Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

National Public Data Breach: What the US, UK and Canada Headline Really Means

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The National Public Data breach was real, but the claim that it affected everyone in the United States, United Kingdom and Canada is not established. The widely reported figure of up to 2.9 billion refers to records, not a verified count of unique people; Microsoft summarizes reports estimating up to 170 million people, also not a final regulator-confirmed total. The incident dates to 2023–2024, not a newly confirmed 2026 leak.

What happened in the National Public Data breach?

National Public Data, operated by Jerico Pictures, was a private background-check and data-broker business that aggregated information from public and other sources. It was not a government database or a master file of every US, UK and Canadian resident.

In an August 22, 2024 letter, the US House Committee on Oversight and Accountability said National Public Data had reportedly identified malicious attempts to access its systems beginning in late December 2023. Threat actors reportedly advertised data attributed to the company in April 2024, with further leak activity reported that summer. The committee sought information from Jerico Pictures and noted that the scale and scope of the claims were unclear. Read the committee’s letter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The threat actors’ claim that the data covered people in three countries is not the same as independent confirmation of the dataset’s completeness, authenticity or country-by-country reach. The committee described the UK and Canadian scope as possible, rather than a verified count of affected residents.

How many people were affected?

The House committee said it was unclear whether the claimed nearly 3 billion figure referred to records or individuals. Microsoft’s current incident summary describes up to 2.9 billion records and reports an estimate of up to 170 million people. That estimate is not a final, regulator-confirmed victim count. Microsoft’s National Public Data guidance also lists the reported data types.

Record totals can greatly exceed the number of people represented. Data-broker files may repeat entries, retain old addresses and phone numbers, include aliases, or combine records from different sources and periods. They may also include people who have died. A record count cannot be translated directly into a count of unique people, and the available evidence does not establish that every resident of any of the three countries was affected.

What information may have been exposed?

The committee described claims involving names, Social Security numbers, phone numbers, email addresses and mailing addresses. Microsoft also lists those categories. Other reporting has referred to historical addresses, aliases and relatives in some data sets, but the contents can vary by file and person. There is no basis for assuming every affected record held every listed field.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The publicly described exposure centers on identity and contact information. Do not assume that passwords, bank-account numbers or payment-card details were included unless a source confirms those specific fields. The risk depends on which information was present, whether it was accurate and current, and what other information an attacker can combine with it.

What could criminals do with exposed information?

  • Targeted phishing and text scams: A real name, address or phone number can make a fake bank, delivery, government or breach notice more convincing.
  • Account-recovery abuse: Personal details may help an attacker impersonate you when trying to reset an account or persuade customer support to make a change.
  • SIM-swap attempts: A phone number and identifying information can be used in social-engineering attempts against a mobile carrier. A carrier PIN or port-out protection can make unauthorized transfers harder.
  • New-credit or identity fraud: A Social Security number combined with other personal details can raise the risk of fraudulent credit applications or other identity misuse.
  • Credential stuffing: This is a concern if a password exposed in a separate incident was reused on other accounts. The core public descriptions of this incident do not establish a universal password exposure.

How to check your exposure safely

Check email addresses in known breach data

Have I Been Pwned lets you check whether an email address appears in breach data loaded by the service. Check addresses you use now as well as older addresses used for account recovery. A clean result does not show that your Social Security number, address or phone number was absent from National Public Data; it is not a complete forensic check of every field or dataset.

Do not enter a Social Security number, full bank details or full date of birth into an unfamiliar “breach checker.” An unsolicited message offering to verify your exposure may itself be a scam.

Use official recovery guidance and treat commercial scans as limited signals

In the US, the Federal Trade Commission’s data-breach recovery page provides official next steps. Microsoft says its service offers a free identity scan and describes identity-monitoring features for eligible Microsoft 365 Personal and Family subscribers. Those tools are optional signals, not proof that Microsoft can see every record or confirm whether you were included. Monitoring cannot remove copied data or guarantee detection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What US readers should do

Secure accounts and your mobile number

  1. Change passwords that you reused, starting with your primary email account and then banking, mobile-carrier, shopping and social accounts. Use a unique password for each account.
  2. Turn on multifactor authentication, preferably with an authenticator app or security key where the service offers one.
  3. Review account sign-ins, active sessions, recovery addresses and phone numbers, forwarding rules, and unfamiliar devices.
  4. Ask your mobile carrier about adding an account PIN or port-out protection. Be alert to unexpected loss of mobile service or requests to approve a number transfer.

Consider a credit freeze and review your reports

If Social Security number exposure is plausible, a credit freeze is a strong preventive step against many new-credit applications. You must request it separately from each major US credit bureau:

A freeze does not stop account takeover, bank fraud, phishing, tax fraud, SIM swaps or fraud involving organizations that do not use the frozen credit file. A fraud alert is a less restrictive alternative that asks prospective creditors to take additional steps to verify identity; the FTC explains both options in its breach-response guidance.

Review your reports through AnnualCreditReport.com for unfamiliar accounts, inquiries, collection accounts, address changes or applications. If you find signs of identity theft, use IdentityTheft.gov for a recovery plan and reporting steps.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What UK readers should do

The UK does not use the US Social Security-number and credit-freeze system, so US freeze instructions do not apply directly. Instead:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review bank, card, loan and mobile-phone activity. Contact providers using the official number on a card, statement or their app if you spot something unfamiliar.
  • Change reused passwords, enable multifactor authentication and review account-recovery details.
  • Be wary of messages claiming to be from HMRC, a bank, a delivery firm, police or a breach-check service. Do not share authentication codes or follow unsolicited links.
  • Report suspected fraud or cybercrime through Report Fraud.
  • Consider Cifas Protective Registration if you believe your identity-fraud risk is high. It is a fraud-prevention measure that can add friction to identity checks, not a freeze on all UK credit files.

What Canadian readers should do

  • Contact banks, card issuers and mobile providers through trusted contact details if you see suspicious activity or need to secure an account.
  • Review your credit files with Equifax Canada and TransUnion Canada for unfamiliar inquiries, accounts, address changes, collections or applications.
  • Change reused passwords, enable multifactor authentication and review recovery options on important accounts.
  • Report suspected identity fraud to the Canadian Anti-Fraud Centre.
  • For privacy concerns about an organization under federal jurisdiction, consult the Office of the Privacy Commissioner of Canada.

What the headline does not prove

  • It does not prove that every person in the US, UK or Canada was affected.
  • It does not establish that 2.9 billion unique people were exposed; the reported figure is a record count.
  • It does not establish that every record was current or contained a Social Security number.
  • It does not show that a file advertised on a criminal forum contained the entire claimed dataset, that every field was authentic, or that all records were sold.
  • A match in a commercial database alone cannot prove that a particular person was included in the National Public Data incident.

Do not respond to a breach-themed call or message by giving out an MFA code, a full Social Security number, or remote access to your device. Verify notices independently through the organization’s official website or phone number, and do not move money because a caller says your identity was exposed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.