NetProspex 2016 Data Breach

NetProspex Dun & Bradstreet B2B Marketing Database Breach (2016): 33 Million Professional Contact Records Exposed

Data Broker · B2B contact data aggregation and sales intelligence · Marketing data broker and lead intelligence provider · USA

NetProspex Dun & Bradstreet B2B Marketing Database Breach (2016): 33 Million Professional Contact Records Exposed

B2B marketing data service (now part of Dun & Bradstreet).

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
24/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
33.7MRecords
2016Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Data & IdentityData BrokersThird Party2016

Breach Summary

NetProspex, a B2B marketing database service operated by Dun & Bradstreet, exposed 33.7 million professional records when the data leaked online in 2016. The company did not suffer a direct system breach. Instead, Dun & Bradstreet concluded that a customer who had purchased the dataset lost control of it, allowing the records to circulate publicly. The individuals in the database had no direct relationship with NetProspex; their contact information had been aggregated from various sources and packaged as a commercial marketing asset. The exposed records included names, email addresses, job titles, employer names, phone numbers, and physical addresses, all organized specifically for outbound business targeting. That structure is what makes the exposure particularly useful to bad actors. A dataset pre-sorted by employer, role, and contact details provides ready-made material for spearphishing campaigns, executive impersonation, and business-focused fraud at scale. No formal notifications were issued to affected individuals, which is consistent with how B2B data brokers operate: the people whose information is sold are third parties, not customers, and are generally outside the scope of standard breach notification obligations. For those whose records appeared in the dataset, the practical risk is ongoing. The data remains well-suited to targeted phishing and social engineering attacks, particularly those crafted to appear as legitimate business communications.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

33.7M records analyzed

About NetProspex

NetProspex was a B2B marketing data service that compiled and sold contact information for professionals across corporate America, including names, job titles, employer names, phone numbers, email addresses, and physical addresses. The company was acquired by Dun & Bradstreet in 2015 and operated as part of D&B's data and analytics portfolio. It is not a consumer-facing brand — its records represent professionals whose contact information was aggregated for B2B marketing purposes.

Why They Hold Your Data

Marketing data brokers aggregate business contact records, job titles, company profiles, emails, and phone numbers into lead-intelligence products for B2B targeting.

Recent Developments

NetProspex has been absorbed into Dun & Bradstreet's broader data and analytics product suite and no longer operates as a distinct standalone brand. D&B has continued to expand its B2B data and intelligence services.

Data Points Exposed

6 verified field types
Email Address
Employer
Full Name
Job Information
Phone Number
Physical address High

Breach Impact

In 2016 a corpus of approximately 33.7 million records sourced from D&B's NetProspex service leaked online. The exposed data included names, email addresses, employers, job titles, phone numbers, and physical addresses of professionals across corporate America. Dun & Bradstreet confirmed the leak but attributed the exposure to a customer who had purchased the data and subsequently lost control of it rather than to a breach of D&B's own systems. The distinction matters: the individuals in the dataset had no direct relationship with NetProspex. Their information was aggregated from various sources and sold as a commercial asset. No formal notification was issued to affected individuals, consistent with the B2B data broker model where the subjects of the data are third parties rather than customers.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Employment-based social engineering using job and employer data

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation