{"id":4926,"date":"2024-08-19T10:39:54","date_gmt":"2024-08-19T15:39:54","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/national-public-data-confirms-massive-breach"},"modified":"2024-08-19T10:39:54","modified_gmt":"2024-08-19T15:39:54","slug":"national-public-data-confirms-massive-breach-2","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/19\/national-public-data-confirms-massive-breach-2\/","title":{"rendered":"National Public Data Confirms Massive Breach"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd0c21b630c287ee1\/66bfacebe239dc13dd0d2403\/breach_Hananeko_Studio_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data aggregator National Public Data (NPD) has finally confirmed a breach that has exposed personal identity records belonging to potentially hundreds of millions of consumers across the US, UK, and Canada.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nationalpublicdata.com\/Breach.html\" rel=\"noopener\">statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that offered little details, the Coral Springs, Fla.-based company acknowledged what numerous others have reported in recent days about a &#8220;third-party bad actor&#8221; accessing data from NPDs databases sometime in April 2024. The company described the data which the threat actor accessed as including full names, email addresses, phone numbers, Social Security numbers, and mailing addresses belonging to an unknown number of people.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Real and Accurate Data\">Real and Accurate Data<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NPD&#8217;s advisory contained the usual boilerplate language about the company taking steps to protect against a similar incident but left it entirely up to victims to take measures to protect themselves against ID theft and other fraud resulting from its security lapse. NPD is a data aggregator that claims businesses, private investigators, human resources departments, and staffing agencies use its data for background checks, to obtain criminal records and other uses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">News of the breach has been circulating since at least April when <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/DailyDarkWeb\/status\/1777335594567283045?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1777335594567283045%7Ctwgr%5Eb2711fc3782b0ed06364184e14bf156cf85bcd57%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.troyhunt.com%2Finside-the-3-billion-people-national-public-data-breach%2F\" rel=\"noopener\">Dark Web Intelligence<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> posted on X about &#8220;USDoD&#8221; a hacker with a reputation for previous data heists, having obtained a database from NPD containing some 200 gigabytes of personal information on residents in the US, UK, and Canada. The threat actor claimed the NPD database contained some 2.9 billon rows of records. Many have incorrectly reported that as the number of victims instead in characterizing the breach as one of the biggest ever of private data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VX-underground a community focused on malware and cybercrime which <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/x.com\/vxunderground\/status\/1797047998481854512\" rel=\"noopener\">reviewed the dataset<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> assessed the leaked data as being &#8220;real and accurate&#8221; and containing the first name, last name, SSN, current address and addresses for individuals going back over 30 years. &#8220;It also allowed us to find their parents, and nearest siblings,&#8221; VX-underground said. &#8220;We were able to identify someone&#8217;s parents, deceased relatives, Uncles, Aunts, and Cousins.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition, the NPD database contains information on deceased individuals, some of whom had been deceased more than 20 years.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Troy Hunt, who maintains the &#8220;Have I Been Pwned&#8221; site, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/08\/nationalpublicdata-com-hack-exposes-a-nations-data\/\" rel=\"noopener\">reported finding 134 million unique<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> email addresses and millions of rows of criminal records. He assessed the massive dataset as containing a kludge of useful data (to criminals) as well as useless, incorrect, and redundant data that NPD appears to have built by scraping publicly available data from countless\u2014and now untraceable\u2014sources.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Need to Stop Use of SSNs for ID Verification\">A Need to Stop Use of SSNs for ID Verification<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The massive breach has prompted the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/massive-data-breach-vf-35m-vans-retail-customers\" rel=\"noopener\">usual concerns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> about the need for organizations to implement stronger controls for protecting data that consumers entrust to them. An <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/2021%20and%202022,\" rel=\"noopener\">Apple study last year<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> found data breaches compromised a staggering 2.5 billion consumer records in 2021 and 2022.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But it has also resurfaced a long-standing sentiment among many about the need for organizations, government entities, and others to stop using SSNs as the primary identifier for pretty much any and all transactions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;NPD should have done lots of things better but there is one thing that&#8217;s on us: it&#8217;s past time to get rid of SSN,&#8221; says Ambuj Kumar, CEO of Simbian. Replacing SSN with a digital ID similar to what&#8217;s used in cryptography and in a technology like Apple Wallet is relatively easy and straightforward he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The impediments are purely psychological and inertia,&#8221; Kumar says. &#8220;Think of a digital ID as a government issued credit card number that is known only to the government and the individual,&#8221; he notes. When applying for a mortgage, for example, a token is generated from the original number and this new number is shared with the bank. If there is a breach at the bank, the original number is still safe since the bank only saw the token.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Limit to What Consumers Can Do?\">A Limit to What Consumers Can Do?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The breach has also focused attention on the limits to what consumers can do to protect their data. Chris Deibler, vice president of security at DataGrail, says none of the usual recommendations\u2014such as using password managers, adding multi-factor authentication, and paying attention to accounts resets\u2014would have helped in the NPD breach. The real effort now has to come at the corporate and regulatory level and more effort should be focused on disincentivizing mass data aggregation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Corporations don&#8217;t respond to the same stimuli as individuals, so advocating for better education and letting the moral arc of the universe do its thing probably isn&#8217;t going to cut it,&#8221; Deibler notes. &#8221; You need levers that actually change the conversation about data collection and handling risk at the board level. In that context, corporations respond to specific liabilities &#8212; reputational, civil, criminal, existential.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He argues that harmed parties in a data breach have specific, statutorily defined compensations available to them that go well beyond just one year&#8217;s worth of free credit monitoring. Similarly, executives at companies that knowingly put customer data at risk should share criminal liability for a breach. &#8220;In the most egregious of circumstances, if you mess up hard on customer data, you should not be permitted to have the opportunity to do so again, either at the corporate or individual level.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/national-public-data-confirms-massive-breach\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data aggregator National Public Data (NPD) has finally confirmed a<\/p>\n","protected":false},"author":12,"featured_media":4928,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/national-public-data-confirms-massive-breach.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4926"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4926\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4928"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}