Index_breached.vc.zip
: Details on how their databases were structured and accessed. The Dark Web Leak
The breach wasn't necessarily a complex hack but a critical oversight. A security researcher discovered that NPD had left a zip file—often identified as index_breached.vc.zip or similar variants—publicly accessible on their website. This file contained: index_breached.vc.zip
Once discovered, the data was reportedly scraped and posted to the dark web by a threat actor known as "USDoD." The hacker initially attempted to sell the database for , claiming it contained 2.9 billion records , including: Full names Social Security numbers (SSNs) Mailing addresses Phone numbers The Impact : Details on how their databases were structured
The "story" behind this file involves a sequence of security failures and dark web leaks that ultimately exposed the sensitive information of millions of individuals: The Accidental Exposure This file contained: Once discovered, the data was
Following the leak, multiple class-action lawsuits were filed against Jerico Pictures Inc. for failing to secure the data. You can find technical post-mortems and security analysis of the breach on platforms like the Huntress Blog or specialized security news sites like Risky Business .