Data breach
Fractal
- Records
- 12,262,912
- Breach date
- 1 May 2021Estimated
- Added
- 4 February 2025
What was exposed
6 types of data · 2 more reported
- Employment12,262,912
- Employers12,262,912
- Job titles12,262,912
- Names12,262,687
- Phone numbers12,215,416
- Email addresses12,166,159
- PasswordsReported, not counted
- CountriesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
An exposed database tied to Fractal, the artificial intelligence and analytics firm behind fractal.ai, left millions of records with personal and professional details open to unauthorized access. According to our investigation team, the incident is estimated to have occurred around May 1, 2021, and involves 12,262,912 rows of data. No individual or group has publicly claimed responsibility for the breach.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
May 1, 2021: HEROIC dates the breach to this day, reporting that records tied to the company circulated on dark web forums and Telegram channels.
October 30, 2024: LeakedSource indexed the breach in its database, describing it as stemming from an exposed server connected to the company's Customer Genomics division and reporting roughly 12.2 million affected users.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names, present in 12,262,687 records
Job titles, present in all 12,262,912 records
Job company names, present in all 12,262,912 records
Phone numbers, present in 12,215,416 records
Email addresses, present in 12,166,159 records
LeakedSource additionally reported hashed passwords, first and last names, and country data among the compromised fields. HEROIC reported a similar set for a subset of 404,180 records tied to the fractal.ai domain.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The mix of contact details and employment information creates several practical risks. Names combined with email addresses and job details can support convincing phishing messages that appear to come from a colleague, employer, or business contact. Phone numbers in the wrong hands can invite smishing, which is phishing by text message, and can support SIM swapping attempts aimed at intercepting one-time passcodes sent by SMS.
Where password hashes were part of the exposed data, attackers who crack them gain credentials that may work on other accounts if a person reused the same password elsewhere. HEROIC analysts described this as a chained attack risk, in which the leaked combination of names, phone numbers, and password hashes can be used to move from a phishing message to an account takeover. Even without credentials, the dataset resembles a marketing contact list, which scammers can use for targeted cold calls, fake recruiter outreach, and fraudulent business offers that exploit the job and company information in each record.
What Should You Do If You Were Affected?
If you had an account with Fractal or its services, change that password now, and change the password on any other account where you reused it.
Use a unique, strong password for every account, and consider a password manager to keep track of them.
Turn on two-factor authentication where it is offered, preferably using an authenticator app rather than text messages.
Be cautious with unexpected emails or texts that reference your job, employer, or a business opportunity, and do not click links or share codes from unsolicited messages.
If you receive calls or texts claiming to be from your bank, a recruiter, or a service provider, verify the contact independently before responding.
