The strangest thing about the National Public Data breach was the relationship between the company and its victims: there wasn't one. NPD was a background-check data broker — it harvested and resold personal information scraped and purchased from other sources. Nobody signed up. Nobody clicked "I agree." And in August 2024, after a slow-motion leak that had been trickling through criminal forums since spring, the trove was published in full: a dataset the seller claimed held 2.9 billion records, including names, addresses, and — the detail that made it a national story in the United States — Social Security numbers.
The headline figure deserves the scepticism this archive always applies to attacker arithmetic: 2.9 billion "records" is not 2.9 billion people, and researchers who examined the files found extensive duplication, historical addresses, and stale entries. But the core was real, and large enough that the practical American advice became universal: freeze your credit, assume your SSN is public, and behave accordingly. For a national identifier designed in the 1930s and never intended as a secret, August 2024 was the closest thing to a formal announcement that the secret was over.
What followed was almost more instructive than the breach. Lawsuits arrived quickly; the parent company filed for bankruptcy protection within weeks. The data broker had extracted value from hundreds of millions of people who never transacted with it, lost that data, and then dissolved — leaving those people with the consequences and no counterparty. It is the clearest illustration this archive can offer of why data-protection regimes like India's DPDP framework insist on naming a responsible fiduciary: without one, the harm has nowhere to land.
Halliburton and industrial ransomware
On August 21, oilfield services giant Halliburton disclosed a cyberattack — later attributed to the RansomHub operation — that forced it to take systems offline and shift parts of its business to manual workarounds. Energy services rarely make consumer headlines, but the incident belonged to the year's most consequential trend: ransomware crews had moved decisively from data theft alone to disrupting heavy industry, where downtime is measured in millions per day and where IT and operational technology are joined more tightly than most executives realise.
Columbus sues the researcher
After ransomware struck the city of Columbus, Ohio in July, officials publicly characterised the stolen data as largely unusable. A security researcher demonstrated otherwise, showing that the leaked files included unredacted personal information — including material relating to police records and crime victims. The city's response was to sue him. The legal action, and the temporary restraining order that followed, produced an industry-wide backlash: whatever the intent, suing the person who corrected your public statement teaches every other researcher to stay quiet. It remains a reference case in the argument over how organisations should treat those who bring them unwelcome accuracy.
A law without a rulebook, one year on
August 2024 marked a full year since India's Digital Personal Data Protection Act received presidential assent — and the operational rules that would make it enforceable still had not been published. For Indian businesses the anniversary was an awkward one: a statute on the books, penalties on paper up to ₹250 crore, and no clarity on consent notices, breach timelines, or who would be designated a Significant Data Fiduciary. Compliance teams spent the year building to a specification that did not exist. The draft rules were still five months away, and the final notified version fifteen — a gap that, viewed from 2026, explains a great deal about how unevenly Indian organisations were prepared when the clock finally started.
⏳ Time capsule — August 2024
- "Freeze your credit" became mainstream American advice, repeated on morning television.
- The Paris Olympics closed without the cyber catastrophe organisers had drilled for — a quiet win worth noting.
- Telegram's founder was arrested in France late in the month, opening a year-long argument about platform liability.
- Security teams returned from summer to a new board question: "are we in the National Public Data file?"
The identifier that stopped identifying
National Public Data settled the argument about the Social Security number: it is an identifier, not an authenticator, and any system still treating it as proof of identity is running on borrowed time. The breach accelerated US state-level data-broker regulation and deletion-request regimes, and it remains the standard example of a harm with no responsible party — which is precisely the gap that accountability-based laws exist to close. Columbus's lawsuit, meanwhile, did lasting damage of its own: researchers now weigh legal exposure before disclosing, and organisations that value early warning have learned to say so in writing, before they need it.