NPD Breach Reveals Data on Hundreds of Millions, Here’s How to Respond

A few months ago, news broke about the latest massive data breach, this time from a company called National Public Data, a company that collects vast amounts of personal data about individuals from public data sources, including addresses, employment history, criminal records, and Social Security numbers. NPD then sells access to that data to employers conducting background checks, landlords screening potential tenants, banks verifying loan information, and more.

Unfortunately, NPD’s data security was lax, with the company publishing its own passwords in a file that was freely available from its homepage. How many people are affected remains unclear, though it seems likely to be hundreds of millions, if not the three billion reported by some outlets. Precisely what is included in the breach varies by person, but it includes names, physical addresses, phone numbers, dates of birth, and Social Security numbers for many. Email addresses may be included as well.

Put bluntly, this is terrible. It’s bad enough when a firm to which you’ve entrusted your data suffers a breach, but no one affected by the NPD breach had a relationship with the company. NPD was just hoovering up everything it could find and reselling it. NPD is far from alone in this field—numerous other companies do the same thing, and some of them have also suffered data breaches.

What can you do? Honestly, not much. Your data appeared in the breach through no fault of your own, so apart from generally trying to keep the amount of your personal data available online to a minimum (watch social media in particular), nothing you do will make a big difference.

You might be tempted by services that promise to “scrub the Internet!” of your data at people-search sites, but a Consumer Reports study found that they were largely ineffective, working for only about a third of the profiles tested. (The study was admittedly fairly small.) The best of the services was effective less than 70% of the time, and manually opting out at each site was slightly more effective. Plus, the study only looked at sites that offer opt-out options—with companies like NPD, there’s no way to know if they have your data or will remove it if asked.

However, several sites will now tell you if your data was included in the NPD breach, including npdbreach.com and npd.pentester.com. Keep in mind that both come from companies that also offer data removal services, although neither were included in the Consumer Reports study.

Breached companies will often offer free credit monitoring services to affected customers. That’s highly unlikely to happen with NPD because it has no business relationship with the people whose data it lost. But there’s a better approach anyway: placing a freeze on your credit reports. Doing so is free and prevents an identity thief from opening new financial accounts in your name by blocking access to your credit file from prospective creditors. Freezing your credit report has no impact on your credit score.

However, before you freeze your credit reports, check them to ensure they’re accurate. You can get free weekly credit reports from all three credit bureaus at AnnualCreditReport.com, authorized by the federal government, which also offers other useful information about protecting yourself from identity theft. If you discover any mistakes, work with the credit bureau to resolve them.

Once you’ve checked your credit reports, you can freeze them, which you need to do with each of the three credit bureaus:

Security freezes remain in place indefinitely, and many people can leave them that way. However, you’ll need to remove the freeze temporarily if you plan to rent a new apartment or house, take out a loan, apply for a credit card, set up a new mobile phone plan or utility account, apply for a new job, or undergo a background check. All three services provide such a capability online, or you can contact them via phone or postal mail, as mentioned above. It can be hard to think about removing a freeze proactively, so if something that might involve checking your credit score fails unexpectedly, remember the freezes. You might even make an annual reminder in your calendar so you don’t go too long without remembering.

It’s a shame that data breaches have become a fact of life, but that’s unavoidable without significantly stronger privacy regulations that prevent large companies from unnecessarily storing personal data and punishing them when they don’t protect it effectively.

(Featured image by iStock.com/BackyardProduction)


Social Media: Hundreds of millions of people had their names, addresses, and Social Security numbers revealed in the massive NPD breach. There isn’t much you can do to protect yourself, but we explain the one thing everyone should do.

More Insights

Make Apple Devices Easier for Family to Access with Secondary Biometrics
Tech Tip

Make Apple Devices Easier for Family to Access with Secondary Biometrics

It’s only safe to share your iPhone, iPad, and Mac passcodes and passwords with people you trust completely, which typically includes family members whom you would trust with your healthcare and bank accounts. If those people also use your devices regularly, you can simplify their access by adding their fingerprint to Touch ID or their […]

Read More »
Why Passkeys Are Better than Passwords (And How to Use Them)
Tech Article

Why Passkeys Are Better than Passwords (And How to Use Them)

No one likes passwords. Users find managing them annoying, and website managers worry about login credentials being stolen in a data breach. The industry has developed a better solution: passkeys. Passwords versus Passkeys Traditional multi-factor authentication involves three methods of authentication, at least two of which are required for protection. They include something you know […]

Read More »
Beware Domain Name Renewal Phishing Attacks
Tech Tip

Beware Domain Name Renewal Phishing Attacks

Most phishing attacks are easy to identify, but we’ve just seen one that’s more likely to evade detection. Those who own personal or business Internet domain names—to personalize their email or provide an online presence for their website—may receive fake messages claiming that a domain has been deactivated due to a payment issue. Because scammers […]

Read More »
Consider Business Cyber Insurance
Tech Article

Consider Business Cyber Insurance

When discussing digital security, we typically focus on preventive measures, such as using strong passwords with a password manager, enabling multi-factor authentication, keeping systems up to date, maintaining regular backups, and training employees to recognize potential security threats. While these practices are essential, they don’t guarantee complete protection. No one is immune to online attacks—the […]

Read More »
Apple Silicon Macs Can’t Boot from the DFU Port
Tech Tip

Apple Silicon Macs Can’t Boot from the DFU Port

Booting from an external SSD (hard disks are too slow) provides a convenient way to test specific versions of macOS or troubleshoot problems with your Mac’s internal storage. However, a little-known gotcha has caused untold hair loss among those trying to boot from an external drive. Macs with Apple silicon cannot start up from external […]

Read More »
Tech Article

Use AirPlay to Mirror or Extend Your Mac’s Display

Apple’s AirPlay is one of those low-level technologies that’s more capable than many people realize. In addition to allowing you to stream video and audio from an iPhone, iPad, or Mac to an Apple TV connected to a large-screen TV, AirPlay also enables you to use that TV as an external Mac display, either mirroring […]

Read More »

If you are here and not sure how to proceed, please call us at 626-286-2350, and we would be happy to help you find a solution to your needs.