LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › NetProspex Data Breach (2016)

HIGH severityConfirmedHow we verify

NetProspex Data Breach (2016): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 1, 2016

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

NetProspex Data Breach (2016)

Reported September 1, 2016. Approximately 33.7M people affected.

HIGH
Severity
33.7M
People affected
6
Data types exposed
September 1, 2016
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The NetProspex Data Breach (2016) (reported September 1, 2016) exposed Email addresses, Employers, Job titles and Names belonging to roughly 33.7M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the NetProspex Data Breach (2016) breach?
33.7M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2016, a dataset tied to NetProspex was reported as having appeared online, containing records for 33.7 million individuals. The material originated from Dun & Bradstreet’s NetProspex service and included corporate contact details that had been sold for marketing purposes. Dun & Bradstreet stated at the time that the data appeared to have been lost by one of its customers rather than taken directly from its own systems. The scale of the exposure placed the incident among the larger marketing-data leaks disclosed that year. Public records show the list surfaced on September 01, 2016, though the precise date it was first obtained or posted remains undisclosed.

Breaking down the breach

The reported incident involved a single collection of records described as targeted marketing data. No technical intrusion into NetProspex or Dun & Bradstreet infrastructure was alleged. Instead, the company indicated the information had left its control after being purchased by a customer. The exact method by which the dataset reached public view, the identity of any intermediary, and the full chain of custody were not detailed in available statements. No confirmation has been released regarding whether additional copies of the same dataset exist or whether the exposure extended beyond the 33.7 million records initially reported.

How a breach like this happens

Marketing-data services routinely sell large batches of contact records to corporate clients for outreach campaigns. Once transferred, the data moves outside the original provider’s direct oversight. Loss can occur through customer-side storage failures, inadvertent sharing, or theft from the purchaser’s environment. Because the records are intended for repeated use, copies often proliferate across multiple systems, increasing the chance that one instance will later surface without the knowledge of the original seller.

Who is NetProspex?

NetProspex operated as a business-to-business data service focused on compiling contact information for sales and marketing teams. Its parent, Dun & Bradstreet, maintains extensive commercial databases used to identify decision-makers within organizations. Such services aggregate names, professional titles, and employer details so that vendors can reach potential clients more precisely. A compromise at this layer affects not only the individuals listed but also the companies that rely on the accuracy and controlled distribution of that information for legitimate commercial activity.

The information in question

The disclosed records contained email addresses, names, job titles, employers, phone numbers, and physical addresses. These categories align with the typical contents of corporate marketing lists. No further categories, such as financial details or passwords, were named in connection with this exposure. The precise fields present in every record remain unconfirmed, as does any indication of whether the dataset included additional attributes beyond those listed.

The real-world impact

Individuals whose details appeared in the dataset face an elevated chance of receiving unsolicited contact through the channels that were exposed. Organizations that purchased the same marketing data may encounter questions about how their own customer or prospect lists are protected after leaving the supplier. Because the records were already sold for commercial use, the primary change introduced by the leak is wider and uncontrolled circulation rather than the creation of entirely new data types.

Were you affected?

Anyone who held a corporate role in the United States around the mid-2010s may wish to review the contact information they use professionally. Basic steps include monitoring email accounts for unexpected messages that reference the exposed details and verifying that any public professional profiles do not publish phone numbers or physical addresses unnecessarily. Several services allow individuals to enter an email address and receive a report on whether that address has appeared in previously published breach collections; running such a check provides a factual starting point without requiring payment.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyNetProspex security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See NetProspex’s full breach history →

More recent breaches

Data Enrichment Records Data Breach (2016)December 23, 2016RankWatch Data Breach (2016)November 19, 2016Modern Business Solutions Data Breach (2016)October 8, 2016Justdate.com Data Breach (2016)September 29, 2016

Latest breaches

Read GalaxyWarden’s full analysis of the NetProspex Data Breach (2016) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram