of the 2.9B, more or less?)

    Moreso, if the data includes past addresses for people going back 30 years, while this has its own issues, that data is less dangerous.

    In any case, other countries DO have laws against this sort of thing. That's what the GPDR and the EU data privacy laws are about. If this company has scraped data for Europeans, then they're going to get railed by the EU. The main problem is the US which is so protective of businesses' rights over citizens' rights that they'll never bring in that strict a set of laws to protect the public from this kind of infringement of privacy.

    Reply

  • JaniceIce

    TheWerewolf said:

    That's not actually an explanation relevant to his question.

    SSNs are unique to the US. Canada has SINs and the UK has NI numbers, for example. There are only 340M people in the US and so even taking into account 30 years of data, 2.9B is almost nine times the entire population of the US.

    If the article had said 2.9 billion distinct records, that would be possible, with multiple records per person (although, again nine records per person?).

    Alternatively, this is world data, but then why mention SSNs repeatedly when that's not relevant for most of the records (ie: 2.5B of the 2.9B, more or less?)

    Moreso, if the data includes past addresses for people going back 30 years, while this has its own issues, that data is less dangerous.

    In any case, other countries DO have laws against this sort of thing. That's what the GPDR and the EU data privacy laws are about. If this company has scraped data for Europeans, then they're going to get railed by the EU. The main problem is the US which is so protective of businesses' rights over citizens' rights that they'll never bring in that strict a set of laws to protect the public from this kind of infringement of privacy.

    Since 1936, about 500 million SSNs have been issued. This 2.9B click-bait article is WAY over exaggerated.

    Reply

  • COLGeek

    JaniceIce said:

    Since 1936, about 500 million SSNs have been issued. This 2.9B click-bate article is WAY over exaggerated.

    Source? That number would seem low.

    A lot of people have existed over the last thirty years, more than the existing population at one given time.

    Even if 2.9B is over the mark, the impact of this latest hack is massive and highlights the poor data protection mechanisms (added to outright selling of data) in place. Correlating all that data is trivial (in a manner of speaking) given the tools available to sift through all of this data.

    From personal experience, I have been notified via multiple monitoring services (all provided free due to previous incidents) about my own personal data being in this pile. Much of it is very dated and wrong. Some is correct and that is indeed worrisome.

    Reply

  • Enkimoré

    A data breach is the best way to launder money with fake political, faith, and countless ways of donation using your information. We can debate who's to blame but the real reason is for money laundering.

    Reply

Most Popular
Chelsea vs Crystal Palace live stream: How to watch Premier League game online and on TV, team news
iPhone 16 Pro’s gold titanium color just revealed before Apple event
Newcastle vs Tottenham live stream: How to watch Premier League game online and on TV, team news
5 best new movies to stream this weekend on Netflix, Max, Peaco*ck and more
New on Prime Video and Freevee in September 2024 — all the new shows and movies to watch
I tried this amazing smart couch with built in surround sound and wireless charging — and it's more affordable than you'd expect
7 biggest new games launching in September 2024 for PS5, Nintendo Switch, Xbox and PC
Apple Watch 10 — should you wait or get Apple Watch Series 9 now?
Argentina vs Australia live streams 2024: How to watch Rugby Championship online, Creevy's last stand
NYT Connections today hints and answers — Saturday, August 31 (#447)
NYT Strands today — hints, spangram and answers for game #181 (Saturday, August 31 2024)
2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed (2024)

References

Top Articles
The Latest Scoop: Shonda Rhimes's Dating Life Explored
Uncovering The Parents Of WNBA Legend Diana Taurasi
Funny Roblox Id Codes 2023
Golden Abyss - Chapter 5 - Lunar_Angel
Www.paystubportal.com/7-11 Login
Joi Databas
DPhil Research - List of thesis titles
Shs Games 1V1 Lol
Evil Dead Rise Showtimes Near Massena Movieplex
Steamy Afternoon With Handsome Fernando
fltimes.com | Finger Lakes Times
Detroit Lions 50 50
18443168434
Newgate Honda
Zürich Stadion Letzigrund detailed interactive seating plan with seat & row numbers | Sitzplan Saalplan with Sitzplatz & Reihen Nummerierung
Grace Caroline Deepfake
978-0137606801
Nwi Arrests Lake County
Justified Official Series Trailer
London Ups Store
Committees Of Correspondence | Encyclopedia.com
Pizza Hut In Dinuba
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
Free Online Games on CrazyGames | Play Now!
Sizewise Stat Login
VERHUURD: Barentszstraat 12 in 'S-Gravenhage 2518 XG: Woonhuis.
Jet Ski Rental Conneaut Lake Pa
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Ups Print Store Near Me
C&T Wok Menu - Morrisville, NC Restaurant
How Taraswrld Leaks Exposed the Dark Side of TikTok Fame
University Of Michigan Paging System
Dashboard Unt
Access a Shared Resource | Computing for Arts + Sciences
Speechwire Login
Healthy Kaiserpermanente Org Sign On
Restored Republic
Lincoln Financial Field, section 110, row 4, home of Philadelphia Eagles, Temple Owls, page 1
Jambus - Definition, Beispiele, Merkmale, Wirkung
Ark Unlock All Skins Command
Craigslist Red Wing Mn
D3 Boards
Jail View Sumter
Nancy Pazelt Obituary
Birmingham City Schools Clever Login
Thotsbook Com
Funkin' on the Heights
Vci Classified Paducah
Www Pig11 Net
Ty Glass Sentenced
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 6438

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.