[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ktv3buqcqoes":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":31,"seoTitle":10,"seoTitleEn":32,"seoDescription":10,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":4,"isMalware":35,"company":36},"68e3266eda11adda488250c7","Acuity","Acuity Spam Data List","acuity","","2020-06-18T00:00:00.000Z","2023-11-15T07:16:23.000Z","2026-07-20T05:21:05.363Z","Unknown","https:\u002F\u002Fwww.troyhunt.com\u002Facuity-who-attempts-and-failures-to-attribute-437gb-of-breached-data\u002F",[15],14055729,"known",null,"email_identifiers","Critical",[23,24,25,26,27,28,29,30],"Dates of birth","Email addresses","Genders","IP addresses","Names","Phone numbers","Physical addresses","Salutations","\u003Cp>The June 18, 2020-dated \u003Cstrong>Acuity data corpus\u003C\u002Fstrong> contains 14,055,729 unique email addresses across 21,873,706 rows.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified data classes are dates of birth, email addresses, genders, IP addresses, names, phone numbers, physical addresses, and salutations. The source file had an exceptionally broad and orderly structure of 414 columns, but only the eight explicitly verified classes are shown publicly. Passwords, payment cards, and identity-document numbers are not verified classes and should not be treated as exposed. Combining a name, birth date, phone number, email, and street address can support targeted phishing, fake support calls, postal fraud, and attempts to infer identity-verification answers. The presence of a field does not mean it was populated, current, or correctly linked to the same person in every row. Because this is an \u003Cstrong>unattributed aggregated data set\u003C\u002Fstrong>, a match does not prove that someone was a customer of any company named Acuity.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>June 18, 2020 was selected from the filename “ACUITY_MASTER_18062020.csv”; it is not a confirmed date of system access or extraction. The approximately 437 GB corpus was later distributed extensively and underwent detailed attribution analysis in 2023. The file contained 21,873,706 email rows, of which 14,055,729 were unique, so total records and unique affected addresses are different measures. Highly standardized formatting, many different values in a “datasource” field, and the fact that almost every address had already appeared in other breach or spam collections suggest that a data aggregator may have assembled it rather than it being a raw user table from one service. That possibility does not prove a specific organization. None of the healthcare, insurance, software, lighting, or scheduling businesses named Acuity could be confidently verified as the source, so the corpus must not be attributed to them.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People at risk are those whose email appears in the corpus and whose row may connect a name, phone, address, birth date, gender, salutation, or IP context. They do not need to have had any relationship with a business named Acuity; the data may have been combined from marketing lists, older services, or collections already in circulation. Employees using corporate email addresses can receive more convincing invoice, delivery, human-resources, or support messages when phone and postal context is available. Consumers should be cautious with fake bank, shipping, insurance, or government messages that combine a name, birth date, and address. Clean formatting does not guarantee accuracy: old addresses, reassigned phone numbers, and incorrect person matches may exist. Results must therefore be interpreted with both security exposure and false-association risk in mind.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>No password field was verified\u003C\u002Fstrong> in this record, so an Acuity match alone does not require a password reset as the first response. Increase scrutiny of unexpected email, phone, and postal messages. Do not assume a sender is legitimate merely because they know a name, birth date, or address; those details may come from aggregated data. Verify account, payment, delivery, and identity requests by opening the organization’s official site yourself rather than following a message link. Never disclose a one-time code, security answer, or identity-document image. Enable multi-factor authentication on email, review suspicious sessions, and block unwanted calls or messages. If unexpected credit, subscription, or account notices appear at your address, contact the named organization through an independent channel. Consider data-broker removal and correction processes for inaccurate or outdated information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Protection from aggregated data collections requires a broader approach than securing one account. Separating personal and business email, using aliases where appropriate on public forms, and leaving unnecessary profile fields blank make it harder to correlate records across sources. Use multi-factor authentication on email and important accounts, store unique passwords in a password manager, and review recovery details regularly. Treat phone numbers, birth dates, and street addresses as fixed identifiers rather than secret passwords; ask support providers not to accept those fields alone as proof of identity. Periodically review opt-out options for data brokers and marketing lists. Consider credit or identity monitoring where available and proportionate to your risk. Monitoring new breach matches and maintaining phishing awareness reduce the impact when old information is repackaged and redistributed years later.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>An Acuity match through LeakData means the email address appears in this unattributed corpus; it does not show that you were a customer of a particular Acuity company or that such a company lost your data. It also does not prove that all eight data categories were populated or accurate in your row. Treat the result as a warning that contact information may have circulated in marketing or spam lists. Never enter an actual password, birth date, or street address into a breach-search field. No match is not an absolute guarantee that personal information is absent from other collections. Monitor security alerts on your email, verify suspicious messages through independent channels, and keep multi-factor authentication enabled. The correct response is to manage exposure and targeted-fraud risk without assigning blame to an unverified organization.\u003C\u002Fp>","Acuity Spam Data List (14.1 Million Email Identifiers)","Acuity Spam Data List. 14.1 Million email identifiers were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Facuity.webp",false,{"name":37,"sector":38,"country":14,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":19},"Unattributed Acuity data corpus","Unattributed Data Corpus"]