DemandScience by Pure Incubation Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The DemandScience by Pure Incubation Data Breach (2024) (reported February 28, 2024) exposed Email addresses, Employers, Job titles and Names belonging to roughly 121.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In early 2024, records tied to more than 121 million people associated with DemandScience by Pure Incubation became available for sale on a popular hacking forum. For those whose names, work emails, phone numbers, employers, job titles, physical addresses or social-media profile links appear in that material, the practical stakes are straightforward: business contact details that were once scattered across public sources are now concentrated in a single, easily traded package that can be used for phishing, social engineering or unwanted outreach.
Public reporting places the disclosure around 28 February 2024 and attributes the exposure to a leak from a decommissioned legacy system rather than an active production network. Exact technical methods remain limited in the public record, yet the scale and the nature of the data make the incident relevant to anyone who has ever appeared in B2B contact databases.
What happened
According to the available facts, a large corpus of data from DemandScience, a company owned by Pure Incubation, appeared for sale on a popular hacking forum in early 2024. The material was later attributed to a leak from a decommissioned legacy system. The reported contents consisted largely of business contact information that had been aggregated from public sources. Specifically, the data included approximately 122 million unique corporate email addresses together with physical addresses, phone numbers, employers, job titles, names and, for many individuals, links to LinkedIn profiles. The number of people affected is given as 121.8 million. No further public detail has been released on the precise date the system was decommissioned, the exact mechanism of the leak, or any subsequent containment steps.
How a breach like this happens
Incidents involving decommissioned or legacy systems typically unfold when older infrastructure is taken offline without a complete inventory of residual data stores, backup media or forgotten access paths. Over time, credentials, configuration files or entire databases can remain reachable—sometimes through misconfigured cloud storage, unpatched remote-access services or simply physical media that was never securely wiped. Once an unauthorised party obtains a copy, the data can be offered for sale on underground forums. Because the information is often compiled from public or semi-public sources, it may not trigger the same immediate alarms as a live customer database, yet the concentration of verified contact fields still creates a ready-made resource for fraudsters. No specific threat group has been attributed in the public facts for this case; the pattern itself is a recurring one across many organisations that maintain large historical contact repositories.
DemandScience by Pure Incubation and its sector
DemandScience operates in the business-to-business demand-generation and data-services sector. Companies of this type typically collect, enrich and license professional contact records—names, corporate email addresses, job titles, employers, phone numbers and social-media profiles—so that marketing and sales teams can reach decision-makers. Pure Incubation is the parent organisation. Because the core product is aggregated professional data, a breach of even a legacy store can expose a broad cross-section of working adults whose details were gathered over years of public and commercial collection. The consequential nature of such an event lies less in the novelty of any single field and more in the volume and the ready usability of the combined records for targeted outreach or impersonation.
What was likely exposed
The facts name the following categories of information as present in the leaked corpus:
- Email addresses (approximately 122 million unique corporate addresses)
- Employers
- Job titles
- Names
- Phone numbers
- Physical addresses
- Social media profiles (including LinkedIn links for many individuals)
The data is described as largely business contact information aggregated from public sources. Exact contents beyond these named types remain unconfirmed in the public record; organisations in this sector commonly hold additional enrichment fields, but no such fields have been verified for this incident.
Why it matters
For affected individuals the primary risks are practical rather than catastrophic. Concentrated professional contact data can be used to craft convincing phishing messages that reference a real employer or job title, to place unsolicited sales or recruitment calls, or to attempt account-takeover attacks that rely on knowledge of a work email and associated personal details. Physical addresses raise the possibility of more targeted physical-world scams or doxxing, though the bulk of the material is business-oriented. For the organisation, the exposure of a large historical contact store can erode trust among clients who licensed the data and among the professionals whose records were held, and it may trigger regulatory scrutiny depending on jurisdiction and the presence of any personal data subject to privacy rules. Because the leak is attributed to a decommissioned system, the incident also illustrates the longer-term governance challenge of ensuring that retired infrastructure does not retain usable copies of sensitive information.
Were you affected?
If you have ever held a corporate email address, appeared in professional directories, or maintained a public LinkedIn profile, your details may be among the 121.8 million records. Practical first steps include monitoring work and personal email accounts for unexpected messages that reference your employer or job title, enabling multi-factor authentication wherever available, and treating unsolicited calls or LinkedIn connection requests with extra caution. Readers can also run a free exposure scan of their email address to check whether that address has already surfaced in known breach data sets. Public detail on individual notification remains limited; vigilance and basic hygiene remain the most immediate protections available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Aman Data Breach (2026)7-Eleven Data Breach (2026)Association Nationale des Premiers Secours Data Breach (2026)Speedio Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the DemandScience by Pure Incubation Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.