Breach report
Data BrokerExactis
A New Data Leak Reportedly Exposed 230 Million Americans' Personal Information
A little-known Florida marketing firm left a database of about 340 million records on American adults and businesses open to the internet, exposing hundreds of personal attributes per person without any hacking required.
Reported by Fortune
Records exposed
340M
About 340 million records (roughly 230 million consumers and 110 million business contacts)
Scale vs. largest on file
- When
- 2018
- How they got in
- Unsecured publicly accessible Elasticsearch database
- Sector
- Data Broker
In June 2018, security researcher Vinny Troia discovered that Exactis, a small marketing and data aggregation company based in Florida, had left a massive database publicly accessible on the internet. First reported by Wired, the exposed server held about 340 million records, split roughly between 230 million records on American consumers and 110 million on business contacts. By some estimates, that covered a large share of U.S. adults.
No hacking was needed to reach the data. The information sat in an Elasticsearch database, a popular search and analytics tool, configured without a password or other access controls. Troia said he found it using a widely used internet scanning tool, which meant others could easily have located it as well. It was unclear how long the database had been exposed, and there was no public evidence showing whether criminals had downloaded it before it was secured.
The records did not include Social Security numbers or payment card details, but they were unusually detailed. According to reports, each entry could contain hundreds of data points, including phone numbers, home and email addresses, ages and genders, and granular lifestyle details such as religion, whether a person smoked, the number and ages of their children, hobbies and pet ownership. This kind of profile is built for targeted advertising, but in the wrong hands it enables precise social engineering and identity fraud.
Exactis did not immediately respond to media inquiries, and it secured the database after being alerted. Within days, a class-action lawsuit was filed in federal court in Florida, arguing the company had failed to protect consumers who had never knowingly given it their information. The incident drew comparisons to the Equifax breach of the previous year, since the number of people potentially affected was larger, though the data was less sensitive.
The Exactis exposure became an emblem of the risks posed by the data brokerage industry. Companies that most people have never heard of compile detailed dossiers from public records, purchases and online activity, then store them with varying levels of care. The case added momentum to calls for U.S. privacy legislation similar to Europe's GDPR, which took effect weeks earlier, and it highlighted how often large exposures stem from simple database misconfigurations rather than sophisticated attacks.