Your Social Security Number Leaked on the Dark Web

Your Social Security Number Leaked on the Dark Web

Author: The most important weekly tech news + solutions. September 24, 2024 Duration: 5:33

In a year already marked by massive cybersecurity incidents, another major data breach has come to light, affecting millions of Americans. National Public Data (NPD), a background check company owned by Jerico Pictures Inc., recently disclosed that it fell victim to two separate cyberattacks in 2024, with the first occurring in April.

According to NPD's statement, the stolen data includes highly sensitive personal information like names, Social Security numbers, phone numbers, email addresses, and mailing addresses. While the company has not specified the exact number of individuals affected, a lawsuit filed in the US District Court for the Southern District of Florida suggests the impact could be staggering, potentially reaching millions of affected individuals.

In response to media inquiries, NPD, led by CEO Salvatore Verini, has removed detailed information about its databases from its website and has not provided public comment.

Malware research group vx-underground said that they could “...confirm the data present in it is real and accurate...We searched up several individuals who consented to having their information looked up...It also allowed us to find their parents, and nearest siblings. We were able to identify someones [sic] parents, deceased relatives, Uncles, Aunts, and Cousins,”. However, independent investigations by TechCrunch revealed a combination of correct and inconsistent information that is publicly available.

The cybercriminal group known as USDoD allegedly put the stolen data up for sale on the dark web for $3.5 million, highlighting the immediate risks posed by this breach. The self proclaimed hackvist group has been around in the underworld since at least 2020. They once bragged about pulling off a hack-and-leak operation on a major professional networking platform, only to have industry experts call out their bluff.

USDoD's modus operandi typically involves social engineering tactics to steal sensitive data, a method that's proven pretty effective in both their hacktivist escapades and for-profit schemes. In the past couple of years, they've grown more ambitious, focusing on high-profile targeted intrusion campaigns like the now infamous Crowdstrike incident.

Historical Context

If this story feels like déjà vu, you're not wrong. Both the frequency and scale of cyberattacks are increasing. We're barely halfway through 2024, and we've already seen AT&T and Ticketmaster get hit by large scale cyber attacks. According to the Identity Theft Resource Center, more than 1,500 data breaches occurred in the first half of 2024 alone, impacting approximately 1 billion people.

The scale of the NPD breach draws comparisons to other significant data breaches in recent history, such as the 2017 Equifax breach that exposed the personal information of 147 million Americans, and the Yahoo breach disclosed in 2016 that affected 3 billion user accounts.

Implications and Response

NPD stated that they are cooperating with law enforcement and have implemented additional security measures to prevent future incidents. However, the company's delayed public response – nearly two weeks after some individuals were notified through third-party identity theft protection services – has raised questions about corporate responsibility in the face of such breaches.

Finding Out If You Were In The Breach

Pentester.com offers a service to look your information up in the NPD data breach. You can check to see if you’re in it. Please make sure to read Pentester’s terms of service.

https://npd.pentester.com/

Additionally, if you’re concerned about any of your email accounts or passwords you can check haveibeenpwned to see if your accounts have been leaked.

Keep your eyes peeled for phishy emails and texts. Don’t click links from unknown senders even if there’s a supposed emergency or it’s a hacker claiming they have your password.

Many have also advocated freezing credit cards so that cybercriminals can’t apply for loans under your newly leaked SSN data. The NPD breach is just another reminder that you can never trust any of your information in the hands of Big Tech and Big Data.

Sources

https://www.cnet.com/personal-finance/identity-theft/social-security-numbers-and-personal-data-of-billions-breached-in-national-public-data-cyber-attack-heres-what-you-need-to-know/

https://techcrunch.com/2024/06/11/the-mystery-of-an-alleged-data-brokers-data-breach/

https://www.crowdstrike.com/blog/hacktivist-usdod-claims-to-have-leaked-threat-actor-list/

https://www.scmagazine.com/brief/crowdstrike-ioc-list-exposed-by-usdod-threat-actor

https://tbot.substack.com/p/did-the-at-and-t-hack-uncover-a-surveillance

https://help.ticketmaster.com/hc/en-us/articles/26110487861137-Ticketmaster-Data-Security-Incident

https://www.idtheftcenter.org/wp-content/uploads/2024/01/ITRC_2023-Annual-Data-Breach-Report.pdf

https://www.ftc.gov/enforcement/refunds/equifax-data-breach-settlement

https://www.darkreading.com/cyberattacks-data-breaches/deconstructing-the-2016-yahoo-security-breach



This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit tbot.substack.com/subscribe

Hakeem Anwar hosts The #TBOT Show, a weekly podcast dedicated to cutting through the noise of the tech world. Instead of just reporting headlines, this show focuses on the technology news that actually shapes your daily routine, privacy, and digital freedom, explaining why it matters in clear terms. Each episode is designed to be concise and actionable, wrapping up in under twenty minutes. You’ll hear informed analysis and straightforward recommendations on how to navigate the week’s developments. True to its mission, every installment also provides a practical takeaway: this might be a powerful open-source tool you can use, a privacy-enhancing skill to learn, or a sustainable tech solution to implement. It’s a blend of necessary context and usable insight, making it a resource for anyone who wants to understand and take back control of their tech life. Tune in for a focused, efficient update that prioritizes depth over duration, ensuring you stay informed without being overwhelmed. This podcast delivers exactly what its author promises: the most important weekly tech news paired with tangible solutions.
Author: Language: English Episodes: 80

The #TBOT Show with Hakeem Anwar
Podcast Episodes
How a Zero-Day Attack Targeted an Activist [not-audio_url] [/not-audio_url]

Duration: 4:16
This story of an activist in the UAE shows the sophistication of zero-day exploits. After jail time and surveillance, he received a Pegasus link disguised as info on detainees. Instead of clicking, he sent it to Citizen…
⚠️ What to do if cell service requires digital ID — FOSS War Room [not-audio_url] [/not-audio_url]

Duration: 1:41
At the Parallel Society 2026 “FOSS War Room,” we war‑gamed five imminent tech‑freedom disasters and gathered the sharpest minds to sketch real‑world solutions.Scenario: Starting July 2026, Mexico will block any mobile li…
#TBOT 16: Digital ID in North America [not-audio_url] [/not-audio_url]

Duration: 30:08
We’re kicking off a 6-part series on Digital ID around the world — starting with North America. From facial recognition at borders to national ID frameworks quietly forming behind the scenes, this episode dives into how…