Modern Business Solutions Data Breach (2016): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Modern Business Solutions Data Breach (2016) (reported October 8, 2016) exposed Dates of birth, Email addresses, Genders and IP addresses belonging to roughly 58.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The incident came to light on October 8, 2016, when the MongoDB file appeared publicly on Twitter. The file contained more than 58 million unique email addresses along with associated details. No official statement from Modern Business Solutions has addressed how the data was obtained, stored, or why the file became accessible. Timing of the initial compromise and the method by which the file left the company’s control remain undisclosed in available reports.
How a breach like this happens
Incidents involving exposed database files often stem from misconfigured systems that allow external access without authentication. In other cases, copies of internal data are transferred to less secure environments for analysis or backup and then inadvertently or deliberately shared. Public posting of such files on social platforms can occur when an individual with access chooses to release them or when credentials are obtained by an external party. These events do not require sophisticated intrusion techniques when basic access controls are absent or when data copies circulate beyond monitored systems.
Modern Business Solutions and its sector
Modern Business Solutions operates in the data storage and database hosting sector, providing infrastructure that supports the retention and management of large customer or client datasets. Organizations in this field routinely process information on behalf of other businesses, which can include aggregated records collected from multiple sources. A breach at such a provider is consequential because the data may represent individuals who have no direct relationship with the company and may be unaware their information is held in a single repository.
What was likely exposed
The publicly shared file included dates of birth, email addresses, genders, IP addresses, job titles, names, phone numbers, and physical addresses. These data types were explicitly present in the records described in contemporaneous reports. It is not confirmed whether additional categories of information were also contained in the file or in other systems belonging to the company. The exact scope of data held by Modern Business Solutions beyond the contents of the shared file remains unconfirmed.
What's at stake
Individuals whose records appeared in the file face the possibility that their contact details and personal attributes could be used for targeted phishing, unsolicited marketing, or identity-related fraud. Email addresses combined with names and addresses can facilitate account takeover attempts if reused passwords exist elsewhere. For the organization, the incident raises questions about data governance and the handling of information collected from third parties, potentially affecting trust from clients who rely on its hosting services.
What to do if you're exposed
Review recent account activity on services tied to the exposed email address and enable multi-factor authentication where available. Monitor statements from financial institutions and consider placing fraud alerts with credit reporting agencies if physical addresses or dates of birth were included. Individuals can run a free exposure scan of their email address to check whether their information has appeared in known breach data sets and review guidance from privacy regulators on steps to limit further misuse of disclosed details.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Data Enrichment Records Data Breach (2016)RankWatch Data Breach (2016)Justdate.com Data Breach (2016)Real Estate Mogul Data Breach (2016)Latest breaches
Read GalaxyWarden’s full analysis of the Modern Business Solutions Data Breach (2016) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.