pwshub.com

National Public Data says only 1.3M affected by breach

The data broker at the center of what may become one of the more significant breaches of the year is telling officials that just 1.3 million people were affected.

In any normal scenario, the news of a leak affecting 1.3 million people would be staggering, but this one is an oddity since many investigators previously put the number far, far higher in recent weeks.

Florida-based National Public Data (NPD) confirmed the number of affected individuals on Friday via a filing with Maine's attorney general. Said filings require organizations to list the total number of affected individuals and separately the number affected in Maine alone.

The digital break-in, NPD said, took place in December 2023 but it acknowledged that leaks of this data started in April this year, continuing throughout the summer.

Those leaks came at the hands of a criminal who uses the moniker USDoD. They began selling a stolen database allegedly comprised of 2.9 billion lines of data, supposedly concerning US, Canadian, and British citizens, for $3.5 million in April.

Troy Hunt, venerable infosec expert and maintainer of HaveIBeenPwned, looked into the database and found 134 million unique email addresses. So, unless every one of the 1.3 million affected people had 100 email addresses, which is pretty unlikely, there is a chance that more people are affected than what NPD told Maine's AG.

The situation doesn't come without precedent either. It's not uncommon for organizations disclosing data breaches with US state officials to update those filings down the line as investigations into potentially compromised data continue.

It happened with Financial Business and Consumer Solutions (FBCS) in June, when it updated its notification to reflect the much larger scope. After previously disclosing that 2 million people were affected, it later upped this to 3.2 million.

"There appears to have been a data security incident that may have involved some of your personal information," letters from NPD to affected individuals read. "The incident is believed to have involved a third-party bad actor that was trying to hack into data in late December 2023, with potential leaks of certain data in April 2024 and summer 2024. We conducted an investigation and subsequent information has come to light. 

"The information that was suspected of being breached contained name, email address, phone number, social security number, and mailing address(es).

"We cooperated with law enforcement and governmental investigators and conducted a review of the potentially affected records and will try to notify you if there are further significant developments applicable to you. We have also implemented additional security measures in efforts to prevent the reoccurrence of such a breach and to protect our systems."

  • After nearly 3B personal records leak online, Florida data broker confirms it was ransacked by cyber-thieves
  • Attacker steals personal data of 200K+ people with links to Arizona tech school
  • Breaking the economy of trust: How busts affect malware gangs
  • UK Electoral Commission slapped for basic cybersecurity fails

The same wording was used in a breach disclosure web page that NPD stood up last week, which has reignited interest in the incident. The page didn't, however, state the number of affected individuals like the filing with Maine's AG.

In addition to the 134 million unique email addresses, Hunt also discovered that criminal record data appeared to be included. 70 million of them, in fact – something NPD didn't include in its disclosure letters.

Atlas Data Privacy, a business that offers clients a service that removes their data from data brokerages like NPD, also found 272 million unique social security numbers littered among the vast trove of data.

It was discovered that these services do indeed work, since no one who registered for them had their data mixed up in the leak, and that a decent portion of the data concerns people who are no longer alive. Millions of records belonging to people who would be older than 120 years featured, for example, with the average age of affected individuals standing at 80. ®

Source: theregister.com

Related stories
1 month ago - If your Social Security number is included in the reported massive data theft of 2.9 billion records of people, you can take steps to secure your personal information.
3 weeks ago - 2.9 billion records were reportedly stolen in a massive data theft. How you can see if your Social Security number is part of the hack and how to secure your personal information.
3 weeks ago - Here's how you can check if your Social Security number is part of the massive data theft and secure your personal information.
2 weeks ago - How you can check if your Social Security number is part of the data theft, and how to secure your personal information.
2 weeks ago - Here's how you can check if your Social Security number was stolen in the data theft, and how to secure your personal information.
Other stories
42 minutes ago - Experts at the Netherlands Institute for Radio Astronomy (ASTRON) claim that second-generation, or "V2," Mini Starlink satellites emit interference that is a staggering 32 times stronger than that from previous models. Director Jessica...
43 minutes ago - The PKfail incident shocked the computer industry, exposing a deeply hidden flaw within the core of modern firmware infrastructure. The researchers who uncovered the issue have returned with new data, offering a more realistic assessment...
43 minutes ago - Nighttime anxiety can really mess up your ability to sleep at night. Here's what you can do about it right now.
43 minutes ago - With spectacular visuals and incredible combat, I cannot wait for Veilguard to launch on Oct. 31.
43 minutes ago - Finding the perfect pair of glasses is difficult, but here's how to do so while considering your face shape, skin tone, lifestyle and personality.