Home / Data Breaches / Exactis
Verified breach record

Exactis Data Breach

Understand what this public breach record reports and choose next steps based on the information involved.

Breach date: June 1, 2018131,577,763 affected accounts in the record
01

What happened?

In June 2018, the marketing firm Exactis inadvertently publicly leaked 340 million records of personal data . Security researcher Vinny Troia of Night Lion Security discovered the leak contained multiple terabytes of personal information spread across hundreds of separate fields including addresses, phone numbers, family structures and extensive profiling data. The data was collected as part of Exactis' service as a "compiler and aggregator of premium business & consumer data" which they then sell for profiling and marketing purposes. A small subset of the exposed fields were provided to Have I Been Pwned and contained 132 million unique email addresses.

02

When did it happen?

The breach date in the public record is June 1, 2018. The record was added to the catalogue on July 25, 2018 and last updated there on July 25, 2018.

03

What information was reported as exposed?

  • Credit status information
  • Dates of birth
  • Education levels
  • Email addresses
  • Ethnicities
  • Family structure
  • Financial investments
  • Genders
  • Home ownership statuses
  • Income levels
  • IP addresses
  • Marital statuses
  • Names
  • Net worths
  • Occupations
  • Personal interests
  • Phone numbers
  • Physical addresses
  • Religions
  • Spoken languages

These are incident-level categories. The record does not prove that every category was exposed for every affected person.

04

Who may be affected?

This record may be relevant to people who had an account or other relationship with Exactis or used exactis.com around June 1, 2018. A catalogue entry does not establish that every customer was affected or that every listed data category applied to each person. Compare the record with an official notice addressed to you.

05

What should you do?

Verify whether the notice applies to you

Compare the organization, dates, and information categories with any notice you received. Use contact details you independently confirm.

Protect identity information

Review your credit reports and consider a free credit freeze if identity information could support new-account fraud.

Review financial accounts

Check statements for unfamiliar activity and contact the card issuer or financial institution through an independently verified channel.

Expect targeted phishing

Treat unexpected breach follow-ups with caution. Do not use links or phone numbers in a suspicious message; contact the organization directly.

Choose actions that match the information involved. If you find signs that someone is using your identity, the Federal Trade Commission provides a personal recovery plan at IdentityTheft.gov.

Sources and review information

Page reviewed September 14, 2026 by the Data Breach Help Editorial Team. Catalogue details reflect the provider record and may change.