LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Exactis Data Breach (2018)

CRITICAL severityConfirmedHow we verify

Exactis Data Breach (2018): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 1, 2018

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Exactis Data Breach (2018)

Reported June 1, 2018. Approximately 131.6M people affected.

CRITICAL
Severity
131.6M
People affected
20
Data types exposed
June 1, 2018
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Exactis Data Breach (2018) (reported June 1, 2018) exposed Credit status information, Dates of birth, Education levels and Email addresses belonging to roughly 131.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Exactis Data Breach (2018) breach?
131.6M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In June 2018, marketing firm Exactis was found to have exposed a large collection of personal records through an unsecured database. The incident involved 340 million records containing information on an estimated 131.6 million individuals, discovered by security researcher Vinny Troia. Public reporting at the time described the exposure as inadvertent, with the data left accessible without authentication. This event drew attention because it involved a company whose business centered on compiling and distributing detailed consumer profiles. The scale of the records and the range of fields involved illustrate how data held for commercial purposes can reach wide exposure when basic access controls are absent.

Inside the incident

The breach came to light on 1 June 2018 when the unsecured database was identified. It contained multiple terabytes of information spread across hundreds of separate fields. The records originated from Exactis’s role as a compiler and aggregator of business and consumer data intended for profiling and marketing use. A small subset of the exposed fields was later shared with the Have I Been Pwned service for public lookup.

How a breach like this happens

Incidents involving large marketing or data-aggregation databases often stem from configuration errors that leave storage systems reachable from the public internet. In such cases, authentication requirements may be omitted during deployment or later changes, allowing anyone to retrieve the contents. The data itself is typically assembled from multiple sources and retained in flat or lightly structured formats that facilitate bulk querying once access is obtained.

Who is Exactis?

Exactis operated as a data compiler and aggregator, collecting and refining consumer and business information to sell for marketing and profiling purposes. Firms in this sector routinely maintain extensive records that include contact details, demographic attributes, and indicators of purchasing or financial behavior. A breach at such an organization is consequential because the data is already structured for easy reuse and may be held in volumes that exceed those maintained by individual companies about their own customers.

What data was at risk

The fields reported as present in the exposed records include credit status information, dates of birth, education levels, email addresses, ethnicities, family structure, financial investments, and genders. Additional fields referenced in contemporaneous reporting include addresses and phone numbers. The precise full list of fields and the exact condition of every record remain unconfirmed beyond the details provided by the researcher who located the dataset.

What's at stake

For individuals, the presence of birth dates, contact information, and profiling attributes can support more targeted follow-on contact or correlation with other datasets. For the organization, the exposure of its core commercial asset created immediate operational and reputational consequences, including the loss of control over data it had compiled for sale. Because the records were already formatted for marketing use, any party that obtained them could repurpose them without additional processing.

If your data was in this breach

Begin by changing passwords on any accounts that reuse the exposed email address and enable multi-factor authentication where available. Monitor statements and credit reports for unusual activity, particularly if financial or credit-related fields were included. Readers can run a free exposure scan of their email address against known breach data to determine whether their information appears in this or other documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyExactis security record
70/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Exactis’s full breach history →

More recent breaches

Data & Leads Data Breach (2018)November 14, 2018Adapt Data Breach (2018)November 5, 2018Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)October 29, 2018GoldSilver Data Breach (2018)October 21, 2018

Latest breaches

Read GalaxyWarden’s full analysis of the Exactis Data Breach (2018) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram