One of the largest data exposures ever alleged in a U.S. court centers on a background-check company few consumers had ever heard of. A proposed class-action lawsuit contends that a breach at National Public Data compromised personal records for nearly three billion people, including Social Security numbers, names, and addresses. The case, which surfaced in 2024, remains a reference point for the sheer scale of harm a single unsecured database can cause.
The company and the breach
National Public Data, which also operated under the name Jerico Pictures, was a Florida-based background-checking service that aggregated personal information from public and other sources. The documented account of the incident traces the intrusion to a third party that accessed the company’s data in late 2023, with leaks of information following in 2024. Because the firm compiled records on vast numbers of individuals, many of whom had no direct relationship with it, the breach swept in people who did not know the company held their data at all.
The stolen material was serious by any measure. Reports describe a cache including full names, addresses, Social Security numbers, and information about relatives. That combination is precisely what enables identity theft, because it links a durable government identifier to the contextual details needed to impersonate someone or open accounts in their name.
How the data surfaced publicly
The breach became widely known after a threat actor posted a database labeled “National Public Data” for sale on a criminal forum, claiming it contained records for roughly 2.9 billion individuals and seeking millions of dollars for it. Portions of the data later circulated more freely. Coverage from CBS News at the time walked readers through how to determine whether their information was likely included and what protective steps to consider.
The nearly three billion figure drew intense attention, though it warrants context. The number reflects the count of records in the database rather than three billion distinct living people, since the file could contain multiple, overlapping, or outdated entries per individual and information on deceased people. Even discounted, the exposure ranks among the most sweeping on record.
The class-action claim
The litigation argues that the company failed in its duty to protect the sensitive information it amassed. A report on the filing summarizes the core allegation: that the breach could have been prevented had the firm adequately secured its network against foreseeable cyberattacks. Plaintiffs in such cases typically seek damages and court-ordered improvements to data-security practices, and they often press the point that individuals never consented to having their information collected and stored in the first place.
The case highlights a structural problem with data brokers. Consumers cannot easily opt out of companies they never engaged, and they bear the downstream risk when those companies are breached. That mismatch, between who profits from aggregating personal data and who suffers when it leaks, has become a recurring theme in privacy litigation and a driver of calls for stronger regulation of the broker industry.
Why Social Security numbers raise the stakes
The exposure of Social Security numbers is what elevates the breach from a privacy nuisance to a lasting hazard. Unlike a password or even a credit card number, a Social Security number cannot be casually changed, and it functions as a master key across financial and government systems. Once it is circulating, the risk of identity theft persists indefinitely, which is why guidance from the Federal Trade Commission on identity theft stresses ongoing vigilance rather than a one-time fix.
Standard defensive measures include freezing credit files, which blocks new accounts from being opened without explicit authorization, and monitoring credit reports for unfamiliar activity. The FTC’s recovery resource provides step-by-step plans for people who suspect their information has been misused, including sample letters and checklists tailored to specific kinds of fraud.
A benchmark for breach scale
The persistence of the risk also changes how the breach should be understood over time. A stolen password can be reset in minutes, but a Social Security number that has entered criminal circulation stays useful to fraudsters for years, resurfacing in new scams long after the original incident fades from the news. That durability is why security specialists describe such exposures as a lasting condition to manage rather than a one-time emergency to survive, and why a credit freeze, which can be lifted and reinstated as needed, is often recommended as a standing precaution rather than a temporary measure.
The National Public Data case endures as a benchmark in discussions of large-scale breaches, cited whenever a new incident is measured against the biggest exposures on record. Running lists of major breaches, such as the tracker maintained at Tech.co, place it among the most significant events in recent memory precisely because of the number of records and the sensitivity of the data involved. Its lasting lesson is less about any single company than about the concentration of risk in firms that quietly assemble detailed profiles of nearly everyone, then become single points of failure when their defenses give way.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview