Skip to content
Back to Blog
low severity September 05, 2024 · 3 min read

Jerico Pictures, Inc. D/B/A National Public Data Data Breach Notice (Oregon Attorney General)

If you received a notice from Jerico Pictures, Inc., here’s what the filing says was exposed, and what to do about it.

Jerico Pictures, Inc. D/B/A National Public Data notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 05, 2024.

Jerico Pictures, Inc. D/B/A National Public Data Data Breach Notice (Oregon Attorney General)

The filing from Jerico Pictures, Inc. doing business as National Public Data means that the personal information of 1,350,684 people is now outside the company’s control. If you received a notification letter, your records were part of that group.

Personal information in the hands of others cannot be taken back

The Oregon Attorney General’s office received the breach notification on September 05, 2024. The record lists only one category: personal information. No passwords, no financial account numbers, and no government identifiers such as Social Security numbers appear in the disclosed fields.

That absence is meaningful. Because no passwords were exposed, there is no need to change any password connected to National Public Data. The risk lies entirely in the non-credential personal details that were taken. Once those details leave the company, they remain available indefinitely for identity thieves, fraudsters, and anyone seeking to build a profile on you.

What the exposed personal information actually enables

Names combined with addresses, dates of birth, phone numbers, or email addresses remain valuable building blocks for identity theft even years later. Criminals can use them to attempt new account fraud, to impersonate you in customer service calls, or to link your details with information stolen elsewhere.

Because the filing does not name specific sub-fields, the exact combination that applies to any one person is known only through the letter sent by the company. The letter is the definitive source. If you have not received one, it is likely your information was not included. However, if you have moved since the incident, the letter may have gone to an old address. In that case you should contact Jerico Pictures, Inc. directly to confirm whether you were affected.

The scale of this filing

More than 1.35 million individuals appear in this single notification to Oregon. That volume reflects the nature of a people-search and data-broker operation that aggregates records over time. The company’s dual role — holding data and selling access to it — means the same information may already circulate in multiple places even before this incident.

No root cause is stated in the filing. The record does not say whether the data came from a single compromised system, an aggregated database, or another vector. It also does not describe how long the information may have been accessible. Those details remain unknown to the public.

What remains under your control

While the exposed personal information cannot be recalled, several practical steps can limit how effectively it can be used against you.

  • Monitor your credit reports for new accounts opened in your name. Request free weekly reports from Equifax, Experian, and TransUnion. Look for unfamiliar inquiries or accounts.
  • Place a fraud alert or credit freeze. A fraud alert requires lenders to verify your identity before opening new credit. A freeze stops new accounts entirely until you lift it. Either step forces an attacker to clear an extra hurdle.
  • Review bank and credit card statements carefully. Even without account numbers in the breach, thieves sometimes use personal details to authorize small test charges or to support phishing attempts that lead to real losses.
  • Be cautious with unsolicited calls or emails that reference your personal information. Scammers frequently use data from breaches to sound legitimate. Hang up or delete any contact that pressures you to act immediately.
  • Consider identity theft protection services that include dark-web monitoring and restoration assistance. These cannot prevent misuse but can speed recovery if fraud appears.

The letter is still the only reliable test

The filing does not state when the incident occurred, only that the notification reached the Oregon Department of Justice on September 05, 2024. Without an incident date, there is no way to measure any delay or to anchor a “have you moved” test to a meaningful cutoff. The company is required to notify affected Oregon residents directly, usually by mail. Absence of a letter is therefore the clearest practical indicator that your records were not part of this particular disclosure. Anyone uncertain because of a recent address change should reach out to National Public Data to ask.

This notification adds one more large set of personal records to the pool of information already circulating from data-broker incidents. The exposure cannot be undone, but its practical impact depends on how closely you watch the accounts and identities built from those details in the months and years ahead.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed September 05, 2024
Last reviewed July 22, 2026
Affected 1350684
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email