On February 28, 2024, 121.8 million records belonging to DemandScience, a company owned by Pure Incubation, were added to the Have I Been Pwned database following the appearance of the dataset for sale on a popular hacking forum earlier that year. The breach, which originated from a decommissioned legacy system, exposed the personal and professional details of millions of individuals whose business contact information had been aggregated by the marketing firm.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details Confirmed in the Disclosure
The primary disclosure on Have I Been Pwned states that the DemandScience breach occurred in early 2024 and contains 121.8 million unique records. The data exposed includes email addresses, names, phone numbers, physical addresses, employers, job titles, and links to social media profiles, predominantly LinkedIn URLs. The notification clarifies that much of the information consists of business contact details aggregated from publicly available sources, though the precise number of individuals affected remains unquantified beyond the record count. The leak-site listing and subsequent HIBP entry do not specify ransom demands or internal attack details.
Why This Matters for You and Your Family
If your professional contact information was part of this corpus, it is now permanently available to identity thieves, spammers, and fraudsters. A single exposed work email combined with your name, phone number, physical address, employer, and job title creates an immediate vector for highly targeted phishing campaigns that appear legitimate because they reference real details about your career. For families this risk extends beyond the individual; children’s names or shared household addresses listed in parental professional records can be cross-referenced with gaming usernames or school-related data, accelerating broader household targeting.
February 28, 2024 marks the point at which this dataset moved from a limited forum sale into a widely indexed breach record, meaning the window for opportunistic abuse is now open indefinitely.