{"id":160221,"date":"2024-08-22T07:00:57","date_gmt":"2024-08-22T11:00:57","guid":{"rendered":"https:\/\/valorguardians.com\/blog\/?p=160221"},"modified":"2024-08-20T20:21:10","modified_gmt":"2024-08-21T00:21:10","slug":"massive-data-breach-listen-up","status":"publish","type":"post","link":"https:\/\/www.azuse.cloud\/?p=160221","title":{"rendered":"Massive Data Breach &#8211; listen up!"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-160222 aligncenter\" src=\"https:\/\/www.azuse.cloud\/wp-content\/uploads\/2024\/08\/th-458924136-300x141.jpg\" alt=\"\" width=\"300\" height=\"141\" srcset=\"https:\/\/www.azuse.cloud\/wp-content\/uploads\/2024\/08\/th-458924136-300x141.jpg 300w, https:\/\/www.azuse.cloud\/wp-content\/uploads\/2024\/08\/th-458924136.jpg 474w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>National Public Data is not a household name, maybe, but it should be. They&#8217;re a &#8216;data aggregator&#8217;, used by banks, credit card companies&#8230;these are the folks who keep your data for other folks to access. One would think that sensitive data should be secure, no? Well&#8230;\u00a0 no.<\/p>\n<blockquote>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">statement<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that offered little details, the Coral Springs, Fla.-based company acknowledged what numerous others have reported in recent days about a &#8220;third-party bad actor&#8221; accessing data from NPDs databases sometime in April 2024. The company described the data which the threat actor accessed as including full names, email addresses, phone numbers, Social Security numbers, and mailing addresses belonging to an unknown number of people.<\/span><\/p>\n<p data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NPD is a data aggregator that claims businesses, private investigators, human resources departments, and staffing agencies use its data for background checks, to obtain criminal records and other uses.<\/span><\/p>\n<\/blockquote>\n<p data-testid=\"content-paragraph\">&#8220;Unknown number&#8221;&#8230;try almost 3 BILLION lines of records. That&#8217;s not 3 billion records, thankfully, but still millions upon millions of records. Who do they think they are, VA?<\/p>\n<blockquote>\n<p data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">News of the breach has been circulating since at least April when <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dark Web Intelligence<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> posted on X about &#8220;USDoD&#8221; a hacker with a reputation for previous data heists, having obtained a database from NPD containing some 200 gigabytes of personal information on residents in the US, UK, and Canada. The threat actor claimed the NPD database contained some 2.9 billon rows of records. <\/span><\/p>\n<p data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">X-underground, a community focused on malware and cybercrime, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">reviewed the dataset<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and assessed the leaked data as being &#8220;real and accurate&#8221; and containing the first name, last name, SSN, current address, and addresses for individuals going back over 30 years. <\/span><\/p>\n<p data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Troy Hunt, who maintains the &#8220;Have I Been Pwned&#8221; site, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">reported finding 134 million unique<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> email addresses and millions of rows of criminal records. <\/span><\/p>\n<\/blockquote>\n<p data-testid=\"content-paragraph\">They say that this data was &#8216;scraped&#8217; by NPD from many sources &#8211; I could believe that. I tested my name and birth year and it found multiple listings (even some addresses I had completely forgotten) but at least 25% of the Socials they showed were incorrect. <a href=\"https:\/\/npd.pentester.com\/\">pentester <\/a>has a tester similar to the one I used. I would strongly suggest testing to see if your data was leaked. If so, it is suggesting freezing your credit at the various credit reporting entities is the best response.<\/p>\n<p data-testid=\"content-paragraph\">Of course, the root problem is that we lazily allow the government and financial institutions to use an extremely INsecure number as the basis for all transaction &#8211; our Social Securiy Numbers. They were never intended to be a form of financial ID, and cases like this show the need for the Feds and banks to get off their collective derrieres and bloody well DO something to replace them.<\/p>\n<blockquote>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;NPD should have done lots of things better but there is one thing that&#8217;s on us: it&#8217;s past time to get rid of SSN,&#8221; says Ambuj Kumar, CEO of Simbian. Replacing SSN with a digital ID similar to what&#8217;s used in cryptography and in a technology like Apple Wallet is relatively easy and straightforward he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The impediments are purely psychological and inertia,&#8221; Kumar says. &#8220;Think of a digital ID as a government issued credit card number that is known only to the government and the individual,&#8221; he notes. &#8220;When applying for a mortgage, for example, a token is generated from the original number and this new number is shared with the bank. If there is a breach at the bank, the original number is still safe since the bank only saw the token.&#8221;<a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/national-public-data-confirms-massive-breach\">DarkReading<\/a><\/span><\/p>\n<\/blockquote>\n<p data-testid=\"content-paragraph\">Makes sense to me.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; National Public Data is not a household name, maybe, but it should be. They&#8217;re a &hellip; <a title=\"Massive Data Breach &#8211; listen up!\" class=\"hm-read-more\" href=\"https:\/\/www.azuse.cloud\/?p=160221\"><span class=\"screen-reader-text\">Massive Data Breach &#8211; listen up!<\/span>Read more<\/a><\/p>\n","protected":false},"author":668,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185,11,688],"tags":[],"class_list":["post-160221","post","type-post","status-publish","format-standard","hentry","category-crime","category-economy","category-money"],"_links":{"self":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/160221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/users\/668"}],"replies":[{"embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=160221"}],"version-history":[{"count":0,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=\/wp\/v2\/posts\/160221\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=160221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=160221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.azuse.cloud\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=160221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}