Darknet Diaries

177: National Public Data

Brief

National Public Data centers on two linked strands of identity harm: a decades-old individual identity theft that ruined a man’s life, and a modern mass-breach of a data broker that produced billions of exposed records. Jack Rhysider opens with the 1988 Albuquerque case in which Matthew Kierens stole William Woods’ wallet, copied the birth certificate and Social Security number, and by 1994 had built a full new life as "William Woods" — a driver's license, bank accounts, a $100,000-per-year IT job at the University of Iowa, marriage and property. When the real Woods discovered loans and accounts in 2019 he was treated as the fraudster: bank staff believed the better-documented, well-dressed phone account; Woods was institutionalized for five months, jailed for about 18 months, and hit with an $118,000 psychiatric bill. A University of Iowa investigator later obtained DNA from Woods’ father and proved Woods’ identity, leading to exoneration and cancellation of the bill; Kierens was later sentenced to 12 years federal prison (projected release 2037), according to Jack.

The episode then pivots to organized abuse of brokered data. Jack profiles USDOD — a hacker who claimed the name after publishing stolen Department of Defense email/password lists in February 2020 and later abused InfraGard by impersonation to exfiltrate ~80,000 member contact records via an exposed API. USDOD (identified as Luan Barbosa by CrowdStrike) hunted vulnerable data brokers and discovered a Records Check 'Members.zip' holding site source code and admin credentials. Reused passwords unlocked NationalPublicData.com and allowed the theft of ~277 GB (2.9 billion lines) of PII — names, DOBs, Social Security numbers, addresses, emails and phones — which USDOD offered for $3.5M. Jack details the broker side (Salvatore Verini Jr.'s companies), their minimal security posture, profitability (Jack cites ~$750k in 2002 and ~$1.15M in 2023), and continued operation despite lawsuits. He tracks responses — CrowdStrike’s private doxing and Brazil’s arrest of Luan, Congress’ briefly hopeful but ultimately sabotaged American Privacy Rights Act in April 2024 — and closes with practical warnings: leaked broker data enables SIM swaps, loan fraud and lifelong identity takeover, governments routinely buy brokered data, and individuals should adopt end-to-end messaging, privacy email, and privacy-focused browsers to mitigate risk.

Why it matters

Host Jack Rhysider recounts a 1988 Albuquerque identity-theft: Matthew Kierens stole William Woods' wallet, then used Woods' birth certificate and Social Security number to assume his identity; by 1994 Kierens held a driver's license and a $100,000/yr IT job at the University of Iowa and kept the identity for ~31 years until 2019.

Key details

  • When the real William Woods discovered unauthorized accounts in 2019 he was mistaken for the impostor, spent five months in a psychiatric hospital (forced on medication), then ~18 months in jail, and was charged an $118,000 hospital bill later overturned after University of Iowa investigators used DNA from Woods' father to prove his identity; Matthew Kierens was ultimately sentenced to 12 years in federal prison (expected release 2037) — as reported by Jack.
  • The hacker known as USDOD (later identified by CrowdStrike and others as Luan Barbosa) leaked Department of Defense-related data in February 2020 (full military email/password lists) and exploited InfraGard by impersonating a CEO; he exfiltrated contact records for ~80,000 InfraGard members via a vulnerable API, per Jack's account.
  • USDOD targeted data-broker sites and in 2023 found a 'Members.zip' file on Records Check (owned by Salvatore 'Sal' Verini Jr.) that contained site source code and admin credentials; reused passwords let USDOD access NationalPublicData.com and steal ~277 GB — 2.9 billion lines — of personal records (names, DOBs, SSNs, addresses, emails, phones) and list it for sale for $3.5M, Jack reports.
  • Salvatore Verini Jr. operated National Public Data / Records Check from a home office with minimal cybersecurity (zero budget listed), earned large sums from data sales (Jack cites ~$750k in 2002 and ~$1.15M in 2023), faced multiple lawsuits, attempted bankruptcy (rejected), allegedly sold the company to 'Perfect Privacy LLC', yet the site continued operating after the breach.
  • After the National Public Data leak, Congress proposed the American Privacy Rights Act (April 2024) with a universal opt-out for data brokers, but the bill was weakened at the last minute and died; Jack notes ~35% of congressional members were included in the breach and frames legislative protection as unreliable.
Reader · no content

No body text on file.

Open the original to read the full piece.