Was my contact info sold? California’s SalesIntel data-broker case explained
If you are a customer of Was my contact info sold? California’s, here’s what is being claimed, and what it would mean for you.
California’s privacy regulator fined Virginia-based SalesIntel Research $36,400 for acting as a data broker in 2024 without registering on time. The company had collected and sold names, job titles, emails, and phone numbers on people it never did business with, in a file described as more than 200 million professional contacts and 54 million mobile numbers. Two other brokers, LocateSmarter and Cybba, were fined in August 2026 over similar failures.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On September 1, 2026, California’s privacy regulator announced that it had fined a Virginia company, SalesIntel Research, $36,400 for operating as a data broker in 2024 without registering by the January 31, 2025 deadline. Of that amount, $6,600 is the 2025 registration fee. SalesIntel had been collecting and selling personal information about people it had no direct relationship with. It later registered on time in 2026 for its 2025 activity.
Watch Was my contact info sold? California’s
Get alerted the next time Was my contact info sold? California’s files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Was my contact info sold? California’s’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
The regulator’s order describes more than 200 million professional contacts and 54 million mobile phone numbers, along with inferences about people’s career changes and products that try to turn anonymous website visits into contact details. The information involved includes names, job titles, emails, and phone numbers. The order does not say how many unique people that represents. In the same enforcement wave, Iowa-based LocateSmarter was ordered on August 11, 2026 to pay $116,490, and Boston-based Cybba was ordered on August 13, 2026 to pay $52,400, both for failing to register on time. LocateSmarter was also penalized for California privacy-law violations, including making people provide the last four digits of a Social Security number in order to opt out.
This was not a break-in — and the fine does not take the file off the market
Most write-ups of this case treat it as a late-registration story: a company missed a deadline, California issued a modest fine, enforcement continues. That is accurate, and it is also the part that does not help you decide whether to worry.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
SalesIntel was not a service you opened an account with. It was in the business of gathering information on people it never met and selling it. The $36,400 — a figure that includes the registration fee — does not buy those records back. Agreeing to register does not mean the database is deleted. The company was not shut down; it registered for later activity and remains in that business, with extra rules attached. Copies already sold to other buyers are not recalled by this order.
You should also not wait for a “you were hacked” letter. Nobody is described as breaking into SalesIntel. This is not a hospital, bank, or payroll dump. The honest read is drier than a breach headline and more common than most people realize: a sales-intelligence firm packaged work-life details — who you are at work, how to reach you, whether you might have changed jobs — and sold access to that package. For a lot of people, the day-to-day effect is more unsolicited outreach, not emptied accounts. The sharper risk is joining. A work email and a mobile number in a broker’s file become much more useful to a scammer or a harasser once they are matched to a public people-search listing that adds relatives, extra phone numbers, employers, and previous addresses.
One other detail in the order is easy to skip if you are not in the industry. SalesIntel offered products that try to de-anonymize website traffic — meaning a visit you thought was just a browser session could be tied back to contact data. That is not the same as someone reading your private messages. It is a reminder that “I never gave them my number” is not a complete defense against being in a file like this.
What to actually expect
- You will not get a personal notice telling you that you were, or were not, in SalesIntel’s file. This is a regulator’s penalty, not a consumer breach letter, and there is no public list of names.
- SalesIntel must pay the $36,400 within 30 days, post in its privacy policy how many California privacy requests it gets and how it handles them, and start using the state’s shared deletion system (called DROP) for future deletion requests.
- The contact data already collected, and any copies already sold, stays where it is. This order does not pull it back, and SalesIntel is still allowed to operate as a registered broker.
- LocateSmarter and Cybba are under similar orders from the same stretch of August 2026. Do not expect those cases to produce a personal “you were included” email either.
What you can and cannot fix
What cannot be undone is the data already gathered and already sold. If your name, job title, email address, mobile number, or a guess about a career change was in SalesIntel’s 2024 files — or in a copy a customer already bought — that copy is out. It cannot be recalled. The same is true of records held by the other brokers in this wave. There is no reset button, and no trustworthy way to get a yes-or-no answer on whether you specifically were in the 200 million contacts.
- Use California’s deletion system going forward, if you live in California. The actual new lever in this case is that SalesIntel must connect to the state’s Delete Request and Opt-out Platform and process future deletion requests through it. That can stop some further sales by this broker. It does not erase what already left.
- Shrink the people-search listings that make a broker record dangerous. A bare work-contact record is limited on its own. It becomes a problem when it is joined to people-search sites that add relatives, extra phone numbers, employers, and previous addresses. Those public listings, unlike the copies already sold, can actually be removed or suppressed. That is the cleanup that still has leverage.
- Do not hand brokers more identity in order to disappear. LocateSmarter was penalized in part for requiring the last four digits of a Social Security number to opt out. If a data broker demands extra ID, pause. You should not have to give them a national identifier to ask them to stop selling you.
- Treat calls or emails that already know your job title or a recent role change as a reason to slow down, not to cooperate. Check independently. Do not confirm extra personal details, codes, or payments just because the caller already has your work identity.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Verifications.io — 763 Million Email Records Left on an Open Database (2019)
An email-validation firm most people had never heard of left 763 million records in a MongoDB instan…
Exactis — 340 Million Records of Profiling Data Nobody Consented To (2018)
A marketing data broker left an ElasticSearch node exposed with no firewall. It held about 340 milli…
United Underwriters Data Breach Notice (California Attorney General)
United Underwriters notified California residents of a data breach in a filing reported to the Calif…