
National Public Data, a background-check company most people have never heard of, exposed the personal information of nearly 3 billion people. Social Security numbers, names, addresses, phone numbers, all of it. A hacking group calling itself USDoD pulled the data and put it up for sale on the dark web for $3.5 million. The breach itself happened around April 2024, with some of the data reportedly circulating as early as December 2023.
Here’s the uncomfortable part: you likely never gave National Public Data your information directly. They’re a data broker, one of hundreds of companies that buy, sell, and aggregate personal data behind the scenes, and most people find out they exist only when a breach like this one makes the news.
Why this one actually matters
A stolen password gets changed and the problem is mostly over. A stolen Social Security number doesn’t expire, and that’s what makes this breach different from the usual “change your password” news cycle. With a name, address, and SSN, someone can open credit accounts, file fraudulent tax returns, or pass identity checks that are supposed to keep them out. It also feeds directly into more convincing phishing: a scammer who already has your old address or a family member’s name sounds a lot more legitimate on the phone than one guessing blind.
What to actually do about it
Freezing your credit is the single most effective step, and it’s free. A freeze blocks anyone, including you, from opening new credit in your name until you lift it, which takes minutes when you actually need to apply for something.
Beyond the freeze: check your bank and credit card statements for anything you don’t recognize, and pull your free credit reports regularly rather than waiting for an annual reminder. Use unique passwords on important accounts and turn on multi-factor authentication wherever it’s offered, since a breach like this makes old, reused passwords even more dangerous. Be extra skeptical of unexpected calls or texts asking you to “verify” information you’d expect them to already have. And if you have older parents or relatives, it’s worth walking them through this specifically. They’re the more common target once stolen data like this starts circulating.
None of this guarantees nothing bad happens. It just means that if someone tries, they hit a freeze instead of an open door.
It’s the same underlying problem in a different outfit: once a company holds your data, you rarely get much say in what happens to it until something goes wrong.


