Acuity Data Breach (2020): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Acuity Data Breach (2020) (reported June 18, 2020) exposed Dates of birth, Email addresses, Genders and IP addresses belonging to roughly 14.1M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
A corpus of 437 GB was assembled in mid-2020 and later shared widely. The material was presented under the name Acuity and contained more than 14 million rows, each holding an email address plus dozens of additional fields. Reporting of the incident appeared on 18 June 2020. No confirmed account of how the data left its original location has been made public, and the precise source remains unverified.
How a breach like this happens
Large personal-data collections are frequently obtained through remote access to inadequately protected storage systems, stolen administrator credentials, or the exploitation of software vulnerabilities that allow bulk export. Once copied, the files can be compressed, packaged, and posted to file-sharing or trading platforms. Because the initial access method is rarely disclosed by the affected organisation, analysts must rely on the structure and content of the released data to infer likely exposure routes.
Acuity and its sector
Public records do not identify a single well-known company named Acuity that matches the scale and column count of the released material. Entities that accumulate hundreds of columns of personal information are typically data brokers, marketing list compilers, or service providers that aggregate records from multiple sources. Such organisations routinely hold contact details, demographic attributes, and online identifiers for millions of individuals, making any confirmed loss of custody significant within the data-supply chain.
What data was at risk
The published records included dates of birth, email addresses, genders, IP addresses, names, phone numbers, physical addresses, and salutations. Each row reportedly contained more than 400 columns in total. The exact scope of every field that may have been present has not been independently audited, so the full set of exposed attributes remains unconfirmed beyond the categories already listed.
What's at stake
Individuals whose records appear in the corpus face an elevated chance that their contact information and basic biographical details will be used for unsolicited communications or combined with other leaked data sets. For the organisation, the circulation of such a volume of records can prompt regulatory inquiries and contractual disputes with any clients whose data was included. Because the origin of the corpus is still unclear, responsibility for notification and remediation has not been formally assigned.
What to do if you're exposed
Anyone who believes their information may be involved should monitor their email accounts for unusual activity and consider enabling additional authentication steps on services that hold sensitive data. Changing passwords for any accounts that reuse the exposed email address is a prudent first measure. Readers can also run a free exposure scan of their email address against known breach data sets to determine whether their details have appeared in this or other documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
University of California Data Breach (2020)Roblox Developer Conference (2023) Data Breach (2020)Travel Oklahoma Data Breach (2020)Capital Economics Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the Acuity Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.