Data Broker / Public Records Exposure · Domain registration and WHOIS records · WHOIS data corpus · Global
WHOIS domain registration data corpus scraped and indexed by Intelligence X
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
A threat actor identified as "pompompurin" scraped and publicly released a dataset of historical WHOIS domain registration records in 2021, compiled from the Intelligence X (intelx.io) platform. The scrape covered WHOIS records spanning 2012 to 2021 and resulted in over 425 million unique records being exposed. No intrusion into Intelligence X's own systems occurred. The data was extracted by exploiting access to the platform's indexed public records, then shared on hacking forums. Pompompurin was later identified as Conor Brian Fitzpatrick, the operator of BreachForums, who was arrested by U.S. authorities in 2023. The exposed data included email addresses, names, phone numbers, and home addresses submitted by individuals when registering internet domains. This information was originally collected through the WHOIS system, a public directory of domain ownership, before widespread adoption of privacy protection services that shield registrant details. Because the data links real people to specific websites and internet infrastructure, it is particularly useful for targeted attacks. Affected individuals face elevated risks of spearphishing, social engineering, and doxxing, as the dataset enables bad actors to build detailed profiles connecting identities to online assets. No regulatory enforcement actions or mandatory breach notifications have been publicly reported in connection with this dataset. The data subjects are third parties whose information was captured in WHOIS records and later aggregated by Intelligence X, meaning many individuals may be unaware their details were included. Anyone who registered a domain between 2012 and 2021 without privacy protection should treat their email address, phone number, and home address as potentially compromised and be alert to unsolicited contact or targeted scams.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
425.3M records analyzed
Intelligence X, operating at intelx.io, is a search engine and data archive service used by security researchers, journalists, and intelligence professionals to access historical records, leaked datasets, and WHOIS domain registration data. The platform indexes and makes searchable large corpora of data that are otherwise difficult to query systematically. It is operated as a private commercial and research tool.
WHOIS corpora aggregate domain registration data, registrant names, contact details, organization records, and infrastructure-linked ownership information across internet registration systems.
Intelligence X continues to operate as a threat intelligence and open-source research tool. No major organizational changes have been publicly reported. The platform's role in the security research ecosystem has remained consistent.
The 2021 IntelX WHOIS dataset represents a scrape of historical WHOIS domain registration records compiled and released by an actor identified as Pompompurin — later unmasked as BreachForums operator Conor Brian Fitzpatrick, who was arrested in 2023. The dataset contained over 400 million unique email addresses extracted from domain registration records, along with names, phone numbers, and home addresses submitted by registrants before WHOIS privacy protections became standard. No breach of Intelligence X's own systems was involved. The significance is the scale of the aggregation: historical WHOIS data collected personal contact information that registrants had no expectation would be compiled into a searchable corpus and republished.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation