LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › SaverSpy Data Breach (2018)

HIGH severityConfirmedHow we verify

SaverSpy Data Breach (2018): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 18, 2018

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

SaverSpy Data Breach (2018)

Reported September 18, 2018. Approximately 2.5M people affected.

HIGH
Severity
2.5M
People affected
4
Data types exposed
September 18, 2018
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The SaverSpy Data Breach (2018) (reported September 18, 2018) exposed Email addresses, Genders, Names and Physical addresses belonging to roughly 2.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the SaverSpy Data Breach (2018) breach?
2.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2018, security researcher Bob Diachenko identified a large collection of personal records that had been left accessible in an unprotected MongoDB instance. The data set, labeled with the description "Yahoo_090618_ SaverSpy," contained nearly 2.5 million unique email addresses, all originating from Yahoo, together with associated names, genders, and physical addresses. The incident was reported on 18 September 2018 and affected an estimated 2.5 million individuals.

The exposure is notable because the records appear to have originated from marketing-related activity rather than from a conventional corporate database breach. No further technical details about the duration of the exposure or the precise circumstances that led to the database being left open have been made public.

Inside the incident

The records were discovered in an unprotected MongoDB instance. The only identifier attached to the data set was the string "Yahoo_090618_ SaverSpy," which suggests the information had been compiled for marketing campaigns. The data supplied to Have I Been Pwned contained almost 2.5 million unique Yahoo email addresses along with names, genders, and physical addresses. No additional technical indicators, such as logs or configuration files, were reported in connection with the discovery.

How a breach like this happens

Incidents involving exposed databases commonly result from configuration errors that leave storage systems accessible over the public internet without authentication. MongoDB instances, in particular, have historically been left open when default settings are not changed or when access controls are omitted during deployment. Once reachable, such databases can be indexed by automated scanning tools, allowing researchers or others to locate and retrieve their contents without any intrusion into the host network.

About SaverSpy

SaverSpy operated in the consumer marketing sector, collecting contact information to support promotional campaigns. Organisations of this type routinely hold names, email addresses, physical addresses, and basic demographic details such as gender in order to segment and target messages. A data set of this nature therefore reflects the standard customer or prospect records maintained by marketing services.

What was likely exposed

The records confirmed as present in the exposed data set include email addresses, names, genders, and physical addresses. All of the email addresses were from Yahoo. No other categories of information have been documented in connection with this incident, and the exact scope of any additional fields remains unconfirmed.

Why it matters

Names paired with physical addresses and email accounts can be used for unsolicited contact or to support more targeted phishing attempts. When such records are already linked to marketing activity, the immediate practical effect for most individuals is an increased volume of spam. For the organisation, the exposure highlights the risks that arise when data collected for commercial purposes is stored without adequate access controls.

If your data was in this breach

Individuals can begin by reviewing recent email activity for any unexpected messages and by ensuring that their Yahoo account uses a strong, unique password with two-factor authentication enabled. Monitoring bank and credit statements for unusual transactions provides a further practical step. Readers may also run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanySaverSpy security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See SaverSpy’s full breach history →

More recent breaches

Data & Leads Data Breach (2018)November 14, 2018Adapt Data Breach (2018)November 5, 2018Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)October 29, 2018GoldSilver Data Breach (2018)October 21, 2018

Latest breaches

Read GalaxyWarden’s full analysis of the SaverSpy Data Breach (2018) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram