97,257 SSNs From the USDA RD Loan Breach Surfaced Online
In June 2022, USDA RD Loan, a U.S.-based financial lending service, suffered a database breach that exposed 97,257 customer records. The compromised data included some of the most sensitive personal identifiers a breach can expose: Social Security Numbers, alongside full names, phone numbers, email addresses, and gender information. This breach recieved limited public attention but represents a serious identity theft risk for nearly one hundred thousand Americans.
How Attackers Can Exploit the USDA RD Loan Breach
Social Security Numbers are the cornerstone of identity fraud in the United States. With SSNs, full names, phone numbers, and email addresses all in a single dataset, a threat actor can open fraudulent lines of credit, file false tax returns, impersonate victims with financial institutions, and launch highly targeted phishing or vishing campaigns. No passwords were involved, meaning the risk is not credential-based but rather long-term identity exploitation that can be seperate and distinct from any single account compromise.
What Was Exposed in the USDA RD Loan Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Gender
- Social Security Numbers
Why the USDA RD Loan Breach Still Matters
Unlike password breaches, SSN exposure has no simple fix. You cannot change your Social Security Number. Affected individuals remain at elevated risk of identity fraud for years after the initial breach. Financial institutions, the IRS, and credit bureaus all rely on SSNs as primary identifiers, meaning this data can be exploited across a wide range of financial and governmental systems long after the breach itself is forgotten.
How a Database Breach Works
A database breach occurs when an unauthorized party gains access to a backend data store, typically through an exploited vulnerability, misconfigured cloud storage, or stolen credentials. In financial services, large customer databases are attractive targets because they aggregate high-value PII in a single location. Once an attacker exports the data, it can be packaged and sold on dark web marketplaces where buyers purchase it specifically for identity fraud operations.
Check If Your Data Was Exposed
HEROIC's DarkWatch monitors over 400 billion leaked records, including data from breaches like USDA RD Loan. Search your email address now to find out if your personal information is in circulation on the dark web and take steps to protect your identity before further harm occurs.
Breach Breakdown
97,257 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds