TL;DR: In December 2023, someone breached National Public Data (NPD), a Florida background check firm doing business as Jerico Pictures, Inc. By April 2024, a hacker using the alias "USDoD" was selling the database on a dark web forum for $3.5 million. The dataset contained 2.9 billion rows with full names, current and past addresses, Social Security numbers, dates of birth, and phone numbers [1]. NPD only confirmed the breach after a class action was filed in August 2024. The company filed for Chapter 11 bankruptcy, got its case thrown out for lacking insurance, shut down in December 2024, and was sued by a coalition of 25 state attorneys general in August 2025 [2]. Brazil arrested the alleged hacker on October 16, 2024 [3]. If you are an American, your SSN is probably in there.

What Is National Public Data?

You've probably never heard of them. They had your data anyway.

National Public Data (NPD) was a subscription background check service run by Jerico Pictures, Inc., a Florida company. Private investigators, employers, and anyone willing to pay could run a search on a person and get back their name, current and past addresses, phone number, date of birth, and Social Security number [4].

The data wasn't collected from people who signed up. The Bloomberg Law complaint describes it this way: NPD "had the misfortune of having their PII targeted, mined, and scraped" from "non-public sources without their consent" [1]. The plaintiffs named in Hofmann v. Jerico Pictures, Inc. were never customers. They didn't know NPD had their data until the breach hit the news.

Bloomberg Law's reporting described the database as covering "over 270 million people" [1]. Once you collapse the duplicates between multiple address histories, the unique person count is in the hundreds of millions, not the 2.9 billion rows number in the original listing.

What Was Stolen

The leaked dataset included everything a criminal needs to open a new account in your name:

  • Full names
  • Current and past home addresses (some decades old)
  • Social Security numbers
  • Dates of birth
  • Phone numbers

The complaint in Hofmann v. Jerico Pictures describes the dataset as "unencrypted personal information" [1]. The CyberScoop reporting on the arrest of the alleged hacker described the stolen data as spanning "at least three decades" [4].

The 2.9 billion rows number is total records, not unique people. Bloomberg Law reported the database was 277.1 GB uncompressed [1]. UpGuard's analysis put the unique SSN count at roughly 272 million and unique email addresses at roughly 137 million [7]. The dataset is "heavily disputed" because the figures depend on how you count duplicates, but the bottom line is the same: nearly every adult American is in there.

Timeline

  • December 2023: An attacker begins attempting to breach NPD's systems, according to Rep. Ritchie Torres' investigative report [5].
  • April 8, 2024: A threat actor using the alias "USDoD" lists the NPD database on the "Breached" cybercrime forum for $3.5 million [1].
  • August 1, 2024: Christopher Hofmann files a proposed class action in the U.S. District Court for the Southern District of Florida. Case number 0:24-cv-61383 [1].
  • Mid-August 2024: Multiple additional class actions follow, and news coverage by major outlets forces NPD to publicly acknowledge the breach.
  • September 10, 2024: Rep. Ritchie Torres (NY-15) releases an investigative report. Up to 85.1% of members of the U.S. House and Senate had their data included in the breach [5].
  • October 2, 2024: Jerico Pictures files for Chapter 11 bankruptcy in the Southern District of Florida. Case number 24-20281-BKC-SMG [6].
  • October 16, 2024: Brazil's Federal Police arrest a 33-year-old Belo Horizonte resident identified as "Luan B.G." in connection with the USDoD persona [3][4]. The operation, called "Operation Data Breach," also covered the 2020 and 2022 sales of Brazilian Federal Police officer data.
  • October 31, 2024: The U.S. Trustee's emergency motion to dismiss the bankruptcy is granted. The petition is dismissed because Jerico Pictures carried no liability insurance that would cover a post-petition data breach, a violation of Bankruptcy Code section 1112(b)(4)(C) [6].
  • Late 2024: National Public Data shuts down. A closure notice appears on nationalpublicdata.com telling visitors the company is winding down and no longer offering its data products.
  • August 18, 2025: Florida Attorney General James Uthmeier, joined by 24 other state attorneys general, files suit against National Public Data, Jerico Pictures, Acxiom LLC, and Optic Ideas & Solutions. The complaint alleges negligence, deceptive trade practices, and violations of state consumer protection laws [2].

The Hacker: USDoD

The person behind the USDoD alias is a 33-year-old Brazilian man identified by Brazilian Federal Police as "Luan B.G." and "Luan G," living in Belo Horizonte, capital of the state of Minas Gerais [3][4].

CrowdStrike researchers and the Brazilian tech publication Tecmundo reportedly identified him in August 2024. After the doxing, USDoD publicly confirmed his real identity and told HackRead he "would not be running away and instead try to reach some sort of deal with Brazilian authorities, offering them his cybersecurity expertise" [3].

According to the Brazilian Federal Police statement, the suspect is also linked to:

  • The 2023 breach of the FBI's InfraGard portal
  • An Airbus data breach
  • A breach at the U.S. Environmental Protection Agency
  • The sale of Brazilian Federal Police officer data on May 22, 2020 and February 22, 2022 [3]

The arrest happened. The data is still out. Those are different problems.

The Lawsuits

Three class actions were filed in August 2024. The Reed Smith analysis later described Jerico Pictures as facing "nearly two dozen class action lawsuits, regulatory scrutiny, customer attrition, and" the bankruptcy petition [6].

Hofmann v. Jerico Pictures, the lead case, alleged that:

  • Jerico Pictures "mined and scraped" PII from "non-public sources without their consent"
  • Jerico Pictures "assumed legal and equitable duties" to protect the data
  • Jerico Pictures "knew, or at least should have known, it had a responsibility to protect this data" [1]

Damages sought included invasion of privacy, lost or diminished value of PII, and lost opportunity costs from mitigation efforts [1].

Then came the August 18, 2025 multistate suit. Florida Attorney General James Uthmeier leads the coalition of 25 attorneys general. The defendants include NPD's parent Jerico Pictures, the data broker Acxiom LLC, and Optic Ideas & Solutions. The complaint asks the court to prevent future breaches, secure the remaining sensitive data, and obtain financial restitution for affected consumers [2].

As of this writing, no settlement has been approved for the class. Anyone tracking an "NPD settlement check" should look for the MDL court, not marketing pages that promise one.

Why the Bankruptcy Got Thrown Out

Most data breach bankruptcies stumble over insurance. Jerico Pictures' did too.

On October 23, 2024, the U.S. Trustee filed an emergency motion to dismiss the Chapter 11 petition. The motion was granted on October 31, 2024 (ECF No. 31). The reason: Jerico Pictures carried no insurance that would cover a post-petition data breach. That violates Bankruptcy Code section 1112(b)(4)(C), which allows dismissal for "failure to maintain appropriate insurance that poses a risk to the estate or to the public" [6].

The Reed Smith analysis called it a landmark ruling. A data broker with no insurance to cover a data breach cannot use Chapter 11 to park its liabilities. Translation: companies like NPD cannot just declare bankruptcy and walk away from the people they exposed.

How To Check If You're In The Breach

There is no clean official lookup tool NPD left behind. The company shut down in December 2024.

These are the practical ways readers have used to verify exposure:

  • HaveIBeenPwned: Troy Hunt's breach notification service. Enter your email address. If your email is in the NPD dump, it will show up in their breach list.
  • Your credit report: Pull free reports at AnnualCreditReport.com from Equifax, Experian, and TransUnion. Look for accounts or inquiries you do not recognize.
  • Your IRS transcript: Request a wage and income transcript from the IRS. If someone has used your SSN for employment, it will show income you never earned.
  • Your Social Security statement: Create an account at ssa.gov. Review your earnings record. Mismatches mean someone else has used your SSN for work.

None of these tools will tell you "yes, your SSN is in the NPD dump." If you are an American adult, assume yes. The Torres report found 85.1% of Congress had data in the dataset [5]. If 85% of Congress did, you almost certainly did too.

What You Should Do Now

If you've been an adult in the United States at any point since the 1980s: Assume your SSN is in the NPD dataset. Don't wait for a notification that will never come.

Freeze your credit at all three bureaus. This is the single most useful step.

A credit freeze prevents anyone from opening new accounts in your name. It is free, permanent until you lift it, and does not affect your credit score.

Get an IRS Identity Protection PIN.

  • Go to irs.gov/ippin
  • The IRS will mail you a new six-digit PIN every January
  • No PIN, no e-filed return accepted. That blocks most tax refund fraud in your name

File your taxes early every year. The earlier you file, the less window a fraudster has to file a fake return and claim your refund.

Lock your SSN through the Social Security Administration.

  • Create a my Social Security account if you have not already
  • SSA now offers an "SSN Lock" feature that blocks changes to your SSN record without your consent
  • Review your earnings record. Mismatches mean someone has worked under your SSN

Watch for fraud alerts and review your medical EOBs.

  • Read every Explanation of Benefits from your health insurer
  • Any provider visit you do not recognize is medical identity theft
  • Report suspected medical identity theft to your insurer and to the FTC at IdentityTheft.gov

If you receive a breach notice or fraud alert:

  • Save it. It documents the breach for any future legal action.
  • File an FTC report at IdentityTheft.gov. The official Identity Theft Report unlocks certain legal protections.
  • For SSN misuse, file a police report. Local departments increasingly have a cybercrime or identity theft liaison.

The Bigger Picture

The data broker ecosystem sits behind this breach. You did not sign up for National Public Data. You probably never agreed to their privacy policy. A background check service paid a subscription fee and your SSN went into their database, scraped from non-public records without your knowledge or consent [1].

You cannot opt out of a system you never knew existed. That is by design. Data brokers sell the absence of consent.

Two things changed after this breach. First, the bankruptcy dismissal. A company with no insurance covering a breach cannot use Chapter 11 to hide. That precedent will matter for every data broker that gets popped. Second, the multistate AG lawsuit. Florida plus 24 other states suing a defunct company might look symbolic, but it sets up the next case where the company is solvent and still selling data.

Congressman Torres' recommendation was simpler: prohibit data aggregators from collecting SSNs at all [5]. That is the only fix that addresses the structural problem. Until then, your SSN is in someone else's database and the only defense is the credit freeze.

References

  1. Bloomberg Law, Personal Data of 3 Billion People Stolen in Hack, Suit Says (August 2024)
  2. ClassAction.org, Florida Attorney General Sues National Public Data Over Data Breach (August 2025)
  3. SecurityWeek, Brazilian Police Arrest Notorious Hacker USDoD (October 2024)
  4. CyberScoop, Brazil's Federal Police arrest alleged National Public Data hacker (October 2024)
  5. Rep. Ritchie Torres, Investigative Report on the National Public Data Breach (September 2024)
  6. Reed Smith, A recent bankruptcy case demonstrates the increasing risks and expectations around cyber (May 2025)
  7. UpGuard, Biggest Data Breaches in US History (July 2026)