Skip to content
Back to Blog
critical severity February 28, 2024 · 3 min read

DemandScience by Pure Incubation Data Breach (2024)

If you are a customer of DemandScience, here’s what’s now in circulation.

In early 2024, a large corpus of data from DemandScience (a company owned by Pure Incubation), appeared for sale on a popular hacking forum. Later attributed to a leak from a decommissioned legacy system, the breach contained extensive data that was largely business contact information aggregated from public sources. Specifically, the data included 122M unique corporate email addresses, physical addresses, phone numbers, employers and job titles. It also included names and for many individuals, a link to their LinkedIn profile.

DemandScience by Pure Incubation Data Breach (2024)

On February 28, 2024, 121.8 million records belonging to DemandScience, a company owned by Pure Incubation, were added to the Have I Been Pwned database following the appearance of the dataset for sale on a popular hacking forum earlier that year. The breach, which originated from a decommissioned legacy system, exposed the personal and professional details of millions of individuals whose business contact information had been aggregated by the marketing firm.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Details Confirmed in the Disclosure

The primary disclosure on Have I Been Pwned states that the DemandScience breach occurred in early 2024 and contains 121.8 million unique records. The data exposed includes email addresses, names, phone numbers, physical addresses, employers, job titles, and links to social media profiles, predominantly LinkedIn URLs. The notification clarifies that much of the information consists of business contact details aggregated from publicly available sources, though the precise number of individuals affected remains unquantified beyond the record count. The leak-site listing and subsequent HIBP entry do not specify ransom demands or internal attack details.

Why This Matters for You and Your Family

If your professional contact information was part of this corpus, it is now permanently available to identity thieves, spammers, and fraudsters. A single exposed work email combined with your name, phone number, physical address, employer, and job title creates an immediate vector for highly targeted phishing campaigns that appear legitimate because they reference real details about your career. For families this risk extends beyond the individual; children’s names or shared household addresses listed in parental professional records can be cross-referenced with gaming usernames or school-related data, accelerating broader household targeting.

February 28, 2024 marks the point at which this dataset moved from a limited forum sale into a widely indexed breach record, meaning the window for opportunistic abuse is now open indefinitely.

Doxxing and Identity-Chain Implications

The combination of corporate emails, LinkedIn profiles, physical addresses, and phone numbers allows attackers to build complete identity chains. Once a LinkedIn URL is tied to a name and address, it is trivial to locate social-media accounts, family members, and even children’s online footprints. These chains frequently cascade into account takeovers on personal services that reuse the same email or password. Gaming accounts belonging to you or your children are particularly vulnerable because credential-stuffing tools automatically test breached corporate emails across Steam, Epic, Roblox, and Discord. The result is not theoretical; it is a documented pathway from professional data leaks to full doxxing of entire households.

What to Do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, physical addresses, and real identity, with cleanup handled by the service.
  • Rotate every password used at DemandScience or any related Pure Incubation service wherever it has been reused, and immediately enable 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught and addressed in hours rather than months.
  • Cover the entire household with DoxxScan family coverage, which extends protection to dependents and children’s gaming accounts that often chain back to the same addresses and emails exposed in breaches like this one.
  • Let DoxxScan remediation specialists manage takedown requests across data brokers and exposed profiles on your behalf while you focus on securing your accounts.

The DemandScience incident demonstrates that even data described as “aggregated from public sources” becomes far more dangerous once centralized and released in bulk. Acting quickly on the exposure of your names, employers, job titles, phone numbers, and LinkedIn profiles can prevent the slow bleed of identity compromise that follows these large business-data leaks. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that explicitly includes children’s gaming accounts at risk of cascading takeovers.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a DemandScience customer?
DemandScience is one listing. Your email is probably in others.
121.8M accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Critical contact details only, none of them permanent
Disclosed February 28, 2024
Last reviewed July 22, 2026
Affected 121.8M
Data exposed Email addressesEmployersJob titlesNamesPhone numbersPhysical addressesSocial media profiles
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email