About 134 million unique emails sat in later National Public Data dumps after 2024 headlines of “3 billion people.” This row is people-search identity data, not passwords, and it is flagged unverified. Check whether your address is in the file, then treat a credit freeze as the first job.
Quick answer — was National Public Data breached?
This page is the 2024 National Public Data people-search exposure. Sellers claimed about 2.9 billion rows; this catalog lists about 134 million unique emails plus names, phones, addresses, dates of birth, and government-issued IDs. Passwords were not included. The row is unverified. A match means your address appeared in that later corpus — not proof that your Social Security number leaked. Check if you were affected.
What happened in the National Public Data data breach?
This catalog row is a people-search / background-check exposure — not a password dump, and not a site you likely signed up for. In April 2024 a seller using the name USDoD offered what they called about 2.9 billion National Public Data records for $3.5 million. Headlines said “3 billion people.” That figure is a row count, not 3 billion unique humans. This lookup lists about 134 million unique email addresses from later partial dumps. The listed types are names, emails, phone numbers, physical addresses, dates of birth, genders, and government-issued IDs. Passwords are not on this row. Industry-standard breach data sources flag the row as unverified: the origin and accuracy of the email-bearing files remain in question.
The first widely reviewed files were identity records — names, addresses, and US Social Security numbers — and those files had no email addresses. Later archives mixed in about 134 million unique inboxes plus a jumble of other personal fields. A match on this page means your address appeared in that later corpus. It is not proof that your Social Security number sat in the first SSN file. Still, names, addresses, phones, and government IDs are the identity playbook: new-account fraud, tax-refund fraud, and phishing that already knows where you live. Changing a password does not unsay a published identity.
National Public Data, a Florida background-check aggregator operated by Jerico Pictures, told reporters in August 2024 that the intrusion dated to December 2023. Krebs on Security reported that a sister site left backend passwords in a file on its homepage. Jerico Pictures filed Chapter 11 on 2 October 2024; the case was dismissed on 31 October 2024. Many people in these files never knowingly gave the company their data. Learn more about what a data breach means for you.
Why was the National Public Data breach so dangerous?
The first widely reviewed files were identity records — names, addresses, and US Social Security numbers — and those files had no email addresses. Later archives mixed in about 134 million unique inboxes plus a jumble of other personal fields. A match on this page means your address appeared in that later corpus. It is not proof that your Social Security number sat in the first SSN file. Still, names, addresses, phones, and government IDs are the identity playbook: new-account fraud, tax-refund fraud, and phishing that already knows where you live. Changing a password does not unsay a published identity.
Yes, for the identity playbook, not the password playbook. Social Security numbers, addresses, and dates of birth do not expire. As of 2026 the files are old, widely copied, and still useful for new-account fraud. A credit freeze at the three major US bureaus is the work — not “logging into National Public Data,” which most people never did. A password change alone does not fix this match.check whether your email was exposed in this breach.
What data was stolen in the National Public Data breach?
Dates of birth — used to verify identity for account takeover and fraud
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Genders — may be combined with other breach data to build a profile for targeted attacks
Government issued IDs — enables full identity theft including fraudulent credit applications
Names — used to build profiles and target you with personalised scams
Phone numbers — enables SIM-swapping attacks and targeted SMS phishing
Physical addresses — combined with other data, used for identity theft and physical fraud
Timeline of the National Public Data breach
December 2023
National Public Data later told reporters the intrusion dated to a December 2023 security incident
8–9 April 2024
A seller using the name USDoD offers an alleged National Public Data database — about 2.9 billion records — for $3.5 million. This catalog dates the row 9 April 2024
June–July 2024
SSN-heavy files circulate; researchers and people who checked samples confirm real names, addresses, and Social Security numbers, including deceased relatives. Those first files have no emails
August 2024
Larger “partial” dumps appear; about 134 million unique emails are counted. National Public Data acknowledges an intrusion. Class actions and state claims follow
13 August 2024
The email corpus is added to public breach-notification catalogs as unverified — origin and accuracy of the later files remain in question
2 October 2024
Jerico Pictures, doing business as National Public Data, files Chapter 11 in the Southern District of Florida; the case is dismissed on 31 October 2024
2024–2026
Copies remain in identity-fraud and people-search kits. A match is still the freeze-and-watch playbook
Is the National Public Data breach still dangerous in 2026?
Yes, for the identity playbook, not the password playbook. Social Security numbers, addresses, and dates of birth do not expire. As of 2026 the files are old, widely copied, and still useful for new-account fraud. A credit freeze at the three major US bureaus is the work — not “logging into National Public Data,” which most people never did. A password change alone does not fix this match.
Government IDs and home addresses do not expire. A freeze ages new-account fraud out of your life. Learn how long stolen data stays dangerous.
What is this National Public Data row — and what is it not?
National Public Data sold background checks and people-search access to investigators, resellers, and apps. It hoovered public records and broker files. You did not need an account there for a row to exist. That is why a match can surprise people who never heard the name.
Two files, two jobs. Public analysis of the first SSN-heavy dump found billions of rows, lots of repeats, and no emails. Later “partial” archives — including a large 27-part set — contained about 134 million unique email addresses and a messy mix of other personal fields. Some rows next to a real inbox were wrong. Industry-standard breach data sources loaded the email corpus as unverified for that reason.
This is not a password breach. It is not Equifax 2017, and it is not a company you can log into to “reset National Public Data.” Do not invent a password leak from this match. Do not read “3 billion people” as 3 billion unique Social Security numbers. Krebs and others advised a credit freeze because identity data of this class is already cheap and widely sold.
- This row — later NPD-attributed dumps. ~134 million unique emails. Names, phones, addresses, dates of birth, government IDs. Unverified.
- The first SSN-heavy file had no emails. A match here does not prove your SSN was in that file.
- A match is the identity playbook: freeze credit, watch tax and new-account fraud. Not a password reset.
What does an EmailLeaked National Public Data match mean?
If your address is in the later email corpus, EmailLeaked shows a named National Public Data match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2024 archives, and we do not crawl hidden markets live.
A match is not proof someone opened a loan in your name this week. It is evidence that the address — and often a name, phone, or address from that era — appeared in a file that has been public since 2024. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach and the identity / email-only playbook there. Shrink people-search copies with the data-broker opt-out guide. For a second public index, see free data breach checkers.
What to do if your email was in the National Public Data breach
Confirm the match and what was listed
Run the email check if you need the named incidents in one list. This National Public Data row lists identity fields, not passwords. That decides the playbook.
Check this email — freeFreeze credit at the three US bureaus
A freeze at Equifax, Experian, and TransUnion blocks most new-account fraud. It is free. It does not unsay the file. Check weekly free credit reports for accounts you did not open. If you file US taxes, consider an IRS Identity Protection PIN.
Treat unexpected “NPD / identity” mail as hostile
The file gives scammers a name next to an inbox and often a home address. Do not tap reset or “credit monitoring” links in surprise messages. Walk the account security checklist for recovery contacts and leftover logins.
Open the account checklistFollow the after-breach identity playbook
Use the first-hour and 24-hour lists, then the identity / email-only playbook — not the password-leak playbook unless a different incident also listed passwords.
Open the after-breach playbookShrink people-search listings
A leaked email plus a public broker page makes phishing more convincing. That is a separate job from a freeze. See the data broker opt-out guide for official forms.
Open data-broker opt-outsFrequently asked about the National Public Data breach
What is the National Public Data breach this page covers?
Did this breach include Social Security numbers?
I never used National Public Data — how can I be in it?
Should I change my passwords after a National Public Data match?
How does EmailLeaked show a National Public Data match?
Is National Public Data still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the National Public Data breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored