The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The incident behind the 763-million figure was the 2019 Verifications.io exposure, not a newly reported breach. A MongoDB database used by the email-validation service was reportedly reachable from the public internet without authentication. Mozilla Monitor lists approximately 763 million unique email addresses; a separate UpGuard account reports about 809 million total records. Those are different measurements, and neither establishes how many individual people were affected.
What happened in the Verifications.io exposure?
Verifications.io provided email-validation services. Reports about the incident described a MongoDB database that could be accessed publicly without a password or other authentication control. Mozilla Monitor dates the incident to February 25, 2019, and records it in its breach database on March 9, 2019.
Public accessibility shows that the database was exposed to the internet. The available incident records do not establish how many people downloaded the data, whether a particular attacker copied it, or whether it was later misused. Those questions remain separate from the fact that the database was reportedly reachable.
How should the 763 million and 809 million figures be read?
The headline number is a count of email-address entries, not a count of people. Another report uses a larger total-record count. Deduplication, repeated records and the proportion of entries belonging to the same person mean the figures cannot be converted into a person-level total.
#1 Best Overall
| Figure | What it measures | Source and qualification |
|---|---|---|
| Approximately 763 million | Unique email addresses | Mozilla Monitor’s Verifications.io listing; incident dated February 25, 2019 and added to its breach database March 9, 2019. |
| About 809 million | Total records | UpGuard report dated September 22, 2026; total records are not the same as unique addresses or unique people. |
There is no authoritative person-level count in the available incident records, and they do not establish what share of entries was newly added to any later breach index.
What data was reportedly exposed?
Incident listings describe a dataset extending beyond email addresses. Depending on the record, it reportedly included:
- email addresses
- IP addresses
- phone numbers
- dates of birth
- physical addresses
- names, employers, genders and geographic locations
- job titles
These are reported categories, not a guarantee that every record contained every field. Mozilla Monitor’s listing says passwords were not exposed. The incident should therefore not be described as a password breach.
What are the practical risks?
More convincing unwanted contact
Combining an email address with a phone number, location, employer or job title can make phishing, spam and impersonation attempts appear more credible. That is a risk explanation, not evidence that misuse occurred in this incident.
Recommended Free Tools
Personal-information exposure
Addresses, birth dates and contact details can increase the impact of later data matching. The public records do not provide a verified measure of downstream harm or confirmed misuse.
No password-reset mandate from this incident alone
Because the incident listing says passwords were not included, a password reset is not required solely because an address appears in the Verifications.io listing. Password changes are still appropriate wherever a person reused a password exposed in a different breach.
How to check whether your email appears
- Search for the address in Mozilla Monitor’s Verifications.io breach listing or in Have I Been Pwned.
- Use the exact address you want to check, including any older or secondary addresses.
- Read the result as confirmation that the address appears in indexed breach data, not as a complete history of every copy of the database.
- If the service reports a match, treat messages that use your employer, location, phone number or other profile details as possible social-engineering attempts.
A “no result” response cannot prove that an address was never exposed: lookup services index particular datasets and may not contain every copy or later redistribution.
What should you do after checking?
Use unique passwords
Give every important account its own password. A password manager can generate and store those credentials, reducing the chance that a password from an unrelated incident can unlock another service.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Change reused credentials where needed
If you used the same password on accounts involved in another breach, change it on every affected account and enable multifactor authentication where available. That advice addresses password reuse generally; it does not imply that Verifications.io exposed passwords.
Harden your response to targeted messages
- Do not confirm personal details in an unexpected email, call or text.
- Open a company or financial service through a known bookmark or typed address rather than a message link.
- Check the sender domain and independently verify urgent requests for payment, codes or account changes.
- Consider whether an exposed phone number or address makes a request unusually specific; specificity is not proof of legitimacy.
What is still unknown?
- The number of people represented by the records.
- How many records were downloaded or copied.
- Whether a regulator or court made a formal finding.
- Whether Verifications.io issued a verified public statement in the available reporting.
- How much confirmed downstream fraud, spam or social-engineering activity resulted from this exposure.
Keeping these unknowns separate prevents the 763-million address figure from being presented as a confirmed count of victims or as proof of misuse.
Bottom line on the “latest” wording
The event identified by this headline is a 2019 Verifications.io database misconfiguration. The durable facts are the reported unauthenticated public access, the approximately 763 million unique-address figure, the separate 809 million total-record figure, and the reported inclusion of contact and profile data without passwords. Check reputable breach indexes, use unique credentials and remain alert to tailored messages, while recognizing that a lookup cannot erase exposed data or prove that no other copy exists.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

