Were three billion people's details leaked online last week? This top security expert isn't so sure

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Top  background check company National Public Data was recently hit by a class action lawsuit which claimed the personal data of almost three billion people was leaked online.

A cyber criminal group known as ASDoD listed the database for sale online at $3.5 million, but there is no evidence that anyone has yet paid the sum.

If confirmed, this could be one of the biggest data breaches on record - or could it? Troy Hunt, one of the most renowned security experts around, and the founder of breach site HaveIBeenPwned, looked into the breach and found much of the information surrounding the incident didn’t appear to add up.

Did ASDoD bump up the numbers?

Firstly, Hunt points out, the initial post of the database on the dark web stated that it contained 2.9 billion rows of data, and that it was the entire population of the USA, Canada, and the UK - which, at last count, doesn’t have a combined population of 2.9 billion.

ASDoD also stated the database contained social security numbers (SSN), which, Hunt points out “are a rather American construct with Canada having SINs (Social Insurance Number) and the UK having, well, NI (National Insurance) numbers are probably the closest equivalent.”

Secondly, the ASDoD post claimed the database is 200GB compressed, which expands out to 4TB uncompressed, but when verified by Hunt and cybersecurity repository vx-underground, the total file size only totaled 277.1GB uncompressed. What’s more, when checking to see if the database contained verifiable data and SSNs, Hunt found that the first six rows were the same person, just with the first name and last name alternated, and listed at different addresses in the same city.

Taking a larger sample of the data, Hunt found out of the 100 million row sample, just 31% contained a unique SSN. Now this does mean that a significant amount of the data does contain the legitimate personal information and SSNs of thousands of victims, but the scale may be slightly less than 2.9 billion people and is instead, just 2.9 billion rows of duplicated data.

Now as for whether the data was legitimate, Hunt ran into difficulties attributing the database to a single source because of how generic the data was. In Hunt’s words, “how many different places have your first and last name, address, SSN, etc?”

Curious, Hunt also searched to see if any of his own information had been included in the breach. His email showed up in 28 different rows, but without his own name, address, or correct date of birth, indicating that much of the data could be inaccurate and mismatched between victims.

Hunt speculates that the breach was so widely shared across social media and news outlets because of the initial legitimacy of SSNs in the first dump, with follow up dumps of data being sucked into the hype of ‘the biggest data breach ever.’ Hunt also suggests that as NPD is a data brokerage, they could have syphoned a huge amount of publicly available data into the database before it was stolen.

Ultimately there are a number of possibly legitimate SSNs floating around, but the data contained within the breach shows that they may not be displayed with the correct names and addresses. However, there are 134 million email addresses in public circulation, which could be used for phishing or to target those without adequate identity theft protection.

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Outdoor photograph of a pair of hands holding a smartphone with navigator location points in the background
Millions of phone location records feared leaked as one of the biggest data leaks ever may be a whole lot worse
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Security
American National Insurance Company breach data found online
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space