X

Exactis said to have exposed 340 million records, more than Equifax breach

We hadn't heard of the firm either, but it had data on hundreds of millions of Americans and businesses and leaked it, according to Wired.

Abrar Al-Heeti Technology Reporter
Abrar Al-Heeti is a technology reporter for CNET, with an interest in phones, streaming, internet trends, entertainment, pop culture and digital accessibility. She's also worked for CNET's video, culture and news teams. She graduated with bachelor's and master's degrees in journalism from the University of Illinois at Urbana-Champaign. Though Illinois is home, she now loves San Francisco -- steep inclines and all.
Expertise Abrar has spent her career at CNET analyzing tech trends while also writing news, reviews and commentaries across mobile, streaming and online culture. Credentials
  • Named a Tech Media Trailblazer by the Consumer Technology Association in 2019, a winner of SPJ NorCal's Excellence in Journalism Awards in 2022 and has three times been a finalist in the LA Press Club's National Arts & Entertainment Journalism Awards.
Abrar Al-Heeti
2 min read
Database leak

Some of your most personal information may have been made available to hackers. 

Getty Images

If you're a US citizen, your personal information -- your phone number, home address, email address, even how many children you have -- may have just become easily available to hackers in an alleged massive data leak.

Florida-based marketing and data aggregation firm Exactis exposed a database containing nearly 340 million individual records on a publicly accessible server, Wired reported. Earlier this month, security researcher Vinny Troia found that nearly 2 terabytes of data was exposed, which seems to include personal information on hundreds of millions of US adults and millions of businesses, the report said.

"It seems like this is a database with pretty much every US citizen in it," Troia told Wired.

Exactis didn't respond to a request for comment or confirmation.

The alleged breach reportedly exposed highly personal information, such as people's phone numbers, home and email addresses, interests and the number, age and gender of their children. Credit card information and Social Security numbers don't appear to have been leaked. Troia told Wired that he doesn't know where the data is coming from, "but it's one of the most comprehensive collections I've ever seen."

Because Exactis hasn't confirmed the leak, and the data is reportedly no longer accessible, it's hard to know exactly how many people are affected. But Troia found two versions of the database that each had around 340 million records, with roughly 230 million on consumers and 110 million on business contacts, according to Wired. Exactis says on its website that it has over 3.5 billion consumer, business and digital records.  

The data leak is noteworthy not only for its breadth, but also for the depth of information the records have on people. Every record reportedly has entries that include more than 400 variables on characteristics like whether the person smokes, what their religion is and whether they have dogs or cats. But Wired noted that in some instances, the information is inaccurate or outdated.  

Just because people's financial information or Social Security numbers weren't leaked doesn't mean they're not at risk for identity theft. The amount of personal information that was exposed could still help scammers impersonate or profile them. 

Huge compromises to personal information have been making headlines in recent years. In 2017, Equifax was involved in a massive data breach of 145.5 million people's data -- Social Security numbers, names, birthdates and addresses were stolen. And in October, Yahoo revealed that all 3 billion accounts were hacked in a 2013 breach

Watch this: Worst hacks of the year

First published June 27, 2:14 p.m. PT.
Update, June 28 at 10:14 a.m. PT: Adds more background on recent hacks.

Cambridge Analytica: Everything you need to know about Facebook's data mining scandal.

Follow the Money: This is how digital cash is changing the way we save, shop and work.