Contact Management Platform · Personal and professional contact management application · Contact management and networking app · Global
Contact management and networking app.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In February 2020, a large trove tracked as "db8151dd" was found exposed on a publicly facing Elasticsearch server and later confirmed by the contact-management app Covve as coming from a legacy, decommissioned system. It contained roughly 103 million records covering about 22 million individuals, including names, job titles, email addresses, phone numbers, and physical addresses. Many affected people were third-party contacts stored/enriched by Covve users rather than Covve customers. The data was provided to Have I Been Pwned.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
22.8M records analyzed
Covve is a contact-management / smart-address-book app (developed in Cyprus) that helps users organize professional contacts and enriches contact records with data gathered from the internet.
Contact-management apps collect personal and professional contact records, emails, phone numbers, notes, network relationships, and account data tied to address-book organization and networking workflows.
In February 2020, an exposed publicly facing Elasticsearch database (initially tracked as "db8151dd") was found and later confirmed by Covve as originating from a legacy, decommissioned system. It contained ~103 million records covering about 22 million people.
Because Covve enriched and stored contact records for people who were merely in users' address books (not Covve users themselves), the exposure affected millions of third parties with no direct relationship to the app. Exposed names, job titles, emails, phones, and addresses enable targeted phishing, business-themed social engineering, and doxxing.
• Targeted phishing and business-themed social engineering using name/job/employer | • SIM-swap targeting using phone numbers | • Doxxing and physical targeting from exposed addresses | • Identity enrichment across contact graphs
A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Attribution based on available breach intelligence.
Read the full threat-actor profile →Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation