Data broker has database of over 100 million people swiped and put up for sale online

email
(Image credit: Image by Muhammad Ribkhan from Pixabay)

  • Hacker found selling a database of 180+million emails on the dark web
  • The archive was stolen from a data broker
  • The data broker confirmed the information was scraped from public sources

A hacker is selling a database containing 183 million records of people’s contact details, including email addresses, stolen from a data broker who, in turn, generated it by scraping publicly available data.

One might say, no harm - no foul, but still, whoever buys this database will get the chance to annoy millions of people with spam, and possibly even target them with phishing, malware, and business email compromise (BEC).

The database, which includes people’s business email addresses, postal addresses, phone numbers, employer names, job titles, and links to various social media, is being sold by a threat actor alias ‘KryptonZambie’, for $6,000.

Decommissioned legacy systems

The archive was stolen from a data broker company called DemandScience (previously known as Pure Incubation) who has confirmed the data was publicly available to start with.

"It is also important to note that we process publicly available business contact information, and do not collect, store, or process consumer data or any type of credential information or sensitive personal information including accounts, passwords, home addresses or other personal, non-business information," a DemandScience spokesperson said in an email.

HaveIBeenPwned?, a website that tracks email addresses compromised in various data breaches, reports that the archive was pulled from a “decommissioned legacy system: “In early 2024, a large corpus of data from DemandScience (a company owned by Pure Incubation), appeared for sale on a popular hacking forum. Later attributed to a leak from a decommissioned legacy system, the breach contained extensive data that was largely business contact information aggregated from public sources.”

We don’t know if the hacker managed to sell the database already, or if there were multiple buyers. At press time, there was no information of in-the-wild abuse.

Via The Register

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Security
American National Insurance Company breach data found online
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
healthcare
Over a million clinical records exposed in data breach
Latest in Security
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Security
Broadcom releases fixes for multiple VMware security flaws
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Latest in News
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Asus Prime OC RTX 5070 graphics card with three fans, shown at an angle
Asus reveals Nvidia RTX 5070 launch pricing, and while one model is at MSRP – thankfully – the others make me want to give up my search for a next-gen GPU
Philips Hue lights being dimmed
Got Philips Hue lights? A free app update delivers these 3 improvements
iPad Air M3
The new iPad Air M3 is good value – but I’d still buy this iPad Pro model instead
Samsung Galaxy Z Fold 6
Samsung shows off a creaseless folding phone display – and it improves on the Galaxy Z Fold 6 design in 3 key ways
A piece of paper with the words 'an HBO Original film' on it next to a pile of snow
Jesse Armstrong’s next HBO Original sounds like another Succession-style satire starring Steve Carrell and Jason Schwartzman