Data breach
Instant Checkmate
- Records
- 20,220,810
- Breach date
- 12 April 2019Estimated
- Added
- 17 March 2025
What was exposed
3 types of data · 1 more reported
- Names20,211,353
- Email addresses20,209,634
- Phone numbers7,848,473
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In April 2019, a backup database containing customer records from the background check service Instant Checkmate was taken, and the data resurfaced more than three years later when it was published on a hacking forum. According to our investigation team, the listing tied to this incident holds more than 20.2 million records, most of them Instant Checkmate customer accounts. The breach only came to light in January 2023, when a member of the Breached forum leaked the data, prompting the company's parent, PeopleConnect, to confirm the incident.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
April 16, 2019: Per BleepingComputer, the leaked files covered customer information dating up to this date, when the backup database was created. Our investigation team estimates the attack date as April 12, 2019.
January 21, 2023: A member of the Breached hacking forum published the data, covering roughly 20.22 million customers of Instant Checkmate and its sister service TruthFinder.
February 3, 2023: Instant Checkmate posted a data security incident notice confirming the leak and describing its investigation.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (about 20.2 million), names (about 20.2 million), and phone numbers (about 7.8 million) across 20,220,810 total records.
The company's own notice lists additional fields not counted in our catalog: passwords stored in securely encrypted, hashed form using the scrypt algorithm, along with expired and inactive password reset tokens. The notice states the list does not include user activity such as searches or reports, and does not appear to involve payment information or readable passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is phishing. Attackers holding real names, email addresses, and phone numbers can craft convincing messages that appear to come from Instant Checkmate, TruthFinder, or other trusted services, hoping to trick recipients into handing over passwords or payment details.
Because the leak includes hashed passwords, there is also some risk to anyone who reused the same password on other sites, though scrypt hashing makes cracking difficult compared with older algorithms. Phone numbers in the mix open the door to smishing, or text-based phishing, and to unwanted spam calls. Given that the data circulated for years before it was disclosed, some of it may already have been used.
What Is Instant Checkmate Doing in Response?
In its notice, the company said it retained third-party forensic and threat intelligence advisors. Its investigation found no evidence of malicious activity on Instant Checkmate's own network. The company stated the data was stolen or acquired from a cloud storage location maintained by a former service provider it worked with during 2019, and that this provider had assured the company at termination that the data would be taken offline entirely. The notice also advises customers not to respond to suspicious communications.
What Should You Do If You Were Affected?
Change your Instant Checkmate password, and change it anywhere else you reused it.
Watch for phishing emails and texts that reference the service, your subscription, or a "security issue," and never click links or share credentials in response to unsolicited messages.
Be cautious with calls claiming to be from customer support; hang up and contact the company through its official website instead.
Consider enabling two-factor authentication on your email and other important accounts, since your email address is in the leaked data.
Monitor financial accounts for unusual activity, even though no payment information appears in the leak.
In the news
- BleepingComputer: TruthFinder, Instant Checkmate confirm data breach affecting 20M customersbleepingcomputer.com (opens in a new tab)
- Instant Checkmate: 2019 Account List Data Security Incident noticeinstantcheckmate.com (opens in a new tab)
- SC Media: Data breach impacts over 20M TruthFinder, Instant Checkmate customersscworld.com (opens in a new tab)
- IDStrong: PeopleConnect Suffers Data Breach Affecting Millionsidstrong.com (opens in a new tab)
