National Public Data

Medium

About 134 million unique emails sat in later National Public Data dumps after 2024 headlines of “3 billion people.” This row is people-search identity data, not passwords, and it is flagged unverified. Check whether your address is in the file, then treat a credit freeze as the first job.

134.0M
Records exposed
2024
Year
7
Data types
Free
To check
Check if you were affected — free

Quick answer — was National Public Data breached?

This page is the 2024 National Public Data people-search exposure. Sellers claimed about 2.9 billion rows; this catalog lists about 134 million unique emails plus names, phones, addresses, dates of birth, and government-issued IDs. Passwords were not included. The row is unverified. A match means your address appeared in that later corpus — not proof that your Social Security number leaked. Check if you were affected.

What happened in the National Public Data data breach?

This catalog row is a people-search / background-check exposure — not a password dump, and not a site you likely signed up for. In April 2024 a seller using the name USDoD offered what they called about 2.9 billion National Public Data records for $3.5 million. Headlines said “3 billion people.” That figure is a row count, not 3 billion unique humans. This lookup lists about 134 million unique email addresses from later partial dumps. The listed types are names, emails, phone numbers, physical addresses, dates of birth, genders, and government-issued IDs. Passwords are not on this row. Industry-standard breach data sources flag the row as unverified: the origin and accuracy of the email-bearing files remain in question.

The first widely reviewed files were identity records — names, addresses, and US Social Security numbers — and those files had no email addresses. Later archives mixed in about 134 million unique inboxes plus a jumble of other personal fields. A match on this page means your address appeared in that later corpus. It is not proof that your Social Security number sat in the first SSN file. Still, names, addresses, phones, and government IDs are the identity playbook: new-account fraud, tax-refund fraud, and phishing that already knows where you live. Changing a password does not unsay a published identity.

National Public Data, a Florida background-check aggregator operated by Jerico Pictures, told reporters in August 2024 that the intrusion dated to December 2023. Krebs on Security reported that a sister site left backend passwords in a file on its homepage. Jerico Pictures filed Chapter 11 on 2 October 2024; the case was dismissed on 31 October 2024. Many people in these files never knowingly gave the company their data. Learn more about what a data breach means for you.

Why was the National Public Data breach so dangerous?

The first widely reviewed files were identity records — names, addresses, and US Social Security numbers — and those files had no email addresses. Later archives mixed in about 134 million unique inboxes plus a jumble of other personal fields. A match on this page means your address appeared in that later corpus. It is not proof that your Social Security number sat in the first SSN file. Still, names, addresses, phones, and government IDs are the identity playbook: new-account fraud, tax-refund fraud, and phishing that already knows where you live. Changing a password does not unsay a published identity.

Yes, for the identity playbook, not the password playbook. Social Security numbers, addresses, and dates of birth do not expire. As of 2026 the files are old, widely copied, and still useful for new-account fraud. A credit freeze at the three major US bureaus is the work — not “logging into National Public Data,” which most people never did. A password change alone does not fix this match.check whether your email was exposed in this breach.

What data was stolen in the National Public Data breach?

Dates of birth Email addresses Genders Government issued IDs Names Phone numbers Physical addresses

Dates of birth — used to verify identity for account takeover and fraud

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Genders — may be combined with other breach data to build a profile for targeted attacks

Government issued IDs — enables full identity theft including fraudulent credit applications

Names — used to build profiles and target you with personalised scams

Phone numbers — enables SIM-swapping attacks and targeted SMS phishing

Physical addresses — combined with other data, used for identity theft and physical fraud

Timeline of the National Public Data breach

December 2023

National Public Data later told reporters the intrusion dated to a December 2023 security incident

8–9 April 2024

A seller using the name USDoD offers an alleged National Public Data database — about 2.9 billion records — for $3.5 million. This catalog dates the row 9 April 2024

June–July 2024

SSN-heavy files circulate; researchers and people who checked samples confirm real names, addresses, and Social Security numbers, including deceased relatives. Those first files have no emails

August 2024

Larger “partial” dumps appear; about 134 million unique emails are counted. National Public Data acknowledges an intrusion. Class actions and state claims follow

13 August 2024

The email corpus is added to public breach-notification catalogs as unverified — origin and accuracy of the later files remain in question

2 October 2024

Jerico Pictures, doing business as National Public Data, files Chapter 11 in the Southern District of Florida; the case is dismissed on 31 October 2024

2024–2026

Copies remain in identity-fraud and people-search kits. A match is still the freeze-and-watch playbook

Is the National Public Data breach still dangerous in 2026?

Yes, for the identity playbook, not the password playbook. Social Security numbers, addresses, and dates of birth do not expire. As of 2026 the files are old, widely copied, and still useful for new-account fraud. A credit freeze at the three major US bureaus is the work — not “logging into National Public Data,” which most people never did. A password change alone does not fix this match.

Government IDs and home addresses do not expire. A freeze ages new-account fraud out of your life. Learn how long stolen data stays dangerous.

What is this National Public Data row — and what is it not?

National Public Data sold background checks and people-search access to investigators, resellers, and apps. It hoovered public records and broker files. You did not need an account there for a row to exist. That is why a match can surprise people who never heard the name.

Two files, two jobs. Public analysis of the first SSN-heavy dump found billions of rows, lots of repeats, and no emails. Later “partial” archives — including a large 27-part set — contained about 134 million unique email addresses and a messy mix of other personal fields. Some rows next to a real inbox were wrong. Industry-standard breach data sources loaded the email corpus as unverified for that reason.

This is not a password breach. It is not Equifax 2017, and it is not a company you can log into to “reset National Public Data.” Do not invent a password leak from this match. Do not read “3 billion people” as 3 billion unique Social Security numbers. Krebs and others advised a credit freeze because identity data of this class is already cheap and widely sold.

  • This row — later NPD-attributed dumps. ~134 million unique emails. Names, phones, addresses, dates of birth, government IDs. Unverified.
  • The first SSN-heavy file had no emails. A match here does not prove your SSN was in that file.
  • A match is the identity playbook: freeze credit, watch tax and new-account fraud. Not a password reset.

What does an EmailLeaked National Public Data match mean?

If your address is in the later email corpus, EmailLeaked shows a named National Public Data match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2024 archives, and we do not crawl hidden markets live.

A match is not proof someone opened a loan in your name this week. It is evidence that the address — and often a name, phone, or address from that era — appeared in a file that has been public since 2024. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach and the identity / email-only playbook there. Shrink people-search copies with the data-broker opt-out guide. For a second public index, see free data breach checkers.

What to do if your email was in the National Public Data breach

1

Confirm the match and what was listed

Run the email check if you need the named incidents in one list. This National Public Data row lists identity fields, not passwords. That decides the playbook.

Check this email — free
2

Freeze credit at the three US bureaus

A freeze at Equifax, Experian, and TransUnion blocks most new-account fraud. It is free. It does not unsay the file. Check weekly free credit reports for accounts you did not open. If you file US taxes, consider an IRS Identity Protection PIN.

3

Treat unexpected “NPD / identity” mail as hostile

The file gives scammers a name next to an inbox and often a home address. Do not tap reset or “credit monitoring” links in surprise messages. Walk the account security checklist for recovery contacts and leftover logins.

Open the account checklist
4

Follow the after-breach identity playbook

Use the first-hour and 24-hour lists, then the identity / email-only playbook — not the password-leak playbook unless a different incident also listed passwords.

Open the after-breach playbook
5

Shrink people-search listings

A leaked email plus a public broker page makes phishing more convincing. That is a separate job from a freeze. See the data broker opt-out guide for official forms.

Open data-broker opt-outs

Frequently asked about the National Public Data breach

What is the National Public Data breach this page covers?
A 2024 people-search / background-check exposure. Sellers claimed about 2.9 billion rows. This catalog lists about 134 million unique emails plus names, phones, addresses, dates of birth, genders, and government-issued IDs. The row is unverified. Passwords were not included.
Did this breach include Social Security numbers?
Public reporting on the first dump described US Social Security numbers with names and addresses. That file had no emails. This lookup’s listed type is government-issued IDs. A match on your email does not prove your SSN was in the first file. Treat the identity playbook as the safe default anyway.
I never used National Public Data — how can I be in it?
You probably did not sign up. Aggregators collect public records and broker files. Many people in these dumps had never heard of the company. A match is still a published identity row, not a password leak.
Should I change my passwords after a National Public Data match?
Not because of this row. Passwords are not listed. Change leftovers only if another incident listed passwords. The first job here is a credit freeze and watching for new-account and tax fraud.
How does EmailLeaked show a National Public Data match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: unverified people-search identity data, typically emails and personal details, not passwords. We do not claim exclusive ownership of the files.
Is National Public Data still dangerous in 2026?
The company filed Chapter 11 in October 2024 and that case was dismissed the same month. The files do not expire. A freeze and skepticism toward unexpected identity mail are what age this row out of your life.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the National Public Data breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored