Data & Leads Data Breach (2018): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Data & Leads Data Breach (2018) (reported November 14, 2018) exposed Email addresses, Employers, IP addresses and Job titles belonging to roughly 44.3M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The database was identified as an exposed Elasticsearch instance. It held over 44.3 million unique email addresses together with names, IP addresses, physical addresses, phone numbers, employers, and job titles. Diachenko attributed the data to Data & Leads after examining its contents. Attempts to contact the company received no response. The site associated with Data & Leads subsequently became unavailable. No further details on the duration of exposure or the total volume of records beyond the reported unique emails have been made public.
How a breach like this happens
Incidents involving exposed databases often stem from configuration errors that leave services reachable over the public internet without access controls. Elasticsearch instances, in particular, have historically been deployed with default settings that do not require authentication. When such a service indexes records collected from multiple sources, the entire dataset becomes readable by anyone who locates the open port. These exposures are typically discovered by researchers scanning for misconfigured systems rather than through deliberate intrusion into protected networks.
About Data & Leads
Data & Leads operated as a data aggregator supplying contact and employment information to clients for marketing and lead-generation purposes. Organizations in this sector routinely compile names, addresses, phone numbers, email addresses, and workplace details from public records, commercial sources, and web scraping. The resulting datasets are used to build profiles that combine personal identifiers with professional attributes. A breach at such a firm is consequential because the information is already structured for outreach and can be repurposed without additional effort.
What was likely exposed
The Elasticsearch instance contained email addresses, names, IP addresses, physical addresses, phone numbers, employers, and job titles. These categories were directly observed in the exposed data. The precise scope of records, including whether every field was populated for all 44.3 million entries or whether additional fields existed, remains unconfirmed. Organizations of this type commonly store similar fields to support marketing activities, yet the exact contents of the dataset cannot be stated beyond what was reported by the researcher.
Why it matters
Combined personal and employment data can be used to craft targeted messages that appear legitimate, increasing the effectiveness of phishing or unsolicited contact. IP addresses paired with other identifiers may also assist in mapping online activity to specific individuals. For the organization, loss of control over its primary asset—aggregated contact records—can affect client trust and future data partnerships. Individuals whose records appeared in the dataset face the persistent risk that their details will circulate among parties who acquire exposed marketing lists.
What to do if you're exposed
Review recent account activity for any services tied to the exposed email address and enable multi-factor authentication where available. Consider using a password manager to replace reused credentials. Monitor statements from financial or government accounts for unusual activity. Readers can run a free exposure scan of their email address against known breach datasets to determine whether their information appears in this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Adapt Data Breach (2018)Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)GoldSilver Data Breach (2018)You've Been Scraped Data Breach (2018)Latest breaches
Read GalaxyWarden’s full analysis of the Data & Leads Data Breach (2018) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.