Free tools Windows power users keep installed
One-click scans. No signup required.
In June 2018, security researcher Vinny Troia found an Exactis database reachable from the public internet. The Florida data broker then protected the server, but the exposure had already revealed a dataset reported at about 340 million records.
That figure is a record count, not a verified count of unique Americans or confirmed identity-theft victims. The known incident was an access-control failure or misconfiguration; available reporting does not establish that an attacker broke through authentication, how many outsiders downloaded the files, or that every record was misused.
What was Exactis?
Exactis was a small Florida marketing and data-aggregation company. A congressional record described it as having about 10 employees. Its business involved licensing consumer and business information to marketing and sales customers.
Because a data broker assembles information from many sources, its files can reveal more about a household than a single account database would. Exactis reportedly maintained detailed profiles containing contact, household and financial attributes.
Recommended Free Tools
#1 Best Overall
How the exposure was discovered
In June 2018, security researcher Vinny Troia located the Exactis database on a publicly accessible or misconfigured server. Reporting said the company protected the data after it was alerted. The evidence establishes exposure through weak access controls, not a confirmed malicious intrusion.
“Breach” is commonly used as shorthand for the incident, but “data exposure” is more precise. Public reachability does not show that every record was copied, that a particular attacker obtained the files, or how many people viewed or downloaded them.
How large was the Exactis dataset?
Contemporary reporting cited roughly 340 million records. WIRED later described the files as approximately 230 million personal records and 110 million business records, totaling more than two terabytes.
| Reported measure | What it represents | Qualification |
|---|---|---|
| About 340 million records | Combined personal and business entries | 2018 figure associated with Exactis and the Breach Level Index; not a count of unique people |
| About 230 million personal records | Consumer-oriented entries | Approximate breakdown reported by WIRED |
| About 110 million business records | Business-related entries | Approximate breakdown reported by WIRED |
| More than 2 terabytes | Size of the reported files | Describes stored data volume, not the number of victims |
The available sources do not verify that 340 million unique Americans were exposed. Records can represent the same person or organization more than once, and the dataset included business information as well as personal information.
What information did the files contain?
Reported personal fields were unusually granular. They included:
- Email addresses
- Home addresses
- Phone numbers
- Mortgage values
- Children’s ages or other child-related details
- Other detailed profile attributes
WIRED reported that the files did not include credit-card numbers, passwords or Social Security numbers. That limits some direct account-takeover scenarios, but it does not make the exposure harmless: combining contact, household and financial attributes can make targeting and impersonation more convincing.
Was Exactis hacked?
There is no established evidence in the available reporting of an attacker defeating authentication or penetrating a protected network. The known mechanism was a database left reachable on the internet because of weak access controls or a server misconfiguration.
Nor is there a verified count of unauthorized downloads. The fact that a researcher could find the database proves that it was exposed, not that all 340 million records were copied or used.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsCould the Exactis exposure enable identity theft?
Yes, it created a credible opportunity for harm, but it did not prove that every person in the dataset became an identity-theft victim. Email addresses, phone numbers and home addresses can support targeted spam and phishing. Mortgage information and family details can help an impostor construct a more believable social-engineering message or profile a household.
The risk is best understood as an increase in the quality of information available for profiling and deception. Reporting does not establish a universal misuse event, a confirmed number of identity-theft victims or a complete chain from the exposed files to a particular crime.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.“You used to need supercomputers to do this. Now you can do it from a PC.”
— Exactis founder Steve Hardigree, describing the scale of modern data handling
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
What the incident means for someone who may be in the dataset
Because no public source establishes a complete list of affected individuals, most people cannot confirm their status from the 340 million figure alone. Sensible precautions focus on the kinds of follow-on abuse that detailed contact and household data can enable:
- Be skeptical of highly specific messages. Treat an unsolicited call, email or text that mentions your address, mortgage, family or other personal details as unverified. Contact the organization through a phone number or website you locate independently.
- Monitor financial and account activity. Review statements and account alerts for transactions or changes you did not authorize. Report suspicious activity to the relevant provider promptly.
- Strengthen account defenses. Use unique passwords and multifactor authentication on important accounts. The reported Exactis files did not contain passwords, but exposed profile data can make phishing attempts more persuasive.
- Consider credit protections if you see warning signs. A credit freeze or fraud alert can be appropriate when there is evidence of attempted fraud or identity theft; follow the current instructions of the applicable U.S. credit bureaus and regulators.
Why the Exactis case still matters
The episode shows why the sensitivity of a dataset cannot be judged only by whether it contains passwords or payment-card numbers. A broker’s combined records can map households, finances and contact channels at a scale that makes automated profiling practical.
It also demonstrates why incident numbers need careful wording. Exactis exposed about 340 million records, including personal and business entries, but the evidence does not convert that total into 340 million unique Americans, 340 million downloads or a measured count of identity-theft victims.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

