The strangest thing about the National Public Data breach was the relationship between the company and its victims: there wasn't one. NPD was a background-check data broker — it harvested and resold personal information scraped and purchased from other sources. Nobody signed up. Nobody clicked "I agree." And in August 2024, after a slow-motion leak that had been trickling through criminal forums since spring, the trove was published in full: a dataset the seller claimed held 2.9 billion records, including names, addresses, and — the detail that made it a national story in the United States — Social Security numbers.

The headline figure deserves the scepticism this archive always applies to attacker arithmetic: 2.9 billion "records" is not 2.9 billion people, and researchers who examined the files found extensive duplication, historical addresses, and stale entries. But the core was real, and large enough that the practical American advice became universal: freeze your credit, assume your SSN is public, and behave accordingly. For a national identifier designed in the 1930s and never intended as a secret, August 2024 was the closest thing to a formal announcement that the secret was over.

What followed was almost more instructive than the breach. Lawsuits arrived quickly; the parent company filed for bankruptcy protection within weeks. The data broker had extracted value from hundreds of millions of people who never transacted with it, lost that data, and then dissolved — leaving those people with the consequences and no counterparty. It is the clearest illustration this archive can offer of why data-protection regimes like India's DPDP framework insist on naming a responsible fiduciary: without one, the harm has nowhere to land.

Also that month · The rig goes quiet

Halliburton and industrial ransomware

On August 21, oilfield services giant Halliburton disclosed a cyberattack — later attributed to the RansomHub operation — that forced it to take systems offline and shift parts of its business to manual workarounds. Energy services rarely make consumer headlines, but the incident belonged to the year's most consequential trend: ransomware crews had moved decisively from data theft alone to disrupting heavy industry, where downtime is measured in millions per day and where IT and operational technology are joined more tightly than most executives realise.

Also that month · Shooting the messenger

Columbus sues the researcher

After ransomware struck the city of Columbus, Ohio in July, officials publicly characterised the stolen data as largely unusable. A security researcher demonstrated otherwise, showing that the leaked files included unredacted personal information — including material relating to police records and crime victims. The city's response was to sue him. The legal action, and the temporary restraining order that followed, produced an industry-wide backlash: whatever the intent, suing the person who corrected your public statement teaches every other researcher to stay quiet. It remains a reference case in the argument over how organisations should treat those who bring them unwelcome accuracy.

India desk · August 2024

A law without a rulebook, one year on

August 2024 marked a full year since India's Digital Personal Data Protection Act received presidential assent — and the operational rules that would make it enforceable still had not been published. For Indian businesses the anniversary was an awkward one: a statute on the books, penalties on paper up to ₹250 crore, and no clarity on consent notices, breach timelines, or who would be designated a Significant Data Fiduciary. Compliance teams spent the year building to a specification that did not exist. The draft rules were still five months away, and the final notified version fifteen — a gap that, viewed from 2026, explains a great deal about how unevenly Indian organisations were prepared when the clock finally started.

AI Tech desk · August 2024

Two labs sign with the safety institute

On 29 August 2024 the US AI Safety Institute, housed within the Commerce Department's standards agency, announced memoranda of understanding with OpenAI and Anthropic: the institute would receive access to major new models before and after public release, evaluate capabilities and risks, and feed findings back in collaboration with its British counterpart. It was voluntary, unenforceable, and for a moment the most concrete arrangement in American AI oversight. The mandatory version was next door. California's SB 1047 cleared the Assembly on 28 August and the Senate the following day, sending a frontier-model safety regime to the governor's desk; Newsom vetoed it on 29 September, objecting that the bill graded models by size and cost rather than by where they were deployed. Elsewhere that month Anthropic began publishing Claude's system prompts as documentation, and Google issued three experimental Gemini 1.5 models, among them a smaller Flash-8B. The institute was renamed the Center for AI Standards and Innovation in June 2025 — safety out of the title, and, critics argued, out of the remit.

Digital Guard desk · August 2024

The post-mortem, the letters, the summit

On 6 August 2024 CrowdStrike published its external technical root cause analysis of the Channel File 291 incident: an interprocess communication template defined twenty-one input fields while the sensor code supplied twenty, and the mismatch produced an out-of-bounds read that testing had missed because wildcard matching masked the twenty-first field. The commercial argument ran alongside it. Delta's counsel, David Boies, alleged gross negligence; CrowdStrike's lawyers rejected the characterisation outright, saying the company had offered help within hours and that its chief executive had contacted Delta's without reply. On 23 August 2024 Microsoft announced a Windows Endpoint Security Ecosystem Summit for 10 September, inviting CrowdStrike and its rivals to Redmond to discuss kernel access. At Black Hat USA, meanwhile, SafeBreach's Alon Leviev demonstrated that Windows Update itself could be turned into a downgrade tool, reverting patched components while the operating system continued to report itself current. Microsoft's answer came slowly: by June 2025 a private preview allowed endpoint products to run outside the kernel.

⏳ Time capsule — August 2024

  • "Freeze your credit" became mainstream American advice, repeated on morning television.
  • The Paris Olympics closed without the cyber catastrophe organisers had drilled for — a quiet win worth noting.
  • Telegram's founder was arrested in France late in the month, opening a year-long argument about platform liability.
  • Security teams returned from summer to a new board question: "are we in the National Public Data file?"
Where it stands today — 2026

The identifier that stopped identifying

National Public Data settled the argument about the Social Security number: it is an identifier, not an authenticator, and any system still treating it as proof of identity is running on borrowed time. The breach accelerated US state-level data-broker regulation and deletion-request regimes, and it remains the standard example of a harm with no responsible party — which is precisely the gap that accountability-based laws exist to close. Columbus's lawsuit, meanwhile, did lasting damage of its own: researchers now weigh legal exposure before disclosing, and organisations that value early warning have learned to say so in writing, before they need it.