IntelligenceX 2021 Data Breach

IntelligenceX Open-Source Intelligence Paste Scrape (2021): 92 Million Indexed Email Addresses Exposed

Platform · Data indexing and search services · Open-source intelligence platform · Global

IntelligenceX Open-Source Intelligence Paste Scrape (2021): 92 Million Indexed Email Addresses Exposed

Data indexing and intelligence search platform.

Compilation · ObscureIQ Intelligence
Breach Risk Index i
28/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
92.6MRecords
2021Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
CybersecuritySecurity CommunityUsers2021

Breach Summary

Intelligence X, the investigative search and archival platform operating at intelx.io, was targeted by a scraping attack in approximately August 2021. An attacker harvested data from the platform's publicly indexed "Pastes" section by running systematic searches across common email domains and exporting the results. The scraped archive contained over 80,000 pastes drawn from pastebin.com, pastie.org, and skidpaste.org, yielding approximately 92.6 million records and 46 million unique email addresses. Intelligence X characterized the incident as scraping of publicly indexed content rather than a breach of its core systems. The exposed data consisted of email addresses only, many appearing within email and password combolists or small databases that had been posted to paste sites. No passwords or additional personal information were confirmed as part of the scraped output. However, for the platform's user base of security researchers, journalists, and intelligence professionals, even email exposure carries distinct risks. Knowing who uses a breach intelligence tool can reveal investigative interests, active cases, or professional affiliations, making affected users potential targets for phishing, social engineering, or retaliation. No regulatory action or litigation specific to this incident has been publicly documented. Affected individuals should be alert to phishing attempts and review any accounts tied to exposed email addresses for signs of unauthorized access. Those working in sensitive investigative or security roles should consider whether their professional email exposure creates operational security concerns.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

92.6M records analyzed

About IntelligenceX

Intelligence X, operating at intelx.io, is a search engine and archival platform used by security researchers, journalists, investigators, and intelligence professionals to search leaked datasets, historical web content, and indexed records including WHOIS data and paste content. The platform aggregates and indexes material that has entered the public domain through breaches and leaks, making it searchable for investigative and threat intelligence purposes.

Why They Hold Your Data

OSINT and data-indexing platforms collect user accounts, searches, subscriptions, API activity, and in some cases investigation-linked behavioral records tied to intelligence gathering and data discovery.

Recent Developments

Intelligence X continues to operate as a threat intelligence and research platform. It has maintained its role as a tool for open-source intelligence work. No major organizational changes have been publicly reported.

Data Points Exposed

1 verified field types
Email Address

Breach Impact

In approximately August 2021 an attacker scraped the "Pastes" section of the Intelligence X platform by enumerating searches using common email domains, harvesting approximately 92.6 million email addresses that had appeared in paste content indexed by the service. The irony of a breach intelligence platform appearing in a breach intelligence dataset was noted in security community coverage. Intelligence X characterized the incident as scraping of publicly indexed content rather than a compromise of its core systems. The email addresses collected were not paired with passwords or additional personal information. No regulatory action or litigation specific to this incident has been documented.

Exploitation & Downstream Threats

• Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation