The Setup
I want to tell you about the security infrastructure that protected your Social Security number, your home address, your family relationships, and 30 years of your personal history.
It consisted of:
- Two HP Pavilion desktop computers (estimated value: $200 each)
- One ThinkPad laptop (estimated value: $100)
- Five Dell servers (estimated value: $2,000)
- One guy working from his home in Pompano Beach, Florida
Total value of assets: somewhere between $25,000 and $75,000.
Total records stored: 2.9 billion.
Total people affected by the breach: Approximately 170 million—more than half of all American adults.
And when the lawsuits came—dozens of them, including state attorneys general from nearly every U.S. state and territory—the company filed for bankruptcy. Because it couldn't afford to defend itself.
This is the story of National Public Data: the data broker that proved exactly how unregulated, how absurd, and how fundamentally broken the entire industry really is.
What Was National Public Data?
National Public Data was a background check service operated by a company called Jerico Pictures, Inc.
(Yes, that Jerico Pictures. The same entity that also owned domains like "asseeninporn.com." We'll get to that.)
The company was owned and operated by a single person: Salvatore Verini Jr., a retired deputy with the Broward County Sheriff's Office who also dabbles in acting and reality TV production. His most recent project, according to his website, was a 2019 reality show called "Country Daze" that you can stream on Amazon.
Verini ran National Public Data from his home office. The company "maintains no dedicated physical offices," according to the bankruptcy filing. All infrastructure was "housed in independent data centers."
Despite this modest operation, National Public Data claimed to offer instant background checks with access to billions of records. Their customers included healthcare institutions that needed to screen employees.
And how did they build this massive database?
They scraped it.
According to the class action lawsuit filed by victim Christopher Hofmann, National Public Data "scraped the PII of billions of individuals from non-public sources."
Non-public sources. Without consent.
Here's the kicker: Most of the people in that database had no idea National Public Data even existed, let alone that the company had their information.
What They Collected
According to court documents and data breach analyses, National Public Data's database included:
Personal Information:
- Full legal names
- Social Security numbers
- Dates of birth
- Current addresses
- Historical addresses (spanning at least 30 years)
- Phone numbers
- Email addresses
Family Information:
- Parents' names and information
- Siblings' names and information
- Other relatives and associates
Additional Databases (listed as assets in bankruptcy filing):
- Individuals licensed by the DEA to prescribe controlled substances
- Concealed weapons permit holders
- Public records including marriages, divorces, and bankruptcies
- International financial sanctions data
All of this, collected without consent, stored with apparently minimal security, and available for purchase by anyone willing to pay.
The Breach
In late December 2023, hackers began probing National Public Data's systems.
By April 2024, they were in.
On April 8, 2024, a notorious hacker known as "USDoD" (also called "EquationCorp") posted a listing on the dark web forum Breached. The listing offered for sale:
- 277.1 GB of data
- 2.9 billion records
- Full names, addresses, Social Security numbers, and family information
- Data spanning from 2019 to 2024
The asking price: $3.5 million.
USDoD was no amateur. This was the same hacker who had previously:
- Breached the FBI's InfraGard portal (a cybersecurity information-sharing network), leaking data on 80,000 members
- Stolen data from European aerospace giant Airbus
- Compromised TransUnion
- Breached the U.S. Environmental Protection Agency
In an interview with journalists, USDoD described himself this way: "I can partly f**k any government I want because I don't have a flag or don't follow orders from a king. I have my own flag and that is the black flag. I'm, by nature, a pirate."
Charming.
The Delayed Disclosure
Here's where it gets worse.
The breach happened in April 2024. Data was being sold on the dark web in April 2024.
National Public Data didn't publicly acknowledge the breach until August 2024.
Four months of silence while criminals traded Social Security numbers for hundreds of millions of Americans.
Even then, the company's initial disclosure was misleading. In a filing with Maine's Attorney General (required under state law), National Public Data claimed only 1.3 million people were affected.
Security researcher Troy Hunt, who maintains the breach notification site HaveIBeenPwned, analyzed the leaked database. He found 134 million unique email addresses alone.
The company's notification to affected individuals? According to reports, many victims never received one. The first many people heard about the breach was when they checked HaveIBeenPwned or received alerts from identity theft protection services—not from National Public Data.
As the lawsuit noted:
"NPD did not publicly acknowledge the incident until August 2024, several months after hackers began selling data. This delay has been a critical point in related lawsuits, emphasizing NPD's alleged failure to provide timely notification to consumers and authorities."
The Absurd Math
Let me put this in perspective.
National Public Data's assets (according to bankruptcy filing):
- Flagstar bank account: $39,225
- HP Pavilion desktops (2): $400
- ThinkPad laptop: $100
- Dell servers (5): $2,000
- Domain names (27): $675 (valued at $25 each)
- Various other equipment: ~$3,000
Total estimated assets: Between $25,000 and $75,000
National Public Data's revenue:
- 2022: $746,088
- 2023: $1,152,726
- 2024 (through October): ~$431,000
National Public Data's liabilities:
- Class action lawsuits: Over a dozen
- State attorney general investigations: 20+ states plus territories
- FTC investigation: Ongoing
- Potential victim notification and credit monitoring costs: Hundreds of millions of dollars
A company that grossed about $1.1 million per year was custodian of data that could enable identity theft for half the American population.
And when the breach happened, they had less than $75,000 to show for it.
The bankruptcy filing explicitly stated: "The enterprise cannot generate sufficient revenue to address the extensive potential liabilities, not to mention, defend the lawsuits and support the investigations."
Translation: "We collected data on 170 million people, got hacked, and can't afford a lawyer."
The Domain Names
Sometimes the details tell the story better than any analysis.
In the bankruptcy filing, Verini listed 27 domain names as company assets. Most were related to the background check business:
- nationalpublicdata.com (now defunct)
- criminalscreen.com
- RecordsCheck.net
But also included in the company's portfolio:
- asseeninporn.com
I genuinely cannot explain this. Neither could anyone else who read the filing.
This is the company that was trusted with your Social Security number.
The Hacker Gets Caught
In October 2024—six months after the breach and one month after National Public Data filed for bankruptcy—Brazilian police arrested USDoD.
The 33-year-old, identified as Luan G. from Belo Horizonte, Brazil, was arrested in "Operation Data Breach" after being tracked down by cybersecurity firm CrowdStrike.
His downfall? He got cocky.
After the National Public Data breach, USDoD claimed to have also breached CrowdStrike itself, leaking what he said was their internal threat actor list. CrowdStrike wasn't amused. They tracked him down and shared his real identity with Brazilian authorities.
In an interview after being doxxed but before his arrest, USDoD said:
"I am a huge valuable target and maybe I will talk soon to whoever is in charge but everyone will know that behind USDoD I'm a human like everyone else, to be honest, I wanted this to happen, I can't live with multiple lives and it is time to take responsibility for every action of mine and pay the price doesn't matter how much it may cost me."
He's now facing charges in Brazil. U.S. authorities may seek extradition given the scale of his crimes.
The Bankruptcy Collapse
National Public Data's bankruptcy didn't even last long enough to provide any protection.
On October 2, 2024, Jerico Pictures filed for Chapter 11 bankruptcy in the Southern District of Florida. Chapter 11 is supposed to give companies breathing room to reorganize and continue operating.
But by October 30, 2024, the bankruptcy court dismissed the case.
Why? According to the U.S. Trustee:
- The company failed to file an accurate list of creditors
- There was no "reasonable likelihood" of a meaningful reorganization
- The company simply didn't have the resources to properly notify all the people it owed
The creditors listed in the filing were remarkable: attorneys general from almost all 50 states, plus Guam, Puerto Rico, American Samoa, the Virgin Islands, the Northern Mariana Islands, and the District of Columbia.
The California Privacy Protection Agency filed a claim for $46,000 in fines—for failing to register as a data broker under California law. National Public Data had missed the January 31 deadline and didn't register until September 18, racking up $200-per-day fines.
The FTC investigation remains ongoing.
And the company? It shut down in December 2024. The website now displays only a closure notice.
The Victims
Let me be clear about who's actually harmed here.
It's not Salvatore Verini, who gets to file bankruptcy and walk away.
It's not USDoD, who was living his "pirate" fantasy until he got caught.
It's the 170 million Americans whose Social Security numbers are now circulating on dark web forums.
If your Social Security number was in that breach—and statistically, there's a good chance it was—here's what criminals can do with it:
Immediate Risks:
- Open credit cards in your name
- Take out loans in your name
- File fraudulent tax returns to steal your refund
- Drain your existing bank accounts
- Access your medical records
Long-Term Risks:
- Ongoing identity theft (SSNs don't change)
- Employment fraud
- Medical identity theft
- Criminal identity theft (crimes committed in your name)
- Child identity theft (if your children's data was included)
The data spans 30 years. It includes your previous addresses, your family members, your associations. This isn't just a credit card number you can cancel. This is the permanent architecture of your identity.
And the company responsible has less than $75,000 in assets.
Protecting Yourself
If you're reading this, your data was probably in this breach. Here's what to do:
1. Check if you're affected:
- Visit npd.pentester.com or HaveIBeenPwned.com
- Enter your email to see if it appears in known breaches
2. Freeze your credit (this is free):
- Equifax: equifax.com/personal/credit-report-services/credit-freeze/
- Experian: experian.com/freeze/
- TransUnion: transunion.com/credit-freeze/
A freeze prevents anyone from opening new credit in your name. You can temporarily lift it when you need to apply for credit.
3. Set up fraud alerts:
- Contact any one of the three credit bureaus
- They're required to notify the other two
- Lasts one year (you can renew)
4. Monitor your accounts:
- Check your credit reports at AnnualCreditReport.com (free weekly through 2024)
- Set up alerts on your bank accounts
- Watch for unfamiliar activity
5. Consider an IRS Identity Protection PIN:
- Visit irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin
- Prevents someone from filing a tax return using your SSN
6. Be alert for phishing:
- Scammers will use this breach data to craft convincing attacks
- Be suspicious of calls, texts, or emails referencing your personal info
- Never give out additional information to unsolicited contacts
The Uncomfortable Reality
National Public Data's story exposes an uncomfortable truth: There is nothing protecting you.
Any company can:
- Scrape your personal information without consent
- Store it with minimal security
- Sell it to anyone willing to pay
- Lose it to hackers
- Declare bankruptcy when caught
And you—the person whose data was stolen—have essentially no recourse.
No compensation. No credit monitoring (the company can't afford it). No way to get your Social Security number back.
The only thing you can do is freeze your credit and hope for the best.
This is the system we've built. Or rather, the system we've failed to build.
Until Congress passes comprehensive privacy legislation—with real security requirements, real consent requirements, and real penalties for violations—this will keep happening.
National Public Data won't be the last data broker to collect your information without permission, store it insecurely, lose it to hackers, and walk away.
It's just the one that got caught.
Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform protecting families and seniors from scams and digital threats. She has 20+ years in cybersecurity, including roles at Apple, the White House OCIO, and GuidePoint Security. Follow The Shield Blog for more investigations into the companies that profit from your data.
Sources:
- Wikipedia, "2024 National Public Data breach"
- TechCrunch, "National Public Data, the hacked data broker that lost millions of Social Security numbers and more, files for bankruptcy" (October 2024)
- The Record, "National Public Data files for bankruptcy, citing fallout from cyberattack" (October 2024)
- Bleeping Computer, "USDoD hacker behind National Public Data breach arrested in Brazil" (October 2024)
- Krebs on Security, "Brazil Arrests 'USDoD,' Hacker in FBI Infragard Breach" (October 2024)
- CyberScoop, "Brazil's Federal Police arrest alleged National Public Data hacker" (October 2024)
- The Register, "National Public Data files for bankruptcy after info leak" (October 2024)
- IBM, "National Public Data breach publishes private data of 2.9B U.S. citizens"
- Daily Security Review, "Nearly Three Billion People's Personal Data Exposed in Major National Public Data Data Breach" (August 2024)
- IT Pro, "The National Public Data breach exposed nearly three billion users – now the company has filed for bankruptcy" (October 2024)
- MLex, "National Public Data saga illustrates little-regulated US data broker industry"
- U.S. House Committee on Oversight and Accountability, Letter to Salvatore Verini (August 2024)
- Jerico Pictures Inc. Chapter 11 Bankruptcy Filing, Southern District of Florida (October 2024)
