177: National Public Data

Summary of 177: National Public Data

by Jack Rhysider

47mJuly 21, 2026

Overview of Darknet Diaries 177: National Public Data

This episode connects two disturbing identity-theft stories with one of the largest personal-data leaks in recent memory. Jack Rhysider first tells the story of William Woods, whose identity was stolen for decades by Matthew Kearins after a wallet theft spiraled into a disastrous legal and medical ordeal for the victim. The episode then shifts to Luan Barbosa, also known online as USDOD, a Brazilian hacker who used stolen identities and weak portals to break into government-adjacent systems, including InfraGard. The main focus lands on National Public Data, a data broker run by Salvatore Verrini Jr., whose massive collection of personal records was breached and exposed billions of lines of sensitive data.

Key Stories and Incidents

William Woods vs. Matthew Kearins

  • In 1988, Matthew Kearins stole William Woods’ wallet, which contained crucial identity documents.
  • Matthew used those documents to assume William’s identity for decades:
    • got government ID, Social Security card, driver’s license
    • opened bank accounts
    • got jobs, married, and built a life under William’s name
  • When the real William discovered the fraud in 2019, the system failed him badly:
    • he was mistaken for the imposter
    • the bank called the police
    • he was sent to a mental hospital for months
    • he was later jailed under the wrong name
  • DNA testing eventually proved William was telling the truth.
  • The courts exonerated him and dropped the medical debt they had wrongly charged him.
  • Matthew was arrested and later sentenced to 12 years in federal prison.

USDOD / Luan Barbosa

  • Luan Barbosa, using the hacker handle USDOD, became known for identity-based intrusions and public data leaks.
  • He allegedly first became radicalized after a personal story involving cancer treatment, a hospital worker, and a vanished relationship in the U.S.
  • He used stolen identities and social engineering to access:
    • military-related systems
    • databases tied to the U.S. Department of Defense
    • InfraGard, an FBI-linked portal for critical infrastructure partners
  • He exploited a major InfraGard exposure to steal contact data on roughly 80,000 members.
  • His activity drew attention from law enforcement and cybersecurity researchers.

Salvatore Verrini Jr. and National Public Data

  • Salvatore Verrini Jr. built a data-broker business, including:
    • Records Check
    • Criminal Screen
    • National Public Data
  • The business collected huge amounts of personal data from:
    • public records
    • other data brokers
    • marketing and loyalty databases
    • social media and scraped sources
  • The company reportedly operated with minimal security and very little investment in protection.
  • Luan found a publicly accessible file, members.zip, containing source code and credentials.
  • By using reused passwords, he gained access to National Public Data and extracted:
    • 2.9 billion lines of data
    • about 277 GB of information
  • The breached data reportedly included:
    • full names
    • birth dates
    • Social Security numbers
    • addresses
    • email addresses
    • phone numbers
  • Luan posted the dataset for sale online for $3.5 million.

Main Takeaways

  • Small pieces of identity data are enough to destroy a life.
    • The William Woods story shows how name, birthday, and Social Security number can be enough to impersonate someone for years.
  • Data brokers create massive risk.
    • They aggregate highly sensitive information from many sources and often store it insecurely.
  • A breach of a data broker is especially dangerous.
    • Unlike a normal company leak, a broker’s entire business is built around collecting identity details, making the fallout much broader.
  • The system often punishes victims instead of protecting them.
    • William was treated as the criminal until DNA proved otherwise.
  • Privacy protections in the U.S. are weak and politically fragile.
    • The proposed American Privacy Rights Act was watered down and ultimately failed.
  • Once data is out, it is nearly impossible to contain.
    • Stolen personal data can be used for fraud, SIM swaps, loan applications, account takeovers, and long-term identity theft.

Privacy and Security Advice Mentioned

Jack closes with a strong privacy warning and recommends a few practical steps:

  • Use Signal instead of standard text messaging.
  • Use encrypted email providers like Proton or Tuta.
  • Use a privacy-focused browser such as Brave instead of Chrome.
  • Be cautious about how much personal information you share online.
  • Consider using:
    • burner email addresses
    • burner phone numbers
    • fake/public personas where appropriate
    • stronger privacy habits in everyday life

Outcome and Aftermath

  • William Woods was eventually vindicated and freed from blame.
  • Matthew Kearins was convicted and imprisoned.
  • Luan Barbosa / USDOD was doxxed, arrested in Brazil, and remains in custody there.
  • National Public Data remained controversial even after the breach, with lawsuits, congressional criticism, and ongoing concerns that the service still exists in some form.

Overall Message

This episode is a warning about the modern identity ecosystem:

  • personal data is widely collected,
  • poorly protected,
  • and easily weaponized.

Jack’s central argument is blunt: you cannot assume companies, brokers, or governments will protect your privacy for you. The best defense is to reduce your exposure before your data becomes someone else’s weapon.