Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In June 2018, security researcher Vinny Troia found an Exactis database reachable from the public internet. The Florida data broker then protected the server, but the exposure had already revealed a dataset reported at about 340 million records.

That figure is a record count, not a verified count of unique Americans or confirmed identity-theft victims. The known incident was an access-control failure or misconfiguration; available reporting does not establish that an attacker broke through authentication, how many outsiders downloaded the files, or that every record was misused.

What was Exactis?

Exactis was a small Florida marketing and data-aggregation company. A congressional record described it as having about 10 employees. Its business involved licensing consumer and business information to marketing and sales customers.

Because a data broker assembles information from many sources, its files can reveal more about a household than a single account database would. Exactis reportedly maintained detailed profiles containing contact, household and financial attributes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the exposure was discovered

In June 2018, security researcher Vinny Troia located the Exactis database on a publicly accessible or misconfigured server. Reporting said the company protected the data after it was alerted. The evidence establishes exposure through weak access controls, not a confirmed malicious intrusion.

“Breach” is commonly used as shorthand for the incident, but “data exposure” is more precise. Public reachability does not show that every record was copied, that a particular attacker obtained the files, or how many people viewed or downloaded them.

How large was the Exactis dataset?

Contemporary reporting cited roughly 340 million records. WIRED later described the files as approximately 230 million personal records and 110 million business records, totaling more than two terabytes.

Reported measure What it represents Qualification
About 340 million records Combined personal and business entries 2018 figure associated with Exactis and the Breach Level Index; not a count of unique people
About 230 million personal records Consumer-oriented entries Approximate breakdown reported by WIRED
About 110 million business records Business-related entries Approximate breakdown reported by WIRED
More than 2 terabytes Size of the reported files Describes stored data volume, not the number of victims

The available sources do not verify that 340 million unique Americans were exposed. Records can represent the same person or organization more than once, and the dataset included business information as well as personal information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information did the files contain?

Reported personal fields were unusually granular. They included:

  • Email addresses
  • Home addresses
  • Phone numbers
  • Mortgage values
  • Children’s ages or other child-related details
  • Other detailed profile attributes

WIRED reported that the files did not include credit-card numbers, passwords or Social Security numbers. That limits some direct account-takeover scenarios, but it does not make the exposure harmless: combining contact, household and financial attributes can make targeting and impersonation more convincing.

Was Exactis hacked?

There is no established evidence in the available reporting of an attacker defeating authentication or penetrating a protected network. The known mechanism was a database left reachable on the internet because of weak access controls or a server misconfiguration.

Nor is there a verified count of unauthorized downloads. The fact that a researcher could find the database proves that it was exposed, not that all 340 million records were copied or used.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Could the Exactis exposure enable identity theft?

Yes, it created a credible opportunity for harm, but it did not prove that every person in the dataset became an identity-theft victim. Email addresses, phone numbers and home addresses can support targeted spam and phishing. Mortgage information and family details can help an impostor construct a more believable social-engineering message or profile a household.

The risk is best understood as an increase in the quality of information available for profiling and deception. Reporting does not establish a universal misuse event, a confirmed number of identity-theft victims or a complete chain from the exposed files to a particular crime.

“You used to need supercomputers to do this. Now you can do it from a PC.”

— Exactis founder Steve Hardigree, describing the scale of modern data handling

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the incident means for someone who may be in the dataset

Because no public source establishes a complete list of affected individuals, most people cannot confirm their status from the 340 million figure alone. Sensible precautions focus on the kinds of follow-on abuse that detailed contact and household data can enable:

  1. Be skeptical of highly specific messages. Treat an unsolicited call, email or text that mentions your address, mortgage, family or other personal details as unverified. Contact the organization through a phone number or website you locate independently.
  2. Monitor financial and account activity. Review statements and account alerts for transactions or changes you did not authorize. Report suspicious activity to the relevant provider promptly.
  3. Strengthen account defenses. Use unique passwords and multifactor authentication on important accounts. The reported Exactis files did not contain passwords, but exposed profile data can make phishing attempts more persuasive.
  4. Consider credit protections if you see warning signs. A credit freeze or fraud alert can be appropriate when there is evidence of attempted fraud or identity theft; follow the current instructions of the applicable U.S. credit bureaus and regulators.

Why the Exactis case still matters

The episode shows why the sensitivity of a dataset cannot be judged only by whether it contains passwords or payment-card numbers. A broker’s combined records can map households, finances and contact channels at a scale that makes automated profiling practical.

It also demonstrates why incident numbers need careful wording. Exactis exposed about 340 million records, including personal and business entries, but the evidence does not convert that total into 340 million unique Americans, 340 million downloads or a measured count of identity-theft victims.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.