Security

Cyber-crime

That cyber-heist of 2.9B personal records? There's a class-action lawsuit looming for that

Background check biz accused of negligence


Updated A lawsuit has accused a Florida data broker of carelessly failing to secure billions of records of people's private information, which was subsequently stolen from the biz and sold on an online criminal marketplace.

California resident Christopher Hofmann filed the potential class-action complaint against Jerico Pictures, doing business as National Public Data, a Coral Springs-based firm that provides APIs so that companies can perform things like background checks on people and look up folks' criminal records. As such National Public Data holds a lot of highly personal information, which ended up being stolen in a cyberattack.

According to the suit [PDF], filed in a southern Florida federal district court, Hofmann is one of the individuals whose sensitive information was pilfered by crooks and then put up for sale for $3.5 million on an underworld forum in April.

If the thieves are to be believed, the database included 2.9 billion records on all US, Canadian, and British citizens, and included their full names, addresses, and address history going back at least three decades, social security numbers, and the names of their parents, siblings, and relatives, some of whom have been dead for nearly 20 years. 

Compromised, published, and then sold on the dark web, due to defendant's negligent and/or careless acts

It's believed that a digital thief using the handle SXUL exfiltrated the files from National Public Data and then passed it along to a criminal gang that goes by USDoD, who acted as the data broker for the stolen goods and assured would-be buyers that none of the purloined info was scraped from public sources.

Hofmann, in the August 1 lawsuit, says he received a notice from his identity-theft protection service around July 24 notifying him that his personally identifiable information (PII) had ended up on the dark web. 

He claims he never provided this sensitive info to National Public Data and "believes that his PII was scraped from non-public sources by defendant."

In fact, the data broker scrapes PII of "potentially billions" of people, none of whom ever provided their information to National Public Data, the lawsuit, which references The Register's reporting, alleges. "By obtaining, collecting, using, and deriving a benefit from the PII of plaintiff and class members, defendant assumed legal and equitable duties to those individuals to protect and safeguard that information from unauthorized access and intrusion," it notes.

And this is where National Public Data, allegedly failed miserably. The Florida firm stands accused of negligently storing the database in a way that was accessible to the thieves, without encrypting its contents nor redacting any of the individuals' sensitive information.

"This unencrypted, unredacted PII was compromised, published, and then sold on the dark web, due to defendant's negligent and/or careless acts and omissions and their utter failure to protect customers' sensitive data," the legal complaint alleges. 

And the stolen data, which can be used for identity theft, digital fraud, and even physical stalking and harassment, presents a "continuing risk to the victims" that "will remain for their respective lifetimes," the lawsuit claims.

Hofmann, on behalf of potentially millions of other plaintiffs, has asked the court to require National Public Data to destroy all personal information belonging to the class-action members and use encryption, among other data protection methods in the future.

The lawsuit also wants the background-check firm to implement an infosec program and employee training to help protect people's confidentiality, and it asks the judge to require that National Public Data hire third-party auditors and penetration testers to ensure that criminals can't break into its network and steal any more massive databases.

Additionally, it seeks unspecified monetary relief for the data theft victims, including "actual, statutory, nominal, and consequential damages."

We have sought comment from National Public Data. ®

Updated to add on August 12

Though there have been some leaks of portions of the stolen National Public Data collection here and there, someone has now started distributing for free via the dark web what's claimed to be 2.7 billion records from that collection, totaling nearly 280GB. This would include people's names, addresses, and Social Security Numbers.

Send us news
11 Comments

Drug-screening biz DISA took a year to disclose security breach affecting millions

If there's something nasty on your employment record, extortion scum could come calling

Microsoft names alleged credential-snatching 'Azure Abuse Enterprise' operators

Crew helped lowlifes generate X-rated celeb deepfakes using Redmond's OpenAI-powered cloud – claim

Malware variants that target operational tech systems are very rare – but 2 were found last year

Fuxnet and FrostyGoop were both used in the Russia-Ukraine war

Ghost ransomware crew continues to haunt IT depts with scarily bad infosec

FBI and CISA issue reminder - deep sigh - about the importance of patching and backups

Feds: Army soldier suspected of AT&T heist Googled ‘can hacking be treason,’ ‘defecting to Russia’

FYI: What NOT to search after committing a crime

With millions upon millions of victims, scale of unstoppable info-stealer malware laid bare

244M purloined passwords added to Have I Been Pwned thanks to govt tip-off

Xi know what you did last summer: China was all up in Republicans' email, says book

Of course, Microsoft is in the mix, isn't it

China's Silver Fox spoofs medical imaging apps to hijack patients' computers

Sly like a PRC cyberattack

Snake Keylogger slithers into Windows, evades detection with AutoIt-compiled payload

Because stealing your credentials, banking info, and IP just wasn’t enough

SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN

Roses are red, violets are blue, CVE-2024-53704 is sweet for a ransomware crew

Chinese spies suspected of 'moonlighting' as tawdry ransomware crooks

Some employees steal sticky notes, others 'borrow' malicious code

If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish

Roses aren't cheap, violets are dear, now all your access token are belong to Vladimir