Data breach
RocketText
- Records
- 31,582,200
- Breach date
- 1 January 2020Estimated
- Added
- 4 February 2025
What was exposed
5 types of data · 2 more reported
- Phone carriers31,126,216
- Names30,497,034
- Home addresses28,678,058
- Email addresses27,210,881
- IP addresses16,641,459
- PostcodesReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early 2020, the SMS marketing firm Rocket Text left a database exposed on the internet without a password, putting tens of millions of customer records at risk. Cybersecurity researcher Bob Diachenko documented the exposed MongoDB server in a report published on April 14, 2020, estimating that just over 63 million customer emails and phone numbers were unprotected. The indexed copy of the breach contains 31,582,200 rows, with an estimated attack date of January 1, 2020. The listing was added to the catalog on February 4, 2025. No hacking group has claimed the breach.
The exposed server was not protected by a password, which meant anyone who found it could read the records inside. Diachenko connected the Rocket Text database to ApexSMS, an earlier SMS marketing operation he had flagged in a disclosure to TechCrunch in May 2019. The two databases shared the same administrator, and the exposed Rocket Text instance even carried the "apexsms" name in its URL. Rocket Text later operated under the LaunchSMS name, according to Edgeworth Security.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
May 2019: Diachenko disclosed that ApexSMS, the predecessor operation later linked to Rocket Text, had left a customer database unprotected. TechCrunch reported on the finding.
April 14, 2020: Diachenko published his findings on Security Discovery, reporting that Rocket Text had exposed a similarly unsecured MongoDB database.
What Information Was Compromised?
Our analysis found the following data types in this breach: 30,497,034 names, 28,678,058 home addresses, 27,210,881 email addresses, 31,126,216 phone carrier records, and 16,641,459 IP addresses.
Diachenko's report on the exposed server described records containing first names, last names, email addresses, postal addresses, ZIP codes, and phone numbers. He assessed that the phone numbers in the database were cellphone numbers, though the data did not distinguish them from landlines.
No passwords were part of the indexed data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, home addresses, email addresses, and phone numbers together give scammers the raw material for targeted attacks. Diachenko warned specifically about smishing, or SMS phishing, in which criminals send text messages designed to trick recipients into clicking malicious links or handing over personal information.
Because the leaked phone numbers appear to be cellphone numbers, affected people may be targets for text-based scams impersonating banks, delivery companies, or government agencies. Home addresses and names also support phishing emails and fraudulent offers that look personal and credible. IP addresses add another identifier that can be used to profile victims.
What Is RocketText Doing in Response?
There is no verified public response from the company. Diachenko reported that he contacted the Rocket Text support address listed on its website, but his email was returned with a message saying the account did not exist.
What Should You Do If You Were Affected?
Be skeptical of unexpected text messages. Do not click links in texts from unknown numbers, and avoid replying, because a reply confirms your number is active.
If a text claims to come from a company you know, contact that company directly using the number on its official website.
Watch for phishing emails that reference your name or address. Treat urgent requests for payment or account details as suspect until verified.
Consider a carrier-level protection such as a port-out PIN or SIM lock, which makes it harder for criminals to hijack your phone number.
Review your financial accounts and credit reports for unfamiliar activity.
In the news
- Security Discovery – SMS Spam Operation Rebrands, Continues to Leak Customer Informationsecuritydiscovery.com (opens in a new tab)
- TechCrunch – SMS spammers doxxedtechcrunch.com (opens in a new tab)
- Edgeworth Security – Can Companies Protect Themselves from SMS Data Breaches?edgeworthsecurity.com (opens in a new tab)
