Data breach
Unknown Breach (not SOCRadar)
- Records
- 332,969,030
- Breach date
- 3 August 2024Estimated
- Added
- 1 December 2024
What was exposed
1 type of data
- Email addresses1
About this breach
In August 2024, a dataset of more than 332 million email addresses surfaced on BreachForums, a well-known cybercrime forum, posted under a claim that the addresses had been scraped from SOCRadar, a company that operates a threat intelligence platform at socradar.io. The listing, which our investigation team catalogued under an estimated attack date of August 3, 2024, is not a traditional breach of a company's internal systems. SOCRadar has denied that its systems or customer data were compromised, saying the data actually came from public Telegram channels and that the actors behind the post misrepresented its origin.
According to Cyberinsider, a threat actor using the alias "Dominatrix" uploaded the dataset to BreachForums on August 3, 2024, stating that another hacker known as "USDoD" had scraped socradar.io in July 2024 and had offered the data for sale for $7,000 before Dominatrix purchased it and released it for free.
July 2024: A hacker using the alias "USDoD" allegedly scraped socradar.io and compiled a dataset of roughly 332 million email addresses, according to the BreachForums post cited by Cyberinsider.
August 3, 2024: The alias "Dominatrix" published the full dataset for free on BreachForums.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
The dataset, roughly 14 GB in CSV format according to SynScan, contained about 332 million rows, of which approximately 282 million were unique email addresses in valid format. No passwords, names, or other personal details were included in the dataset.
Not every individual is affected by every type of data listed here.
Because the dataset consists only of email addresses parsed, per the forum post, from stealer logs and combolists, the direct exposure is limited to the addresses themselves.
What Are the Potential Risks for Affected Individuals?
An email address alone is a low-sensitivity data point, but a list of this size still carries real risks. Cybersecurity experts cited in coverage of the leak warned of phishing attacks, spam campaigns, and brute-force login attempts, particularly when email addresses are combined with passwords taken from unrelated breaches. People who reuse the same password across accounts face the greatest danger, since attackers routinely pair leaked email lists with credential databases from other incidents. A very large, freely distributed email list is also attractive to spammers and to criminals crafting targeted phishing messages, because it offers a huge volume of deliverable addresses at no cost.
What Is Unknown Breach (not SOCRadar) Doing in Response?
SOCRadar investigated the claim and publicly rejected it. The company stated there was "no data breach involving our customers or SOCRadar's internal systems." Its Chief Security Officer, Ensar Seker, told Cyberinsider that the threat actors had impersonated a legitimate company, subscribed to the platform, and obtained the names of Telegram channels used to collect email addresses, then "falsely represented this data as being sourced from SOCRadar." The company said the actors provided no evidence the data was gathered from its platform and characterized the dataset as scraped from publicly available sources. Because the true origin of the email addresses remains contested, no organization has issued individual breach notifications.
What Should You Do If You Were Affected?
Check whether your email address appears in this or related datasets using the search tool.
If you use the same password on multiple accounts, change it and use a unique password for every important account, especially email and banking.
Turn on multi-factor authentication wherever it is offered, so a leaked email address alone is not enough to break in.
Be cautious with unexpected emails. Attackers often use leaked address lists for phishing, so verify links and sender addresses before clicking.
Treat a sudden rise in spam as a signal. It may indicate your address is circulating on cybercrime forums.
