IntelX WHOIS 2021 Data Breach

WHOIS Domain Registration Data Breach: 425M Records Including Names, Phone & Home Address

Data Broker / Public Records Exposure · Domain registration and WHOIS records · WHOIS data corpus · Global

WHOIS Domain Registration Data Breach: 425M Records Including Names, Phone & Home Address

WHOIS domain registration data corpus scraped and indexed by Intelligence X

Scrape · ObscureIQ Intelligence
Breach Risk Index i
41/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
425.3MRecords
2021Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Cloud MisconfigurationData & IdentityData BrokersThird Party2021

Breach Summary

A threat actor identified as "pompompurin" scraped and publicly released a dataset of historical WHOIS domain registration records in 2021, compiled from the Intelligence X (intelx.io) platform. The scrape covered WHOIS records spanning 2012 to 2021 and resulted in over 425 million unique records being exposed. No intrusion into Intelligence X's own systems occurred. The data was extracted by exploiting access to the platform's indexed public records, then shared on hacking forums. Pompompurin was later identified as Conor Brian Fitzpatrick, the operator of BreachForums, who was arrested by U.S. authorities in 2023. The exposed data included email addresses, names, phone numbers, and home addresses submitted by individuals when registering internet domains. This information was originally collected through the WHOIS system, a public directory of domain ownership, before widespread adoption of privacy protection services that shield registrant details. Because the data links real people to specific websites and internet infrastructure, it is particularly useful for targeted attacks. Affected individuals face elevated risks of spearphishing, social engineering, and doxxing, as the dataset enables bad actors to build detailed profiles connecting identities to online assets. No regulatory enforcement actions or mandatory breach notifications have been publicly reported in connection with this dataset. The data subjects are third parties whose information was captured in WHOIS records and later aggregated by Intelligence X, meaning many individuals may be unaware their details were included. Anyone who registered a domain between 2012 and 2021 without privacy protection should treat their email address, phone number, and home address as potentially compromised and be alert to unsolicited contact or targeted scams.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

425.3M records analyzed

About IntelX WHOIS

Intelligence X, operating at intelx.io, is a search engine and data archive service used by security researchers, journalists, and intelligence professionals to access historical records, leaked datasets, and WHOIS domain registration data. The platform indexes and makes searchable large corpora of data that are otherwise difficult to query systematically. It is operated as a private commercial and research tool.

Why They Hold Your Data

WHOIS corpora aggregate domain registration data, registrant names, contact details, organization records, and infrastructure-linked ownership information across internet registration systems.

Recent Developments

Intelligence X continues to operate as a threat intelligence and open-source research tool. No major organizational changes have been publicly reported. The platform's role in the security research ecosystem has remained consistent.

Data Points Exposed

4 verified field types
Email Address
Full Name
Phone Number
Physical address High

Breach Impact

The 2021 IntelX WHOIS dataset represents a scrape of historical WHOIS domain registration records compiled and released by an actor identified as Pompompurin — later unmasked as BreachForums operator Conor Brian Fitzpatrick, who was arrested in 2023. The dataset contained over 400 million unique email addresses extracted from domain registration records, along with names, phone numbers, and home addresses submitted by registrants before WHOIS privacy protections became standard. No breach of Intelligence X's own systems was involved. The significance is the scale of the aggregation: historical WHOIS data collected personal contact information that registrants had no expectation would be compiled into a searchable corpus and republished.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation