Data breach
ApexSMS
- Records
- 88,434,530
- Breach date
- 1 January 2019Estimated
- Added
- 3 January 2025
What was exposed
6 types of data · 4 more reported
- Phone numbers88,432,803
- Phone carriers86,840,390
- Names71,212,387
- Home addresses64,427,802
- Email addresses51,643,430
- IP addresses49,143,311
- CitiesReported, not counted
- StatesReported, not counted
- CountriesReported, not counted
- PostcodesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In 2019, a database belonging to an operation called ApexSMS was found sitting on the internet with no password protecting it. Security researcher Bob Diachenko discovered the exposed MongoDB instance on April 11, 2019, and reported his findings to TechCrunch, which published an investigation the following month. The database held roughly 80 million records, described as marketing "leads," tied to a high-volume SMS operation that sent spam text messages pushing recipients toward scam websites promising free money.
The investigation team indexes this listing at 88,434,530 rows, with an estimated breach date of January 1, 2019. The externally verified discovery of the exposed server came later, in April 2019, and it is not known how long the database was open to the internet or whether anyone besides the researcher accessed it. TechCrunch noted that the server was pulled offline by coincidence before the outlet could contact the operators.
April 11, 2019: Researcher Bob Diachenko discovers an unprotected MongoDB instance named ApexSMS, containing about 80 million lead records, indexed by public search engines.
May 9, 2019: TechCrunch reports on the exposure, documenting the spam operation and identifying companies linked to it, including ApexSMS and Mobile Drip.
April 14, 2020: Diachenko reports that Rocket Text, which he identified as formerly ApexSMS, exposed another database with just over 63 million customer emails and phone numbers.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses (49,143,311 records), email addresses (51,643,430), phone numbers (88,432,803), names (71,212,387), home addresses (64,427,802), and phone carrier information (86,840,390).
Diachenko's original findings described records that included MD5-hashed email addresses, first and last names, city, state, country, and zip code, IP addresses, phone numbers, mobile carrier network, and line type indicating whether a number was mobile or landline. TechCrunch also reported that the database recorded which recipients clicked links in spam messages and who replied.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Phone numbers, names, and addresses in the hands of spammers or scammers create openings for smishing, which is phishing carried out by text message. Diachenko himself warned that large phone number leaks expose people to exactly this risk, since criminals can send convincing texts impersonating banks, delivery services, or familiar contacts.
Because the records pair phone numbers with names, addresses, and carrier details, the data can also support targeted scam calls, identity-based social engineering, and attempts to verify or enrich other leaked datasets. The fact that the same operator later leaked a second, similarly unprotected database under a new brand suggests the information was not treated with care after the initial exposure.
What Is ApexSMS Doing in Response?
The picture here is murky because ApexSMS itself was poorly understood. TechCrunch reported that little was known about the outfit and that its website was little more than a login page. When reached, Mobile Drip, the SMS platform tied to the operation, denied any connection to ApexSMS and said it was investigating the extent of any exposure, had engaged an outside legal firm, and had hired a cybersecurity firm to perform a security audit. Mobile Drip also claimed its servers had always been password protected, a claim TechCrunch disputed. TechCrunch reported that it received no response from ApexSMS or the operators named in the database.
What Should You Do If You Were Affected?
Be skeptical of unexpected text messages, especially those with links, even if the sender appears friendly or familiar. Do not reply, since a reply confirms your number is active.
If a text claims to be from a company, contact that company directly using the phone number or website listed on your account, not the details in the message.
Watch for follow-up scam calls and emails that reference personal details such as your name or address, and treat any request for payment or account credentials as suspicious.
Consider reporting spam texts to your carrier by forwarding the message, and report fraud attempts to the Federal Trade Commission.
In the news
- TechCrunch: An unsecured SMS spam operation doxxed its ownerstechcrunch.com (opens in a new tab)
- Security Discovery: Massive SMS Bombing Operation Uncoveredsecuritydiscovery.com (opens in a new tab)
- Security Discovery: SMS Spam Operation Rebrands, Continues to Leak Customer Informationsecuritydiscovery.com (opens in a new tab)
- SiliconANGLE: 80M records exposed in text marketing company ApexSMS data breachsiliconangle.com (opens in a new tab)
