Impact & Downstream Threats
This breach carries critical risk due to the extraordinary depth of profiling data — combining financial, demographic, behavioral, and contact information across 110 million individuals.
- Synthetic identity construction using full demographic + financial profile data
- Targeted phishing leveraging personal interests, religion, ethnicity, and family structure
- Financial fraud using income, net worth, credit status, and investment data
- Real estate and title fraud using homeownership + address data
- Doxxing risk due to physical address, phone, email, and family linkage
- Employment-based social engineering using occupation and employer data
Data brokers collect and cross-reference hundreds of attributes per individual. When exposed, it enables highly personalized attacks.
Breach Intelligence
Executive Summary
In June 2018, security researcher Vinny Troia of Night Lion Security discovered that Exactis had accidentally exposed a massive database containing approximately 340 million records on a publicly accessible server.
The dataset spanned multiple terabytes with hundreds of data fields per individual — one of the most granular consumer profiling datasets ever publicly exposed.
A subset of 132 million unique email addresses was later indexed by Have I Been Pwned.
The breach underscored the systemic risks of data broker operations, where personal information is compiled, enriched, and resold with minimal oversight.
About Exactis
Exactis was a Florida-based data broker that compiled and aggregated premium consumer and business data for marketing and profiling purposes. The company maintained one of the largest known consumer databases in the United States.
- Compiled detailed consumer marketing profiles
- Aggregated data from public and commercial sources
- Sold enriched datasets to advertisers and marketers
- Maintained records on over 200 million U.S. adults
If your data was collected by any U.S. data broker prior to 2018, your information may be included.
Data Points Exposed
Dark Web Verification
Status: Confirmed — data circulating across multiple channels
- Dataset containing ~110M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Multiple instances observed on dark web forums and data trading channels
- Dataset combined with other breaches to create enriched identity packages
Due to profiling depth, this remains one of the most exploitable datasets in circulation.
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Non-clients may request a breach impact review.
Frequently Asked Questions
In June 2018, security researcher Vinny Troia discovered that Exactis had left a database containing ~340 million records publicly accessible, spanning financial, demographic, and behavioral information.
Over 20 categories including names, emails, addresses, phone numbers, dates of birth, income levels, credit status, net worth, family structure, ethnicity, religion, and personal interests.
Approximately 110 million unique records. 132 million unique email addresses were indexed by Have I Been Pwned.
Yes. Independently verified by Vinny Troia of Night Lion Security and confirmed through HIBP and DataBreach.com.
The data has been observed circulating across dark web forums. The depth of profiling data makes it valuable for identity theft, synthetic fraud, and social engineering.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits and threat monitoring for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer or data subject of Exactis
- Or concerned about data broker exposure
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
