Data breach
Modern Business Solutions
- Records
- 58,847,822
- Breach date
- 8 October 2016Estimated
- Added
- 1 December 2024
What was exposed
7 types of data · 2 more reported
- Email addresses1
- Names1
- Home addresses1
- IP addresses1
- Employment1
- Job titles1
- Phone numbers1
- Dates of birthReported, not counted
- VehiclesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early October 2016, a database containing records on tens of millions of people was exposed online and briefly offered for public download. The data was traced to Modern Business Solutions, an Austin-based company that provides data storage and database hosting services, according to reporting by The Register and DataBreaches.net. Our investigation team has indexed 58,847,822 rows in connection with the incident. The records appear to have come from an unsecured MongoDB database, part of a wider wave of misconfigured MongoDB exposures that year. Modern Business Solutions has not publicly acknowledged the breach or explained how it came to hold the data.
Breach Timeline
October 8, 2016: A Twitter user posted a link to the exfiltrated data on a file-sharing site. The post was taken down quickly, but the data was uploaded again to other file-sharing services, according to DataBreaches.net.
October 11, 2016: DataBreaches.net and Risk Based Security published their findings and notified Modern Business Solutions. Neither firm reported receiving a reply from the company.
October 12, 2016: Researchers confirmed the exposed database had been secured and was no longer accessible, per reporting by SecurityAffairs.
October 18, 2016: DataBreaches.net reported that a vendor had listed the database for sale on the dark web for about $200.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses, email addresses, phone numbers, names, home addresses, and job information including job titles.
Independent reporting on the leak adds further detail. DataBreaches.net, which analyzed the dataset, said the records included full names, IP addresses, dates of birth, email addresses, vehicle data, and occupations. The Register reported the database also contained dates of birth. According to a dark web listing later reviewed by DataBreaches.net, the records did not include passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of a name, home address, phone number, email address, and date of birth gives scammers the raw material for targeted phishing. A message that references your real address or employer is far more convincing than a generic spam email.
Because email addresses were central to the leak, affected people may see a rise in phishing attempts by email, as well as by phone and text. Attackers can also use addresses from this dataset to try those same addresses on other services, checking whether the same credentials work elsewhere.
The leak included no passwords, according to the dark web listing reviewed by DataBreaches.net, which limits direct account takeover risk from this dataset alone. Still, the depth of personal detail here supports identity theft scams, fraud attempts, and doxxing, particularly because the data has circulated and been resold since 2016.
What Is Modern Business Solutions Doing in Response?
Public records show little in the way of company response. DataBreaches.net contacted the company twice in October 2016 and reported receiving no reply. The Register also noted at the time that the company had not publicly acknowledged the breach. Researchers did confirm the exposed database was secured after the findings were disclosed to the company. As of our most recent review of available reporting, DataBreaches.net has also noted that no notification campaign to affected individuals was publicly announced by the company.
What Should You Do If You Were Affected?
Treat unexpected emails, calls, or texts that reference your personal details as suspicious, even when they seem accurate.
Use unique passwords for every account and turn on two-factor authentication where it is offered, especially for email and banking.
Watch your credit reports and bank statements for activity you did not authorize, and consider placing a fraud alert or credit freeze with the major credit bureaus.
Be cautious with links in messages that cite your address, job title, or other details from this leak. Verify requests through a known official channel instead.
In the news
- The Register: Personal info on more than 58 million people spills onto the webtheregister.com (opens in a new tab)
- SecurityAffairs: 58M records dumped from Modern Business Systems DBsecurityaffairs.com (opens in a new tab)
- DataBreaches.net: Modern Business Solutions' leaky bucket provided a field day for downloadersdatabreaches.net (opens in a new tab)
