Data breach
PeopleDataLabs
- Records
- 416,656,027
- Breach date
- 16 October 2019Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 6 more reported
- Names416,656,027
- LinkedIn profiles416,656,027
- Email addresses146,049,081
- Phone numbers18,287,388
- EmploymentReported, not counted
- Job titlesReported, not counted
- EmployersReported, not counted
- Facebook profilesReported, not counted
- X / Twitter profilesReported, not counted
- GitHub profilesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In October 2019, security researchers uncovered an unsecured Elasticsearch server holding roughly 1.2 billion records of personal data, about 4 terabytes in total. The data included an index labeled "PDL" that pointed to People Data Labs, a San Francisco-based data enrichment company. Importantly, the exposed server was not owned by People Data Labs itself. Researchers and the company both concluded that a customer of the firm had left the database open online without a password.
October 16, 2019: Researchers Bob Diachenko and Vinny Troia discovered the unsecured Elasticsearch server and accessed its contents through a web browser without any authentication.
October 2019: Wired first reported the story, noting that People Data Labs co-founder Sean Thorne denied the company controlled the exposed server and that the server was taken offline after Troia notified the FBI.
What Information Was Compromised?
Our analysis found the following data types in this breach: 416,656,027 names and LinkedIn URLs, 146,049,081 email addresses, and 18,287,388 phone numbers.
Contemporaneous reporting by Wired and Computer Weekly described the full dataset as also containing employment histories, job titles, employers, geographic locations, and links to social media profiles on Facebook, Twitter, and GitHub.
Not every individual is affected by every type of data listed here.
No passwords, credit card numbers, or Social Security numbers were reported in the exposed data. Its value to criminals lies instead in the breadth of profile information tied to each person, which is precisely what makes phishing and impersonation convincing.
What Are the Potential Risks for Affected Individuals?
Because this dataset links names, employers, job titles, email addresses, and phone numbers, it is well suited to targeted phishing. An email that references your actual workplace or job title is far more convincing than a generic scam message. The same applies to phone-based fraud, where callers can use accurate employment details to appear legitimate.
Researchers also noted that much of the data appears to have been scraped from LinkedIn and other public sources, then aggregated. While that limits some kinds of harm, the combination into a single searchable database makes social engineering easier and can expose work email addresses for people who never expected them to circulate in this form.
What Is PeopleDataLabs Doing in Response?
According to Computer Weekly, People Data Labs told researchers the server did not belong to the company, and Vinny Troia said he found no evidence to contradict that denial. The company stated that once its data is delivered to customers, securing that database is the customer's responsibility, though it offers security audits and consultations. The server was taken offline after the FBI was notified. No individual or group ever claimed responsibility for the exposure, and it remains unclear how long the database was open before its discovery.
What Should You Do If You Were Affected?
Be cautious with unsolicited emails, calls, or messages that reference your employer, job title, or professional history. Verify requests for information or money through a known channel before responding.
Watch for phishing attempts at both your work and personal email addresses. If you appear in this dataset, attackers may try work addresses that were never publicly listed.
Review the privacy settings on your LinkedIn and other social media profiles and limit what is publicly visible.
No passwords were involved, so there is no mandatory password reset, but if you reuse passwords anywhere, switching to unique ones and a password manager is still good practice.
