LimeLeads Breach: 17.8M Email Addresses Exposed (2026)
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, empl...
Overview
LimeLeads, a B2B marketing leads database that has since shut down, left an Elasticsearch server completely unprotected. Anyone who knew where to look could read the entire database without a password. The result was one of the largest corporate contact leaks ever reported, involving 17,838,396 unique email addresses along with phone numbers, employers, job titles, and geographic locations.
The data surfaced in 2019 and was later added to Have I Been Pwned, which means affected addresses are now searchable by anyone. Because the company no longer operates, there is no customer support line, no breach notification email, and no vendor tool to tell you whether your record was included. The only official verification path is Have I Been Pwned itself.
What Was Exposed
The leaked records were not passwords or payment cards. They were professional profiles, and that distinction matters.
- Email addresses - 17.8 million unique addresses, mostly work accounts
- Phone numbers - direct dials and office lines tied to named individuals
- Employers - who you worked for at the time
- Job titles - your role and likely seniority
- Geographic locations - state, city, and postcode
Individually these fields look harmless. Combined, they form a ready-made targeting profile.
Why Corporate Contact Data Is Dangerous
An attacker reading this dataset does not need to guess. They know your name, your employer, your title, your city, and two ways to reach you. That is the exact input that makes business email compromise and phishing convincing.
A common play runs like this: a fraudster emails a finance employee, names their actual manager, references their real office location, and requests an urgent wire or gift card purchase. The detail makes the message feel internal. Seniority data makes targeting worse, since executives, IT staff, and finance roles appear in plain text. Because these are work accounts, the fallout often lands on employers rather than the individuals whose data leaked.
How the Breach Happened
Elasticsearch is a database engine that ships without authentication enabled by default. If an administrator exposes it to the internet without adding a password, the entire index is public. This class of misconfiguration has produced a long line of leaks, and it is one of the most preventable failures in cybersecurity news.
For LimeLeads, there was no exploit, no ransomware, and no sophisticated intrusion. There was simply a door left open, and the company’s closure means no one was ever held accountable for closing it.
What to Do Right Now
You cannot change what leaked, but you can reduce how useful it is to an attacker.
- Search your email at Have I Been Pwned to confirm exposure
- Treat unsolicited calls and emails that reference your employer or title as suspicious by default
- Verify any payment, wire, or credential request through a second channel you initiate yourself
- Enable multi-factor authentication on your work and personal email accounts
- Consider a secondary email address for public-facing or marketing signups
- Watch for SIM-swap and vishing attempts, since your phone number is in the dump
If you handle finance or IT duties, warn your team that their names and roles may already be in circulation.
Security Insight
This breach is a textbook example of a company treating a lead-generation database as low-risk because it held no passwords or card numbers, when in fact context is exactly what makes social engineering work. The corporate data broker industry has produced repeated incidents of this kind, and the pattern is consistent: contact records get scraped, aggregated, and then abandoned on an unsecured server with no owner left to secure it. The lesson for individuals is that your professional identity is a permanent asset other people can lose for you, and the lesson for buyers is that a vendor’s willingness to sell contact data says nothing about whether they can protect it.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included nam...
In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group . Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, ...
In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-control...