Verifications.io 2019 Data Breach

Verifications.io Email Verification Service Breach: 763M Records Including Names, Phone & Location

Data Broker / Marketing Exposure · Email verification, marketing leads, and contact intelligence · Exposed lead verification database · Global

Verifications.io Email Verification Service Breach: 763M Records Including Names, Phone & Location

Email verification and marketing lead data service (now defunct)

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
24/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
763.1MRecords
2019Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Social EngineeringData & IdentityData BrokersThird Party2019

Breach Summary

Verifications.io, an email validation and marketing-data service, exposed 763 million unique email address records after security researchers Bob Diachenko and Vinny Troia discovered the company's MongoDB database had been left publicly accessible without a password. No sophisticated attack was required. Anyone with an internet connection could access roughly 150 gigabytes of data. The company took its website offline during the disclosure process in February 2019. The exposed records went well beyond email addresses. Many entries also included names, phone numbers, physical addresses, IP addresses, dates of birth, genders, employers, and job titles. Because Verifications.io's core business was confirming that email addresses belonged to real, active users, the dataset was particularly valuable to bad actors. Verified, live addresses are far more useful for phishing campaigns and spam operations than unvalidated lists, and the additional personal details made large-scale identity profiling and targeted fraud easier to carry out. No passwords were included in the breach, but that offers limited reassurance given the volume and richness of the data. Affected individuals had no direct relationship with Verifications.io; their information was collected and held as third-party marketing data. People whose records were exposed face elevated risk of phishing attempts, spam, and identity-linked targeting. Anyone who suspects their information was included should treat unsolicited contact with extra caution, particularly messages that reference personal details to appear legitimate.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

763.1M records analyzed

About Verifications.io

Verifications.io was an email validation and marketing-data service that helped customers clean and verify email lists for outreach and lead-generation use. In practice, that put it in the business of handling very large volumes of email-linked marketing and contact data rather than running a normal consumer platform.

Why They Hold Your Data

Email-verification and lead-intelligence datasets aggregate email addresses, deliverability status, and marketing-linked contact intelligence for outreach and lead-generation workflows.

Recent Developments

Verifications.io appears to be defunct. Public reporting after the 2019 exposure said the site went offline and the company appeared to be out of business shortly afterward, and today it is remembered mainly as a failed email-marketing data operation rather than as a continuing service.

Data Points Exposed

10 verified field types
Date of Birth High
Email Address
Employer
Full Name
Gender
Geographic location
IP Address
Job Information
Phone Number
Physical address High

Breach Impact

The breach impact was severe because it exposed one of the largest publicly known marketing-data corpora of its kind. Have I Been Pwned says 763 million unique email addresses were exposed after researchers found a publicly accessible MongoDB instance with no password, and many records also contained names, phone numbers, IP addresses, dates of birth, and genders. That made the dataset highly useful for phishing, spam operations, identity linkage, profile enrichment, and targeted marketing abuse at enormous scale.

Exploitation & Downstream Threats

• Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Employment-based social engineering using job and employer data

Principal Risk Advisory

What this means for a principal

A data-broker/identity breach: aggregated identity attributes re-seed broker networks and enrich targeting of the individual. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation