LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Covve Data Breach (2020)

HIGH severityConfirmedHow we verify

Covve Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 20, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Covve Data Breach (2020)

Reported February 20, 2020. Approximately 22.8M people affected.

HIGH
Severity
22.8M
People affected
6
Data types exposed
February 20, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Covve Data Breach (2020) (reported February 20, 2020) exposed Email addresses, Job titles, Names and Phone numbers belonging to roughly 22.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Covve Data Breach (2020) breach?
22.8M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In February 2020 a dataset containing records for 22.8 million individuals was found exposed on a publicly accessible server and later supplied to Have I Been Pwned. The material originated from Covve, a contacts-management application, and included names, email addresses, phone numbers, job titles, physical addresses and social-media profiles together with recorded interactions between users and their contacts. The incident was reported on 20 February 2020 after the collection, labelled “db8151dd,” was identified by dehashed.com and forwarded to the breach-tracking service. The exposure illustrates a recurring pattern in which large volumes of personal data become available because storage systems are left reachable from the public internet without authentication. Such incidents continue to surface because organisations increasingly rely on cloud-hosted databases that, when misconfigured, require no additional compromise to be read by anyone who locates them.

What happened

The records were discovered on an Elasticsearch server that had been configured to accept connections without requiring credentials. The dataset was subsequently provided to Have I Been Pwned, which added it to its public corpus on 20 February 2020. No further technical details about the duration of exposure or the precise method of discovery have been released by the parties involved.

How a breach like this happens

Incidents involving publicly reachable databases typically begin with an administrative or development deployment that omits access controls. Once indexed by search engines or located through scanning tools, the contents can be read or copied by any party that finds the endpoint. The absence of authentication or network restrictions means no separate intrusion is required; the data is simply available until the configuration is corrected.

Covve and its sector

Covve operates a mobile application that helps users maintain and enrich their address books by pulling in contact details from multiple sources. Applications of this type routinely store names, communication identifiers and supplementary professional or location data supplied by users or imported from other services. Because the platform aggregates information about both account holders and the people they know, a single incident can affect individuals who never created a Covve account themselves.

The information in question

The material supplied to Have I Been Pwned contained email addresses, job titles, names, phone numbers, physical addresses and social-media profiles. The original report also noted that interactions between Covve users and their contacts were present. No additional categories of data have been confirmed, and the precise scope of any further records remains undisclosed.

What's at stake

Names combined with phone numbers, addresses and employment details can be used for targeted phishing, social-engineering attempts or unwanted contact. When the same records also include interaction histories, they may reveal patterns of communication that individuals would not expect to be public. For the organisation, the incident highlights the operational and regulatory consequences of storing aggregated personal data without adequate access controls.

What to do if you're exposed

Individuals can review the email addresses they have used with contact-management services and change passwords on any accounts that share those addresses. Enabling multi-factor authentication on email and social-media accounts reduces the value of the exposed identifiers to third parties. Readers may also run a free exposure scan of their email address against known breach data to determine whether their information appears in this or other public collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyCovve security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Covve’s full breach history →

More recent breaches

University of California Data Breach (2020)December 24, 2020Roblox Developer Conference (2023) Data Breach (2020)December 18, 2020Travel Oklahoma Data Breach (2020)December 17, 2020Capital Economics Data Breach (2020)December 12, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the Covve Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram