Hackers may have stolen the Social Security numbers of many Americans. Here's what to know. (2024)

MoneyWatch

By Aimee Picchi

Edited By Anne Marie Lee

/ CBS News

A new lawsuit is claiming hackers have gained access to the personal information of "billions of individuals," including their Social Security numbers, current and past addresses and the names of siblings and parents — personal data that could allow fraudsters to infiltrate financial accounts or take out loans in their names.

The allegation arose in a lawsuit filed earlier this month by Christopher Hofmann, a California resident who claims his identity theft protection service alerted him that his personal information had been leaked to the dark web by the "nationalpublicdata.com" breach. The lawsuit was earlier reported by Bloomberg Law.

The breach allegedly occurred around April 2024, with a hacker group called USDoD exfiltrating the unencrypted personal information of billions of individuals from a company called National Public Data (NPD), a background check company, according to the lawsuit. Earlier this month, a hacker leaked a version of the stolen NPD data for free on a hacking forum, tech site Bleeping Computer reported.

That hacker claimed the stolen files include 2.7 billion records, with each listing a person's full name, address, date of birth, Social Security number and phone number, Bleeping Computer said. While it's unclear how many people that includes, it's likely "that everyone with a Social Security number was impacted," said Cliff Steinhauer, director of information security and engagement at The National Cybersecurity Alliance, a nonprofit that promotes online safety.

"It's a reminder of the importance of protecting yourself, because clearly companies and the government aren't doing it for us," Steinhauer told CBS MoneyWatch.

NPD didn't immediately respond to a request for comment.

Here's what to know about the alleged hack.

What is National Public Data?

National Public Data is a data company based in Coral Springs, Florida, that provides background checks for employers, investigators and other businesses that want to check people's backgrounds. Its searches include criminal records, vital records, SSN traces and more information, its website says.

There are many similar companies that scrape public data to create files on consumers, which they then sell to other businesses, Steinhauer said.

"They are data brokers that collect and sell data about people, sometimes for background check purposes," he said. "It's because there's no national privacy law in the U.S. — there is no law against them collecting this data against our consent."

What happened with the USDoD hack?

According to the new lawsuit, USDoD on April 8 posted a database called "National Public Data" on the dark web, claiming to have records for about 2.9 billion individuals. It was asking for a purchase price of $3.5 million, the lawsuit claims.

However, Bleeping Computer reported that the file was later leaked for free on a hacker forum, as noted above.

How many people have been impacted?

The number of people impacted by the breach is unclear. Although the lawsuit claims "billions of individuals" had their data stolen, the total population of the U.S. stands at about 330 million. The lawsuit also alleges that the data includes personal information of deceased individuals.

Bleeping Computer reports that the hacked data involves 2.7 billion records, with individuals having multiple records in the database. In other words, one individual could have separate records for each address where they've lived, which means the number of impacted people may be far lower than the lawsuit claims, the site noted.

The data may reach back at least three decades, according to law firm Schubert Jonckheer & Kolbe, which said on Monday it is investigating the breach.

Did NPD alert individuals about the hack?

It's unclear, although the lawsuit claims that NPD "has still not provided any notice or warning" to Hoffman or other people affected by the breach.

"In fact, upon information and belief, the vast majority of Class Members were unaware that their sensitive [personal information] had been compromised, and that they were, and continue to be, at significant risk of identity theft and various other forms of personal, social, and financial harm," the lawsuit claims.

Information security company McAfee reported that it hasn't found any filings with state attorneys general. Some states require companies that have experienced data breaches to file reports with their AG offices.

Can you find out if your data was part of the hack?

There are tools available that will monitor what information about you is available on the dark web, noted Michael Blair, managing director of cybersecurity firm NukuDo. Commonly breached data includes your personal addresses, passwords and email, he added.

One such service is how Hofmann, who filed the lawsuit, found out that his information has been leaked as part of NPD breach.

"Make sure to use reputable companies to look that up," Blair said.

What should I do to protect my information?

Security experts recommend that consumers put freezes on their credit files at the three big credit bureaus, Experian, Equifax and TransUnion. Freezing your credit is free, and will stop bad actors from taking out loans or opening credit cards in your name.

"The biggest thing is to freeze your credit report, so it can't be used to open new accounts in your name and commit other fraud in your name," Steinhauer said.

Steinhauer recommends consumers take several additional steps to protect their data and finances:

  • Make sure your passwords are at least 16 characters in length, and are complex.
  • Use a password manager to save those long, complex passwords.
  • Enable multifactor authentication, which Steinhauer calls "critical," because simply using a single password to access your accounts isn't enough protection against hackers.
  • Be on alert for phishing and other scams. One red flag is that the scammers will try to create a sense of urgency to manipulate their victims.
  • Keep your security software updated on your computer and other devices. For instance, make sure you download the latest security updates from Microsoft or Apple onto your apps and devices.

You can also get a tracking service that will alert you if your data appears on the dark web.

"You should assume you have been compromised and act accordingly," Steinhauer said.

    In:
  • Data Breach
  • Social Security

Aimee Picchi

Aimee Picchi is the associate managing editor for CBS MoneyWatch, where she covers business and personal finance. She previously worked at Bloomberg News and has written for national news outlets including USA Today and Consumer Reports.

Hackers may have stolen the Social Security numbers of many Americans. Here's what to know. (2024)
Top Articles
De essentiële onderdelen van een succesvolle L&D strategie
Venom X22-GT 250cc Full Size Motorcycle - Fully Automatic
Fighter Torso Ornament Kit
Srtc Tifton Ga
Craigslist Houses For Rent In Denver Colorado
Farepay Login
Craigslist Benton Harbor Michigan
Nfr Daysheet
9192464227
What are Dietary Reference Intakes?
Ati Capstone Orientation Video Quiz
Farmers Branch Isd Calendar
Stream UFC Videos on Watch ESPN - ESPN
Transformers Movie Wiki
Synq3 Reviews
Think Up Elar Level 5 Answer Key Pdf
2024 U-Haul ® Truck Rental Review
Unlv Mid Semester Classes
Willam Belli's Husband
All Obituaries | Buie's Funeral Home | Raeford NC funeral home and cremation
Missouri Highway Patrol Crash
Halo Worth Animal Jam
Uta Kinesiology Advising
Glenda Mitchell Law Firm: Law Firm Profile
Beverage Lyons Funeral Home Obituaries
Surplus property Definition: 397 Samples | Law Insider
2021 MTV Video Music Awards: See the Complete List of Nominees - E! Online
The Eight of Cups Tarot Card Meaning - The Ultimate Guide
Phoenixdabarbie
Little Einsteins Transcript
Evil Dead Rise - Everything You Need To Know
Kristen Hanby Sister Name
Kaiserhrconnect
Calculator Souo
Att U Verse Outage Map
Whas Golf Card
Joplin Pets Craigslist
Ewwwww Gif
Craigslist Lakeside Az
The Syracuse Journal-Democrat from Syracuse, Nebraska
One Main Branch Locator
Join MileSplit to get access to the latest news, films, and events!
St Anthony Hospital Crown Point Visiting Hours
Exam With A Social Studies Section Crossword
Gamestop Store Manager Pay
Whitney Wisconsin 2022
Lesly Center Tiraj Rapid
Egg Inc Wiki
Mikayla Campinos Alive Or Dead
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Powah: Automating the Energizing Orb - EnigmaticaModpacks/Enigmatica6 GitHub Wiki
Cbs Scores Mlb
Latest Posts
Article information

Author: Arline Emard IV

Last Updated:

Views: 5805

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Arline Emard IV

Birthday: 1996-07-10

Address: 8912 Hintz Shore, West Louie, AZ 69363-0747

Phone: +13454700762376

Job: Administration Technician

Hobby: Paintball, Horseback riding, Cycling, Running, Macrame, Playing musical instruments, Soapmaking

Introduction: My name is Arline Emard IV, I am a cheerful, gorgeous, colorful, joyous, excited, super, inquisitive person who loves writing and wants to share my knowledge and understanding with you.