Data breach
Exactis
- Records
- 109,999,829
- Breach date
- 1 June 2018Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 3 more reported
- Home addresses109,999,829
- Names109,999,825
- Email addresses44,786,184
- IP addresses44,133,303
- Phone numbersReported, not counted
- ReligionReported, not counted
- InterestsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In June 2018, Exactis, a small data broker based in Palm Coast, Florida, left a database containing roughly 340 million records exposed on a publicly accessible server. Security researcher Vinny Troia of Night Lion Security discovered the database using the search engine Shodan, which finds internet-connected servers. The records sat in an Elasticsearch database with no firewall protection, meaning anyone who knew where to look could have downloaded the data. According to our investigation team's indexing, this listing contains about 110 million records, a figure that aligns with the business contact portion of the exposure that Troia and Wired described. Exactis compiled and sold this data for marketing purposes, so the exposed material was the company's product rather than its own customer files.
Early June 2018: Troia locates the unsecured Elasticsearch database via Shodan and contacts Exactis and the FBI. The company secures the server shortly afterward.
June 27, 2018: Wired publishes its report on the exposure after independently verifying a sample of the data.
March 18, 2019: Wired follows up with Exactis CEO Steve Hardigree, who disputes calling the incident a breach and says logs and an external assessment found no unauthorized access beyond Troia.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names: about 110 million records
Home addresses: about 110 million records
Email addresses: about 44.8 million records
IP addresses: about 44.1 million records
Reporting by Wired and TechTarget described each record as containing more than 400 variables, including phone numbers, smoking habits, religious affiliation, pet ownership, children's ages, and interests. The exposed database did not appear to include Social Security numbers, credit card details, or passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the data lacks financial details and credentials, experts said the material would be most useful for social engineering rather than direct account theft. Fraudsters can combine names, home addresses, email addresses, and detailed personal profiles to craft convincing phishing emails, phone scams, and targeted spam. The depth of the profiling data, covering habits and family details, can make fraudulent messages appear more legitimate. It also remains unknown whether malicious actors copied the database before Troia reported it, since the server was open for an extended period and the company did not confirm who accessed it.
What Is Exactis Doing in Response?
According to TechTarget, Exactis secured the server after Troia alerted the company. CEO Steve Hardigree told FlaglerLive that the incident was neither a breach nor a leak because nothing was stolen, and said the company was working with the researcher and the Florida Attorney General's office. Wired reported that Exactis did not respond to repeated requests for comment in June 2018, and Hardigree later said company logs and an external security assessment indicated no unauthorized individuals accessed the data apart from Troia. The company, which had roughly ten employees, closed after the episode.
What Should You Do If You Were Affected?
Be cautious with unexpected emails, calls, or texts. Scammers can use your name, address, and personal details to appear credible.
Do not click links or open attachments in unsolicited messages, and verify requests for money or information through a separate, known channel.
Watch your financial accounts and credit reports for unfamiliar activity. You can request free credit reports from the three major bureaus.
Consider placing a fraud alert or security freeze on your credit file if you notice suspicious activity.
Use unique passwords and enable two-factor authentication where available, since email addresses tied to this data could be targeted in phishing attempts.
In the news
- Wired: Marketing Firm Leaked Database With 340 Million Recordswired.com (opens in a new tab)
- Wired: Here's What It's Like to Accidentally Expose the Data of 230M Peoplewired.com (opens in a new tab)
- TechTarget: Exactis leak exposes database with 340 million recordstechtarget.com (opens in a new tab)
- MarketWatch: What is Exactis, and how could it have leaked the data of nearly every American?marketwatch.com (opens in a new tab)
