Florida company confirms massive data breach
By: Mike Snider
USA Today
..... National Public Data, which aggregates data to provide background checks, has confirmed it suffered a massive data breach involving Social Security numbers and other personal data on millions of Americans.
.....
The Florida company posted on its website a notice that "there appears to have been a data security incident that may have involved some of your personal information. The incident is believed to have involved a third-party bad actor that was trying to hack into data in late December 2023, with potential leaks of certain data in April 2024 and summer 2024."
..... News about the breach first came from a class-action lawsuit filed in U.S. district Court in Fort Lauderdale, Florida, and first reported on by Bloomberg law. Stolen from National Public Data were 2.9 billion records including names, address, Social Security numbers and relatives dating back at least thee decades, according to law firm Schubert, Jonkheer & Kolbe, which filed the suit.
.....
NPD said the breached data including names, email addresses, phone number and mailing addresses, as well as Social Security numbers. The company said it is cooperating with investigators and has "implemented additional security measures in efforts to prevent the re-occurrence of such a breach and to protect our systems."
..... Cybersecurity firm Pentester said it got the data and cerated a tool you can sue to see if your information is in the breach - it shows names, addresses, address histories, and Social Security numbers. You will find it at npd.pentester.com .
..... since financial institutions use Social Security numbers on applications for loans and credit cards and on investments, having that information that information available to threat actors poses a serious risk, Pentester.com co-founder Richard Glaser said in an advisory on the company website.
.....
He also suggested freezing credit reports. "Names, addresses and phone numbers might change, but your Social Security number doesn't," Glaser said.
..... NPD also advised consumers to "closely monitor your financial accounts and if you see any unauthorized activity, you should promptly contact your financial institution."
..... Consumers might want to get a credit report and get a fraud alert on their credit file, the company said.
.....
Consumers should do more than that, Odysseas Papadimitrious, the CEO of personal finance site WalletHub, told USA Today.
..... "Placing a fraud alert is not as effective as freezing your report," he said.
..... "A fraud alert is more of a heads-up to lenders, which they can easily ignore. it doesn't do much in practice," Papadimitruou said. "A Freeze, on the other hand, stops fraud in its tracks by preventing identity thieves form opening accounts in your name."
..... He and other security experts suggest consumers take that step because the personal data is likely in the hands of hackers.
..... The class-action suit alleges it was cybercriminal group USDoD that accessed NPD's network and stole unencrypted personal information. Then, the group posted a database it said has information on 2.9 billion people on the dark web on or about April 8, [2024] seeking to sell it for $3.5 million.