Data Broker · B2B contact data aggregation and sales intelligence · Marketing data broker and lead intelligence provider · USA
B2B marketing data service (now part of Dun & Bradstreet).
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
NetProspex, a B2B marketing database service operated by Dun & Bradstreet, exposed 33.7 million professional records when the data leaked online in 2016. The company did not suffer a direct system breach. Instead, Dun & Bradstreet concluded that a customer who had purchased the dataset lost control of it, allowing the records to circulate publicly. The individuals in the database had no direct relationship with NetProspex; their contact information had been aggregated from various sources and packaged as a commercial marketing asset. The exposed records included names, email addresses, job titles, employer names, phone numbers, and physical addresses, all organized specifically for outbound business targeting. That structure is what makes the exposure particularly useful to bad actors. A dataset pre-sorted by employer, role, and contact details provides ready-made material for spearphishing campaigns, executive impersonation, and business-focused fraud at scale. No formal notifications were issued to affected individuals, which is consistent with how B2B data brokers operate: the people whose information is sold are third parties, not customers, and are generally outside the scope of standard breach notification obligations. For those whose records appeared in the dataset, the practical risk is ongoing. The data remains well-suited to targeted phishing and social engineering attacks, particularly those crafted to appear as legitimate business communications.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
33.7M records analyzed
NetProspex was a B2B marketing data service that compiled and sold contact information for professionals across corporate America, including names, job titles, employer names, phone numbers, email addresses, and physical addresses. The company was acquired by Dun & Bradstreet in 2015 and operated as part of D&B's data and analytics portfolio. It is not a consumer-facing brand — its records represent professionals whose contact information was aggregated for B2B marketing purposes.
Marketing data brokers aggregate business contact records, job titles, company profiles, emails, and phone numbers into lead-intelligence products for B2B targeting.
NetProspex has been absorbed into Dun & Bradstreet's broader data and analytics product suite and no longer operates as a distinct standalone brand. D&B has continued to expand its B2B data and intelligence services.
In 2016 a corpus of approximately 33.7 million records sourced from D&B's NetProspex service leaked online. The exposed data included names, email addresses, employers, job titles, phone numbers, and physical addresses of professionals across corporate America. Dun & Bradstreet confirmed the leak but attributed the exposure to a customer who had purchased the data and subsequently lost control of it rather than to a breach of D&B's own systems. The distinction matters: the individuals in the dataset had no direct relationship with NetProspex. Their information was aggregated from various sources and sold as a commercial asset. No formal notification was issued to affected individuals, consistent with the B2B data broker model where the subjects of the data are third parties rather than customers.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Employment-based social engineering using job and employer data
A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation