Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The National Public Data breach was real, but the claim that it affected everyone in the United States, United Kingdom and Canada is not established. The widely reported figure of up to 2.9 billion refers to records, not a verified count of unique people; Microsoft summarizes reports estimating up to 170 million people, also not a final regulator-confirmed total. The incident dates to 2023–2024, not a newly confirmed 2026 leak.
What happened in the National Public Data breach?
National Public Data, operated by Jerico Pictures, was a private background-check and data-broker business that aggregated information from public and other sources. It was not a government database or a master file of every US, UK and Canadian resident.
In an August 22, 2024 letter, the US House Committee on Oversight and Accountability said National Public Data had reportedly identified malicious attempts to access its systems beginning in late December 2023. Threat actors reportedly advertised data attributed to the company in April 2024, with further leak activity reported that summer. The committee sought information from Jerico Pictures and noted that the scale and scope of the claims were unclear. Read the committee’s letter.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →The threat actors’ claim that the data covered people in three countries is not the same as independent confirmation of the dataset’s completeness, authenticity or country-by-country reach. The committee described the UK and Canadian scope as possible, rather than a verified count of affected residents.
#1 Best Overall
How many people were affected?
The House committee said it was unclear whether the claimed nearly 3 billion figure referred to records or individuals. Microsoft’s current incident summary describes up to 2.9 billion records and reports an estimate of up to 170 million people. That estimate is not a final, regulator-confirmed victim count. Microsoft’s National Public Data guidance also lists the reported data types.
Record totals can greatly exceed the number of people represented. Data-broker files may repeat entries, retain old addresses and phone numbers, include aliases, or combine records from different sources and periods. They may also include people who have died. A record count cannot be translated directly into a count of unique people, and the available evidence does not establish that every resident of any of the three countries was affected.
What information may have been exposed?
The committee described claims involving names, Social Security numbers, phone numbers, email addresses and mailing addresses. Microsoft also lists those categories. Other reporting has referred to historical addresses, aliases and relatives in some data sets, but the contents can vary by file and person. There is no basis for assuming every affected record held every listed field.
The publicly described exposure centers on identity and contact information. Do not assume that passwords, bank-account numbers or payment-card details were included unless a source confirms those specific fields. The risk depends on which information was present, whether it was accurate and current, and what other information an attacker can combine with it.
What could criminals do with exposed information?
- Targeted phishing and text scams: A real name, address or phone number can make a fake bank, delivery, government or breach notice more convincing.
- Account-recovery abuse: Personal details may help an attacker impersonate you when trying to reset an account or persuade customer support to make a change.
- SIM-swap attempts: A phone number and identifying information can be used in social-engineering attempts against a mobile carrier. A carrier PIN or port-out protection can make unauthorized transfers harder.
- New-credit or identity fraud: A Social Security number combined with other personal details can raise the risk of fraudulent credit applications or other identity misuse.
- Credential stuffing: This is a concern if a password exposed in a separate incident was reused on other accounts. The core public descriptions of this incident do not establish a universal password exposure.
How to check your exposure safely
Check email addresses in known breach data
Have I Been Pwned lets you check whether an email address appears in breach data loaded by the service. Check addresses you use now as well as older addresses used for account recovery. A clean result does not show that your Social Security number, address or phone number was absent from National Public Data; it is not a complete forensic check of every field or dataset.
Do not enter a Social Security number, full bank details or full date of birth into an unfamiliar “breach checker.” An unsolicited message offering to verify your exposure may itself be a scam.
Use official recovery guidance and treat commercial scans as limited signals
In the US, the Federal Trade Commission’s data-breach recovery page provides official next steps. Microsoft says its service offers a free identity scan and describes identity-monitoring features for eligible Microsoft 365 Personal and Family subscribers. Those tools are optional signals, not proof that Microsoft can see every record or confirm whether you were included. Monitoring cannot remove copied data or guarantee detection.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat US readers should do
Secure accounts and your mobile number
- Change passwords that you reused, starting with your primary email account and then banking, mobile-carrier, shopping and social accounts. Use a unique password for each account.
- Turn on multifactor authentication, preferably with an authenticator app or security key where the service offers one.
- Review account sign-ins, active sessions, recovery addresses and phone numbers, forwarding rules, and unfamiliar devices.
- Ask your mobile carrier about adding an account PIN or port-out protection. Be alert to unexpected loss of mobile service or requests to approve a number transfer.
Consider a credit freeze and review your reports
If Social Security number exposure is plausible, a credit freeze is a strong preventive step against many new-credit applications. You must request it separately from each major US credit bureau:
Best Value
A freeze does not stop account takeover, bank fraud, phishing, tax fraud, SIM swaps or fraud involving organizations that do not use the frozen credit file. A fraud alert is a less restrictive alternative that asks prospective creditors to take additional steps to verify identity; the FTC explains both options in its breach-response guidance.
Review your reports through AnnualCreditReport.com for unfamiliar accounts, inquiries, collection accounts, address changes or applications. If you find signs of identity theft, use IdentityTheft.gov for a recovery plan and reporting steps.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What UK readers should do
The UK does not use the US Social Security-number and credit-freeze system, so US freeze instructions do not apply directly. Instead:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute- Review bank, card, loan and mobile-phone activity. Contact providers using the official number on a card, statement or their app if you spot something unfamiliar.
- Change reused passwords, enable multifactor authentication and review account-recovery details.
- Be wary of messages claiming to be from HMRC, a bank, a delivery firm, police or a breach-check service. Do not share authentication codes or follow unsolicited links.
- Report suspected fraud or cybercrime through Report Fraud.
- Consider Cifas Protective Registration if you believe your identity-fraud risk is high. It is a fraud-prevention measure that can add friction to identity checks, not a freeze on all UK credit files.
What Canadian readers should do
- Contact banks, card issuers and mobile providers through trusted contact details if you see suspicious activity or need to secure an account.
- Review your credit files with Equifax Canada and TransUnion Canada for unfamiliar inquiries, accounts, address changes, collections or applications.
- Change reused passwords, enable multifactor authentication and review recovery options on important accounts.
- Report suspected identity fraud to the Canadian Anti-Fraud Centre.
- For privacy concerns about an organization under federal jurisdiction, consult the Office of the Privacy Commissioner of Canada.
What the headline does not prove
- It does not prove that every person in the US, UK or Canada was affected.
- It does not establish that 2.9 billion unique people were exposed; the reported figure is a record count.
- It does not establish that every record was current or contained a Social Security number.
- It does not show that a file advertised on a criminal forum contained the entire claimed dataset, that every field was authentic, or that all records were sold.
- A match in a commercial database alone cannot prove that a particular person was included in the National Public Data incident.
Do not respond to a breach-themed call or message by giving out an MFA code, a full Social Security number, or remote access to your device. Verify notices independently through the organization’s official website or phone number, and do not move money because a caller says your identity was exposed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

