Critical

LimeLeads Breach: 17.8M Email Addresses Exposed (2026)

By Yazoul AI · automated

In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, empl...

Overview

LimeLeads, a B2B marketing leads database that has since shut down, left an Elasticsearch server completely unprotected. Anyone who knew where to look could read the entire database without a password. The result was one of the largest corporate contact leaks ever reported, involving 17,838,396 unique email addresses along with phone numbers, employers, job titles, and geographic locations.

The data surfaced in 2019 and was later added to Have I Been Pwned, which means affected addresses are now searchable by anyone. Because the company no longer operates, there is no customer support line, no breach notification email, and no vendor tool to tell you whether your record was included. The only official verification path is Have I Been Pwned itself.

What Was Exposed

The leaked records were not passwords or payment cards. They were professional profiles, and that distinction matters.

  • Email addresses - 17.8 million unique addresses, mostly work accounts
  • Phone numbers - direct dials and office lines tied to named individuals
  • Employers - who you worked for at the time
  • Job titles - your role and likely seniority
  • Geographic locations - state, city, and postcode

Individually these fields look harmless. Combined, they form a ready-made targeting profile.

Why Corporate Contact Data Is Dangerous

An attacker reading this dataset does not need to guess. They know your name, your employer, your title, your city, and two ways to reach you. That is the exact input that makes business email compromise and phishing convincing.

A common play runs like this: a fraudster emails a finance employee, names their actual manager, references their real office location, and requests an urgent wire or gift card purchase. The detail makes the message feel internal. Seniority data makes targeting worse, since executives, IT staff, and finance roles appear in plain text. Because these are work accounts, the fallout often lands on employers rather than the individuals whose data leaked.

How the Breach Happened

Elasticsearch is a database engine that ships without authentication enabled by default. If an administrator exposes it to the internet without adding a password, the entire index is public. This class of misconfiguration has produced a long line of leaks, and it is one of the most preventable failures in cybersecurity news.

For LimeLeads, there was no exploit, no ransomware, and no sophisticated intrusion. There was simply a door left open, and the company’s closure means no one was ever held accountable for closing it.

What to Do Right Now

You cannot change what leaked, but you can reduce how useful it is to an attacker.

  • Search your email at Have I Been Pwned to confirm exposure
  • Treat unsolicited calls and emails that reference your employer or title as suspicious by default
  • Verify any payment, wire, or credential request through a second channel you initiate yourself
  • Enable multi-factor authentication on your work and personal email accounts
  • Consider a secondary email address for public-facing or marketing signups
  • Watch for SIM-swap and vishing attempts, since your phone number is in the dump

If you handle finance or IT duties, warn your team that their names and roles may already be in circulation.

Security Insight

This breach is a textbook example of a company treating a lead-generation database as low-risk because it held no passwords or card numbers, when in fact context is exactly what makes social engineering work. The corporate data broker industry has produced repeated incidents of this kind, and the pattern is consistent: contact records get scraped, aggregated, and then abandoned on an unsecured server with no owner left to secure it. The lesson for individuals is that your professional identity is a permanent asset other people can lose for you, and the lesson for buyers is that a vendor’s willingness to sell contact data says nothing about whether they can protect it.

Further Reading

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.