How to Respond: Hundreds of Millions affected by NPD Breach
A few months ago, news broke about the latest massive data breach, this time from National Public Data. This company collects vast amounts of personal data about individuals from public data sources, including addresses, employment history, criminal records, and Social Security numbers. NPD then sells access to that data to employers conducting background checks, landlords screening potential tenants, banks verifying loan information, and more.
Unfortunately, NPD’s data security was lax, with the company publishing its passwords in a file freely available from its homepage. How many people are affected remains unclear, though it seems likely to be hundreds of millions, if not the three billion reported by some outlets. The exact details of the breach vary by person, but they include names, physical addresses, phone numbers, dates of birth, and Social Security numbers for many. Email addresses may also be included.
Put bluntly, this is terrible. It’s bad enough when a firm to which you’ve entrusted your data suffers a breach, but no one affected by the NPD breach had a relationship with the company. NPD was hoovering up everything it could find and reselling it. NPD is far from alone in this field—numerous other companies do the same thing, and some have also suffered data breaches.
What can you do? Honestly, not much. Your data appeared in the breach through no fault of your own, so apart from generally trying to keep the amount of your data available online to a minimum (watch social media in particular), nothing you do will make a big difference. (We have past tips for responding to data breaches.)
Services that promise to “scrub the Internet!” of your data at people-search sites may be tempting. Still, a Consumer Reports study found they were largely ineffective, working for only about a third of the profiles tested. (The study was admittedly reasonably small.) The best of the services was effective less than 70% of the time, and manually opting out at each site was slightly more effective. Plus, the study only looked at sites that offer opt-out options—with companies like NPD, there’s no way to know if they have your data or will remove it if asked.
However, several sites will now tell you if your data was included in the NPD breach, including npdbreach.com and npd.pentester.com. Keep in mind that both come from companies that also offer data removal services, although neither were included in the Consumer Reports study.
Breached companies will often offer free credit monitoring services to affected customers. That’s highly unlikely to happen with NPD because it has no business relationship with the people whose data it lost. But there’s a better approach: freeze your credit reports. Doing so is free and prevents an identity thief from opening new financial accounts in your name by blocking access to your credit file from prospective creditors. Freezing your credit report has no impact on your credit score.
However, before you freeze your credit reports, check them to ensure they’re accurate. You can get free weekly credit reports from all three credit bureaus at AnnualCreditReport.com, authorized by the federal government, which also offers other helpful information about protecting yourself from identity theft. If you discover any mistakes, work with the credit bureau to resolve them.
Once you’ve checked your credit reports, you can freeze them, which you need to do with each of the three credit bureaus:
- Experian: Freeze your Experian credit report online, call 1-888-397-3742, or submit a paper form.
- Equifax: Freeze your Equifax credit report online, call 1-888-378-4329, or submit a paper form.
- Transunion: Freeze your Transunion credit report online, call 1-800-916-8800, or submit a written request.
Security freezes remain indefinitely, and many people can leave them that way. However, you’ll need to remove the freeze temporarily if you plan to rent a new apartment or house, take out a loan, apply for a credit card, set up a new mobile phone plan or utility account, apply for a new job, or undergo a background check. All three services provide such a capability online, or you can contact them via phone or postal mail, as mentioned above. It may not remember to remove a freeze proactively, so if something that might involve checking your credit score fails unexpectedly, remember the freezes. You might even make an annual reminder in your calendar so you don’t forget too long.
It’s a shame that data breaches have become a fact of life, but that’s unavoidable without significantly stronger privacy regulations that prevent large companies from unnecessarily storing personal data and punishing them when they don’t protect it effectively.
(Featured image by iStock.com/BackyardProduction)