LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › GeekedIn Data Breach (2016)

HIGH severityConfirmedHow we verify

GeekedIn Data Breach (2016): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 15, 2016

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

GeekedIn Data Breach (2016)

Reported August 15, 2016. Approximately 1.1M people affected.

HIGH
Severity
1.1M
People affected
6
Data types exposed
August 15, 2016
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The GeekedIn Data Breach (2016) (reported August 15, 2016) exposed Email addresses, Geographic locations, Names and Professional skills belonging to roughly 1.1M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the GeekedIn Data Breach (2016) breach?
1.1M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In August 2016, a technology recruitment site called GeekedIn left a MongoDB database exposed on the internet. An unknown third party extracted more than 8 million records that included email addresses and other profile details for roughly 1.1 million individuals. The incident was reported on 15 August 2016.

The exposed information originated from public GitHub profiles that had been collected earlier. Because the data concerned people who had placed professional details online, the breach raised immediate questions about how widely that information could now circulate beyond its original context.

Breaking down the breach

The facts released at the time state that GeekedIn left its MongoDB database publicly accessible. More than 8 million records were taken. The records contained information that had previously been scraped from GitHub user profiles in violation of that platform’s terms. The breach affected an estimated 1.1 million people, primarily through the exposure of their email addresses along with other profile fields.

No further technical details, such as the precise duration of the exposure or the method used to locate the database, were disclosed in the initial reporting. The identity of the party that extracted the records also remains unknown.

How a breach like this happens

Incidents involving exposed databases often begin with a configuration setting that leaves a service reachable from the public internet without authentication. Once discovered, such a resource can be read in full by any automated scan or manual query. The data itself may have been assembled from multiple sources, including public web scraping, before it is stored in the database.

Because the collection step occurred earlier and the storage step occurred later, two separate opportunities for unintended disclosure existed. In this case the second opportunity, the unprotected database, is the one that led to the reported extraction.

Who is GeekedIn?

GeekedIn operated as a technology recruitment platform. Sites of this type maintain profiles that combine contact information with professional attributes so that employers and recruiters can identify candidates. The service therefore held data that users had already made visible on other public platforms, chiefly GitHub.

When a recruitment site experiences a data exposure, the practical consequence is that information originally posted for limited professional visibility can be copied and redistributed without the original context or consent controls that users may have expected.

The information in question

The records named in the reporting include email addresses, geographic locations, names, professional skills, usernames, and years of professional experience. These fields match the categories of information that technology recruitment platforms commonly store to facilitate candidate matching.

Exact confirmation of every field present in the extracted set has not been published beyond the summary description. The reporting notes that the data reflected details already visible in public GitHub profiles rather than additional private information supplied directly to GeekedIn.

Why it matters

Email addresses combined with professional identifiers can be used for targeted phishing or for building more convincing social-engineering messages. Geographic and skill data add context that may allow an observer to infer employment status or location patterns over time.

For the organisation, the incident highlighted the risk of storing large volumes of scraped public data without adequate access controls. For individuals, the main concern is the loss of control over how widely their professional contact details circulate once they have left the original platform.

If your data was in this breach

Individuals can begin by changing the password on the email account associated with the exposed address and by reviewing any services that still rely on that address for account recovery. Enabling two-factor authentication on important accounts reduces the value of the email address alone to an attacker.

Readers can also run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other documented incidents. Monitoring for unusual login attempts or unsolicited messages that reference the exposed details provides an ongoing way to detect misuse.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyGeekedIn security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See GeekedIn’s full breach history →

More recent breaches

Data Enrichment Records Data Breach (2016)December 23, 2016RankWatch Data Breach (2016)November 19, 2016Modern Business Solutions Data Breach (2016)October 8, 2016Justdate.com Data Breach (2016)September 29, 2016

Latest breaches

Read GalaxyWarden’s full analysis of the GeekedIn Data Breach (2016) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram