Unable to load image

Burgers prove they're still number 1 at everything :marseysaluteusa: as every single Social Security Number gets leaked :marseyaware:

https://www.bleepingcomputer.com/news/security/hackers-leak-27-billion-data-records-with-social-security-numbers/

SUMMARY

In April, hacking group USDoD attempted to sell 2.9 billion records which included personal data on everyone in the US, UK and Canada. Almost 2.7 billion records of personal information for people in the United States were leaked on a hacking forum, exposing names, social security numbers, all known physical addresses, and possible aliases.


The data allegedly comes from National Public Data, a company that collects and sells access to personal data for use in background checks, to obtain criminal records, and for private investigators.

National Public Data is believed to scrape this information from public sources to compile individual user profiles for people in the US and other countries.

In April, a threat actor known as USDoD claimed to be selling 2.9 billion records containing the personal data of people in the US, UK, and Canada that was stolen from National Public Data.

At the time, the threat actor attempted to sell the data for $3.5 million and claimed it contained records for every person in the three countries.

USDoD is a known threat actor who was previously linked to an attempted sale of InfraGard's user database in December 2023 for $50,000.

Since then, various threat actors have released partial copies of the data, with each leak sharing a different number of records and, in some cases, different data.

On August 6th, a threat actor known as "Fenice" leaked the most complete version of the stolen National Public Data data for free on the Breached hacking forum.

However, Fenice says the data breach was conducted by another threat actor named "SXUL," rather than USDoD.

The leaked data consists of two text files totaling 277GB and containing nearly 2.7 billion plaintext records, rather than the original 2.9 billion number originally shared by USDoD.

While BleepingComputer can't confirm if this leak contains the data for every person in the US, numerous people have confirmed to us that it included their and family members' legitimate information, including those who are deceased.

Each record consists of the following information - a person's name, mailing addresses, and social security number, with some records including additional information, like other names associated with the person. None of this data is encrypted.

Previously leaked samples of this data also included phone numbers and email addresses, but these are not included in this 2.7 billion record leak.

It is important to note that a person will have multiple records, one for each address they are known to have lived. This also means that this data breach did not impact 3 billion people as has been erroneously reported in many articles that did not properly research the data.

Some people have also told BleepingComputer that their social security numbers were associated with other people they don't know, so not all the information is accurate.

Finally, this data may be outdated, as it does not contain the current address for any of the people we checked, potentially indicating that the data was taken from an old backup.

The data breach has led to multiple class action lawsuits against Jerico Pictures, which is believed to be doing business as National Public Data, for not adequately protecting people's data.

If you live in the US, this data breach has likely leaked some of your personal information.

As the data contains hundreds of millions of social security numbers, it is suggested that you monitor your credit report for fraudulent activity and report it to the credit bureaus if detected.

Furthermore, as previously leaked samples also contained email addresses and phone numbers, you should be vigilant against phishing and SMS texts attempting to trick you into providing additional sensitive information.

44
Jump in the discussion.

No email address required.

It's just a number lmao you can just count to them

Jump in the discussion.

No email address required.

Ikr like they're only 9 digits, we already know every single one that will ever exist.

Jump in the discussion.

No email address required.

Neat. I guess the jeets will be calling me more than usual.


Krayon sexually assaulted his sister. https://i.rdrama.net/images/17118241526738973.webp https://i.rdrama.net/images/17118241426254768.webp https://i.rdrama.net/images/17156480765435808.webp

Jump in the discussion.

No email address required.

!codecels the future is gay and r-slurred

Jump in the discussion.

No email address required.

Oh what a relief! Now all the climate change asylum seekers can finally apply for jobs.

:#marseybeanrelieved:

Jump in the discussion.

No email address required.

!eurochads life fuel

https://media.tenor.com/1O-ZWP4-g28AAAAx/lost-confused.webp


https://media.tenor.com/s91B_Rm3fEQAAAAx/merry-christmas-to-all-my-facebook-anf-family-celebration.webp

Jump in the discussion.

No email address required.

!britbongs our social security numbers have been leaked :marseyitsover:

Jump in the discussion.

No email address required.

Average UK govt tech contract :marseybsod: :marseyjewofthesubcontinent:

Jump in the discussion.

No email address required.

I thought :marseymindblown: Bong social :marseyredcheck: security :marseyblart: numbers :marseysoypointtrips: are basically irrelevant :marseynothingburger: because you can't choose :marseytrolley: your own national :marseyauthright: healthcare :marseydoctor: provider and you can't access :marsey403: the pension funds without various other forms of ID.

Jump in the discussion.

No email address required.

download link plz, i wanna find my SSN Neighbor :3

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

222-34-2069

Jump in the discussion.

No email address required.

867-00-5309

Jump in the discussion.

No email address required.

Wow that's my grandma's SSN!

Jump in the discussion.

No email address required.

Not anymore :platypiratecaptain:

Jump in the discussion.

No email address required.

3 billion records / 330 million people = 10 records per person

name, an expired email address, an old phone number, five old addresses, and teh wrong social security number or whatever, and it's all publicly available already anyway?

:marseysleep:

Jump in the discussion.

No email address required.

SSNs shouldn't be public. :marseyshrug:

Jump in the discussion.

No email address required.

There should be no harm in having your SSN public because it was never intended to identify you.

Jump in the discussion.

No email address required.

:marseyxd:

Jump in the discussion.

No email address required.

It's the only way to uniquely designate a US citizen, though?

Jump in the discussion.

No email address required.

Nonsense, there's plenty of other ways they could do it. They could come up with their own ID number for their systems (and likely already do), plus I'm sure with all your other identifying info you're probably pretty darned unique (full name + address for example).

They use your SSN purely out of convenience and for literally no other reason. IMO it should be restricted to the social security bureau and it should be literally illegal for any non-government agency to ever require it.

Our lawmakers are unfortunately such kitties they'll never do it but we'd be fine.

Jump in the discussion.

No email address required.

Sure but if two independent entities want to compare notes about you they need to be sure they're talking about the same person

Jump in the discussion.

No email address required.

they got the wrong ssn for the people who checked according to the article

Jump in the discussion.

No email address required.

Having my SSN isn't supposed to be sufficient to open up 100 credit cards in my name :taytantrum:

At least I can freeze my credit report so that nobody will let me open an account

Jump in the discussion.

No email address required.

What can you realistically do with someone's SSN? Like, that and a name, no other information? I didn't think much.

Jump in the discussion.

No email address required.

You could probably cancel my internet and phone service. If I didnt have 2fa with my bank you could get a new debit card delivered

Jump in the discussion.

No email address required.

All those places now have 2FA now surely.

I'm just aware that at least one poster here, probably more in Groomercord, has posted their SSN.

Jump in the discussion.

No email address required.

Brave souls. My BIPOCword usage/salary product is far too high to risk that.

Jump in the discussion.

No email address required.

Each record consists of the following information - a person's name, mailing addresses, and social security number, with some records including additional information, like other names associated with the person. None of this data is encrypted.

Previously leaked samples of this data also included phone numbers and email addresses, but these are not included in this 2.7 billion record leak.

They don't say but even if the data set doesn't contain it, it wouldn't be difficult to get somebody's birth date with all this information (aren't vital records public?). With your full name, address, SSN, and birth date, you can definitely open up lines of credit in somebody else's name.

Jump in the discussion.

No email address required.

If you've ever had health insurance through a company your number had already been leaked to the internet. Excel files of thousands of employees name, dob, ssn, and family get emailed back and forth copied among 80 people who fall for every phishing attempt ever.

And that's assuming it wasn't leaked through the workers comp audit.

Jump in the discussion.

No email address required.

Quick question @box, based on your name, can I assume you come in a box?

Jump in the discussion.

No email address required.

https://media.tenor.com/1KqQHsDGmX4AAAAx/cats-cat.webp

Jump in the discussion.

No email address required.

You ruined my set-up :marseycry:

Jump in the discussion.

No email address required.

https://media.tenor.com/pVQk9bj54bQAAAAx/scratching-koala-koala.webp

Jump in the discussion.

No email address required.

God you're ugly.

Jump in the discussion.

No email address required.

:marseycryinglaptop:

Jump in the discussion.

No email address required.

Honestly feels kind of wholesome that we're all in this together :marseybow:

Jump in the discussion.

No email address required.

good fricking god :marseyyikes:

Jump in the discussion.

No email address required.

I like how I can't find this on the front page of Reddit.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.