Exactis Data Breach (2018): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Exactis Data Breach (2018) (reported June 1, 2018) exposed Credit status information, Dates of birth, Education levels and Email addresses belonging to roughly 131.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach came to light on 1 June 2018 when the unsecured database was identified. It contained multiple terabytes of information spread across hundreds of separate fields. The records originated from Exactis’s role as a compiler and aggregator of business and consumer data intended for profiling and marketing use. A small subset of the exposed fields was later shared with the Have I Been Pwned service for public lookup.
How a breach like this happens
Incidents involving large marketing or data-aggregation databases often stem from configuration errors that leave storage systems reachable from the public internet. In such cases, authentication requirements may be omitted during deployment or later changes, allowing anyone to retrieve the contents. The data itself is typically assembled from multiple sources and retained in flat or lightly structured formats that facilitate bulk querying once access is obtained.
Who is Exactis?
Exactis operated as a data compiler and aggregator, collecting and refining consumer and business information to sell for marketing and profiling purposes. Firms in this sector routinely maintain extensive records that include contact details, demographic attributes, and indicators of purchasing or financial behavior. A breach at such an organization is consequential because the data is already structured for easy reuse and may be held in volumes that exceed those maintained by individual companies about their own customers.
What data was at risk
The fields reported as present in the exposed records include credit status information, dates of birth, education levels, email addresses, ethnicities, family structure, financial investments, and genders. Additional fields referenced in contemporaneous reporting include addresses and phone numbers. The precise full list of fields and the exact condition of every record remain unconfirmed beyond the details provided by the researcher who located the dataset.
What's at stake
For individuals, the presence of birth dates, contact information, and profiling attributes can support more targeted follow-on contact or correlation with other datasets. For the organization, the exposure of its core commercial asset created immediate operational and reputational consequences, including the loss of control over data it had compiled for sale. Because the records were already formatted for marketing use, any party that obtained them could repurpose them without additional processing.
If your data was in this breach
Begin by changing passwords on any accounts that reuse the exposed email address and enable multi-factor authentication where available. Monitor statements and credit reports for unusual activity, particularly if financial or credit-related fields were included. Readers can run a free exposure scan of their email address against known breach data to determine whether their information appears in this or other documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Data & Leads Data Breach (2018)Adapt Data Breach (2018)Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)GoldSilver Data Breach (2018)Latest breaches
Read GalaxyWarden’s full analysis of the Exactis Data Breach (2018) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.