National Public Data (NPD)

National Public Data (NPD)

National Public Data (NPD), a people search site, suffered one of the largest data breaches in history over a year ago, exposing the personal information of 3 billion individuals. The breach involved highly sensitive data sourced from public records, property ownership databases, social media, and government agencies. Despite the site disappearing temporarily, it has since relaunched under Perfect Privacy LLC with the same business model allowing anyone to search for personal details (e.g., addresses, phone numbers, relatives' names) using just a name. The exposed data remains vulnerable to misuse for employment, housing, or credit decisions, while inaccuracies in profiles (e.g., outdated or incorrect information) persist. The breach highlights systemic risks, as the data can resurface across multiple platforms, enabling identity theft, phishing, and fraud. Users must manually opt out to remove their information, but the process is cumbersome and doesn’t guarantee permanent deletion from other data broker sites.

Source: https://www.foxnews.com/tech/notorious-people-search-site-returns-after-massive-breach

TPRM report: https://www.rankiteo.com/company/upstream-intelligence-inc

"id": "ups4671746090625",
"linkid": "upstream-intelligence-inc",
"type": "Breach",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '3 billion individuals',
                        'industry': 'information services',
                        'name': 'National Public Data (NPD)',
                        'type': 'data broker / people search site'},
                       {'customers_affected': '3 billion',
                        'industry': 'n/a',
                        'location': 'global',
                        'name': 'General Public (Individuals)',
                        'type': 'consumers'}],
 'customer_advisories': ['Instructions for opting out of NPD provided on their '
                         'website (nationalpublicdata.com/optout.html).',
                         'Recommendations for broader privacy protection '
                         'measures published by CyberGuy.com.'],
 'data_breach': {'data_exfiltration': ['yes, data exposed publicly'],
                 'number_of_records_exposed': '3 billion',
                 'personally_identifiable_information': ['names',
                                                         'addresses',
                                                         'phone numbers',
                                                         "relatives' names",
                                                         'property records',
                                                         'social media '
                                                         'profiles'],
                 'sensitivity_of_data': ['high (includes names, addresses, '
                                         "phone numbers, relatives' names, and "
                                         'other PII)'],
                 'type_of_data_compromised': ['personally identifiable '
                                              'information (PII)',
                                              'public records',
                                              'property ownership data',
                                              'social media data',
                                              'government agency data']},
 'description': 'National Public Data (NPD), a people search site, exposed the '
                'personal information of 3 billion individuals in one of the '
                'largest breaches in history. The site disappeared after the '
                'breach but has since relaunched under new ownership (Perfect '
                'Privacy LLC). The business model remains unchanged, allowing '
                'users to look up personal data with just a name. The data, '
                'sourced from public records, property ownership databases, '
                'social media, and government agencies, is claimed to be '
                'verified but often contains inaccuracies. Users can request '
                'removal of their data via an opt-out process, but the '
                'incident highlights broader privacy concerns as similar data '
                'may still be available on other platforms.',
 'impact': {'brand_reputation_impact': ['severe damage due to breach scale and '
                                        'relaunch under new ownership with '
                                        'same controversial business model'],
            'customer_complaints': ['likely high due to privacy concerns and '
                                    'inaccuracies in exposed data'],
            'data_compromised': ['personal information (names, addresses, '
                                 "phone numbers, relatives' names, property "
                                 'records, social media data)'],
            'identity_theft_risk': ['high, as exposed data can be used for '
                                    'phishing, fake loan applications, or '
                                    'identity theft'],
            'legal_liabilities': ['potential violations of Fair Credit '
                                  'Reporting Act (FCRA) due to misuse risks '
                                  'for employment, housing, or credit '
                                  'decisions'],
            'operational_impact': ['site temporarily disappeared from the '
                                   'internet'],
            'systems_affected': ['National Public Data (NPD) database']},
 'initial_access_broker': {'data_sold_on_dark_web': ['likely, given the scale '
                                                     'of the breach and the '
                                                     'nature of exposed PII']},
 'investigation_status': 'unclear; no response from NPD to media inquiries',
 'lessons_learned': ['Personal data exposed in breaches can resurface even '
                     'after removal from one platform.',
                     'Opt-out processes are insufficient for comprehensive '
                     'privacy protection due to data redundancy across '
                     'multiple platforms.',
                     'Regular monitoring of personal data across people search '
                     'sites is critical.',
                     'Stronger laws may be needed to regulate data brokers and '
                     'people search sites.',
                     'Individuals must proactively manage their digital '
                     'footprint, including social media privacy settings and '
                     'data removal requests.'],
 'post_incident_analysis': {'corrective_actions': ['Site relaunched under new '
                                                   'ownership (Perfect Privacy '
                                                   'LLC) but with no apparent '
                                                   'changes to data security '
                                                   'or business practices.',
                                                   'Opt-out process '
                                                   'implemented for individual '
                                                   'data removal requests.',
                                                   'No evidence of systemic '
                                                   'improvements to prevent '
                                                   'future breaches or misuse '
                                                   'of data.'],
                            'root_causes': ['Lack of adequate data protection '
                                            'measures for a database '
                                            'containing 3 billion records.',
                                            'Business model inherently risky '
                                            'for privacy (aggregating and '
                                            'selling PII without robust '
                                            'safeguards).',
                                            'Inaccurate or outdated data '
                                            'verification processes.']},
 'recommendations': ['Regularly check for personal data on people search sites '
                     '(e.g., NPD, Whitepages, Spokeo, Radaris) and request '
                     'removals.',
                     'Use personal data removal services to automate opt-outs '
                     'across multiple platforms.',
                     'Monitor financial accounts, credit reports, and online '
                     'activity for signs of identity theft or fraud.',
                     'Implement strong antivirus software to protect against '
                     'malware and phishing attempts.',
                     'Set up fraud alerts with credit bureaus and identity '
                     'theft monitoring services.',
                     'Request redactions or limitations on public records at '
                     'the source (e.g., county property, court, or voter '
                     'registration databases).',
                     'Tighten social media privacy settings to limit data '
                     'scraping by people search sites.',
                     'Consider using alias or disposable email addresses for '
                     'opt-out requests to avoid further data exposure.'],
 'references': [{'source': 'Fox News / CyberGuy.com',
                 'url': 'https://www.foxnews.com/tech/national-public-data-breach-returns-new-ownership-privacy-concerns'},
                {'source': 'CyberGuy.com - Data Removal Services',
                 'url': 'https://www.cyberguy.com/data-removal-services'},
                {'source': 'CyberGuy.com - Antivirus Protection '
                           'Recommendations',
                 'url': 'https://www.cyberguy.com/antivirus-protection'},
                {'source': 'CyberGuy.com - Identity Theft Protection',
                 'url': 'https://www.cyberguy.com/identity-theft-protection'}],
 'regulatory_compliance': {'regulations_violated': ['potential Fair Credit '
                                                    'Reporting Act (FCRA) '
                                                    'violations']},
 'response': {'communication_strategy': ['no response to media inquiries by '
                                         'deadline',
                                         'opt-out instructions provided on '
                                         'website'],
              'containment_measures': ['site taken offline temporarily'],
              'recovery_measures': ['site relaunched with same business model'],
              'remediation_measures': ['opt-out process for data removal',
                                       'relaunch under new ownership (Perfect '
                                       'Privacy LLC)']},
 'title': 'National Public Data (NPD) Massive Data Breach Exposing 3 Billion '
          "Individuals' Personal Information",
 'type': ['data breach', 'privacy violation']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.