DemandScience by Pure Incubation Data Breach (2024)
If you are a customer of DemandScience, here’s what’s now in circulation.
In early 2024, a large corpus of data from DemandScience (a company owned by Pure Incubation), appeared for sale on a popular hacking forum. Later attributed to a leak from a decommissioned legacy system, the breach contained extensive data that was largely business contact information aggregated from public sources. Specifically, the data included 122M unique corporate email addresses, physical addresses, phone numbers, employers and job titles. It also included names and for many individuals, a link to their LinkedIn profile.
DemandScience customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On February 28, 2024, 121.8 million records belonging to DemandScience, a company owned by Pure Incubation, were added to the Have I Been Pwned database following the appearance of the dataset for sale on a popular hacking forum earlier that year. The breach, which originated from a decommissioned legacy system, exposed the personal and professional details of millions of individuals whose business contact information had been aggregated by the marketing firm.
Details Confirmed in the Disclosure
The primary disclosure on Have I Been Pwned states that the DemandScience breach occurred in early 2024 and contains 121.8 million unique records. The data exposed includes email addresses, names, phone numbers, physical addresses, employers, job titles, and links to social media profiles, predominantly LinkedIn URLs. The notification clarifies that much of the information consists of business contact details aggregated from publicly available sources, though the precise number of individuals affected remains unquantified beyond the record count. The leak-site listing and subsequent HIBP entry do not specify ransom demands or internal attack details.
Why This Matters for You and Your Family
If your professional contact information was part of this corpus, it is now permanently available to identity thieves, spammers, and fraudsters. A single exposed work email combined with your name, phone number, physical address, employer, and job title creates an immediate vector for highly targeted phishing campaigns that appear legitimate because they reference real details about your career. For families this risk extends beyond the individual; children’s names or shared household addresses listed in parental professional records can be cross-referenced with gaming usernames or school-related data, accelerating broader household targeting.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
February 28, 2024 marks the point at which this dataset moved from a limited forum sale into a widely indexed breach record, meaning the window for opportunistic abuse is now open indefinitely.
Doxxing and Identity-Chain Implications
The combination of corporate emails, LinkedIn profiles, physical addresses, and phone numbers allows attackers to build complete identity chains. Once a LinkedIn URL is tied to a name and address, it is trivial to locate social-media accounts, family members, and even children’s online footprints. These chains frequently cascade into account takeovers on personal services that reuse the same email or password. Gaming accounts belonging to you or your children are particularly vulnerable because credential-stuffing tools automatically test breached corporate emails across Steam, Epic, Roblox, and Discord. The result is not theoretical; it is a documented pathway from professional data leaks to full doxxing of entire households.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, physical addresses, and real identity, with cleanup handled by the service.
- Rotate every password used at DemandScience or any related Pure Incubation service wherever it has been reused, and immediately enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught and addressed in hours rather than months.
- Cover the entire household with DoxxScan family coverage, which extends protection to dependents and children’s gaming accounts that often chain back to the same addresses and emails exposed in breaches like this one.
- Let DoxxScan remediation specialists manage takedown requests across data brokers and exposed profiles on your behalf while you focus on securing your accounts.
The DemandScience incident demonstrates that even data described as “aggregated from public sources” becomes far more dangerous once centralized and released in bulk. Acting quickly on the exposure of your names, employers, job titles, phone numbers, and LinkedIn profiles can prevent the slow bleed of identity compromise that follows these large business-data leaks. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that explicitly includes children’s gaming accounts at risk of cascading takeovers.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →