Pipl 2019 Data Breach

Pipl People-Search Platform Breach: 52M Records Including Phone Numbers & Religion

Data Broker · Identity search, person resolution, and investigative data services · Identity search and people-data provider · Global

Pipl People-Search Platform Breach: 52M Records Including Phone Numbers & Religion

Identity resolution and people search platform.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
52.1MRecords
2019Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Data & IdentityData BrokersThird Party2019

Breach Summary

Pipl, a people-search platform that aggregates public records and contact data into searchable person profiles, was at the center of a 2019 data exposure that affected approximately 52 million records. Security researcher Bob Diachenko discovered an unsecured MongoDB database left publicly accessible without a password, meaning anyone on the internet could view or download its contents. Pipl stated that its own systems were not directly breached, attributing the exposure to a third-party instance of its aggregated data. The exposed records included names, phone numbers, home addresses, and religion. The inclusion of religious affiliation is notable: it is a protected category of personal information that individuals rarely share publicly and that carries real risk if misused. Because Pipl's core function is identity resolution, the database was already structured and normalized for profiling, making it far easier for bad actors to use than a raw data dump. The consolidated format enabled targeted phishing, doxxing, stalking, and cross-referencing with other leaked datasets. No confirmed regulatory action or litigation specific to this incident has been publicly documented. Affected individuals were not necessarily Pipl customers and may have had no awareness their information was part of the platform's index at all. For those whose data was exposed, the practical risks include unwanted contact, identity fraud, and targeted scams built on detailed personal profiles they never knowingly provided.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

52.1M records analyzed

About Pipl

Pipl is an identity resolution and people-search data broker that aggregates public records, social media profiles, contact information, and other personally identifiable data into searchable person profiles. The platform is marketed to fraud investigators, law enforcement, financial institutions, and other professional verification use cases rather than the general public. Pipl operates as a private company and is used in due diligence and background research workflows.

Why They Hold Your Data

Identity-resolution and people-search providers aggregate names, contact data, aliases, employment records, social identifiers, and linked identity signals into searchable investigative profiles.

Recent Developments

Pipl continues to operate as a professional identity data service. The company has maintained a low public profile with limited publicly available information about organizational or financial developments. Its business model — aggregating public records for professional search use — has faced increasing scrutiny as privacy regulations have expanded globally.

Data Points Exposed

4 verified field types
Full Name
Phone Number
Physical address High
Religion

Breach Impact

In June 2019 security researcher Bob Diachenko discovered an unsecured MongoDB database exposing approximately 188 million records attributed to Pipl data. The dataset included names, phone numbers, home addresses, and religion fields drawn from Pipl's aggregated profile corpus. Pipl maintained that its own systems had not been compromised, characterizing the exposed database as a third-party instance rather than its primary platform. No confirmed regulatory action or litigation specific to this incident has been widely documented. The incident raised questions about the data governance practices of identity aggregators whose business model requires accumulating sensitive personal information from diverse sources.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation