Data & Leads 2018 Data Breach

Data & Leads B2B Contact Aggregator Breach: 44M Professional Records Including Job Titles & Addresses

Data Broker · Business data extraction and lead generation · Lead data provider · Saudi Arabia

Data & Leads B2B Contact Aggregator Breach: 44M Professional Records Including Job Titles & Addresses

Marketing / B2B lead-generation data aggregator.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
24/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
44.3MRecords
2018Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Researcher disclosureDatabase ExposureData & IdentityData BrokersThird Party2018

Breach Summary

In November 2018, security researcher Bob Diachenko identified an unprotected, publicly facing Elasticsearch database containing over 44 million records, later linked to marketing/lead-generation company Data & Leads. Exposed data included email addresses, names, phone numbers, physical and IP addresses, and employment information (employers, job titles). Data & Leads did not respond to inquiries and its website went offline shortly afterward. The data was added to Have I Been Pwned.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

44.3M records analyzed

About Data & Leads

Data & Leads was a marketing and B2B lead-generation company that aggregated professional and consumer contact records. It maintained large volumes of names, emails, phone numbers, addresses, and employment details used for sales/marketing lead generation.

Why They Hold Your Data

Lead-data providers collect and aggregate business and contact records, marketing profiles, and outreach-linked information for sales and lead-generation use.

Recent Developments

In November 2018, researcher Bob Diachenko found an unprotected Elasticsearch database (~44M records) linked to Data & Leads. The company did not respond to inquiries, and its website subsequently went offline.

Data Points Exposed

7 verified field types
Email Address
Employer
Full Name
IP Address
Job Information
Phone Number
Physical address High

Breach Impact

The exposure tied names, emails, phone numbers, physical addresses, employers, and job titles for tens of millions of individuals, enabling targeted phishing, employment/business-themed social engineering, SIM-swap targeting, and doxxing. Because affected people were aggregated as marketing "leads" (often without a direct relationship), most had no way to know their data was held.

Exploitation & Downstream Threats

• Targeted phishing and business/employment-themed social engineering | • SIM-swap targeting using phone numbers | • Doxxing and physical targeting from exposed addresses | • Lead/identity enrichment for downstream fraud

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
RD
Threat Actor: Researcher disclosure
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation