SaverSpy Data Breach (2018): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The SaverSpy Data Breach (2018) (reported September 18, 2018) exposed Email addresses, Genders, Names and Physical addresses belonging to roughly 2.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In September 2018, security researcher Bob Diachenko identified a large collection of personal records that had been left accessible in an unprotected MongoDB instance. The data set, labeled with the description "Yahoo_090618_ SaverSpy," contained nearly 2.5 million unique email addresses, all originating from Yahoo, together with associated names, genders, and physical addresses. The incident was reported on 18 September 2018 and affected an estimated 2.5 million individuals.
The exposure is notable because the records appear to have originated from marketing-related activity rather than from a conventional corporate database breach. No further technical details about the duration of the exposure or the precise circumstances that led to the database being left open have been made public.
Inside the incident
The records were discovered in an unprotected MongoDB instance. The only identifier attached to the data set was the string "Yahoo_090618_ SaverSpy," which suggests the information had been compiled for marketing campaigns. The data supplied to Have I Been Pwned contained almost 2.5 million unique Yahoo email addresses along with names, genders, and physical addresses. No additional technical indicators, such as logs or configuration files, were reported in connection with the discovery.
How a breach like this happens
Incidents involving exposed databases commonly result from configuration errors that leave storage systems accessible over the public internet without authentication. MongoDB instances, in particular, have historically been left open when default settings are not changed or when access controls are omitted during deployment. Once reachable, such databases can be indexed by automated scanning tools, allowing researchers or others to locate and retrieve their contents without any intrusion into the host network.
About SaverSpy
SaverSpy operated in the consumer marketing sector, collecting contact information to support promotional campaigns. Organisations of this type routinely hold names, email addresses, physical addresses, and basic demographic details such as gender in order to segment and target messages. A data set of this nature therefore reflects the standard customer or prospect records maintained by marketing services.
What was likely exposed
The records confirmed as present in the exposed data set include email addresses, names, genders, and physical addresses. All of the email addresses were from Yahoo. No other categories of information have been documented in connection with this incident, and the exact scope of any additional fields remains unconfirmed.
Why it matters
Names paired with physical addresses and email accounts can be used for unsolicited contact or to support more targeted phishing attempts. When such records are already linked to marketing activity, the immediate practical effect for most individuals is an increased volume of spam. For the organisation, the exposure highlights the risks that arise when data collected for commercial purposes is stored without adequate access controls.
If your data was in this breach
Individuals can begin by reviewing recent email activity for any unexpected messages and by ensuring that their Yahoo account uses a strong, unique password with two-factor authentication enabled. Monitoring bank and credit statements for unusual transactions provides a further practical step. Readers may also run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Data & Leads Data Breach (2018)Adapt Data Breach (2018)Elasticsearch Instance of Sales Leads on AWS Data Breach (2018)GoldSilver Data Breach (2018)Latest breaches
Read GalaxyWarden’s full analysis of the SaverSpy Data Breach (2018) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.