[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1152b5mhhfnee":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882514a","clearvoice-surveys","ClearVoice Surveys Data Breach","clearvoicesurveys.com","2015-08-23T00:00:00.000Z","2021-04-23T05:00:19.000Z","2026-07-20T04:12:38.338Z","Config exposure","https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002FCalifornia%20-%20Data%20Breach%20Notification%204.29.21.pdf",[14,16,17,18],"https:\u002F\u002Fwww.troyhunt.com\u002Fweekly-update-240\u002F","https:\u002F\u002Fwww.clearvoicesurveys.com\u002F","https:\u002F\u002Fcdn.sanity.io\u002Fimages\u002Fr5dhxbq7\u002Fproduction\u002Fc3b2a129f92416ec72eebab427a10106ac94a98c-2977x422.png?fm=webp",15074786,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32],"Dates of birth","Email addresses","Genders","IP addresses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>The exposed 2015 ClearVoice Surveys backup contained 15,074,786 unique email addresses and sensitive profile information.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>\u003Cstrong>The verified scope includes 15,074,786 unique email addresses plus names, dates of birth, genders, IP addresses, telephone numbers, physical addresses and plaintext passwords.\u003C\u002Fstrong> More than 17 million rows existed in the source files, but duplicate entries mean that figure is not the number of unique accounts; the public count uses unique email addresses. Payment cards, bank accounts, identity-document numbers, private messages and survey answers are not verified data classes and must not be implied. Plaintext passwords increase risk because an attacker does not need to crack a hash before testing the same credential on other services. A name, birth date, telephone number and address linked to an email can also support targeted phishing, fake support contact, account-recovery fraud and guesses at knowledge-based verification questions.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The breach date of 23 August 2015 represents the period of the database backup that was exposed. The incident became public in April 2021 when the old, publicly reachable backup was taken and redistributed on a criminal forum. The company said it was aware of the event and confirmed that the data was authentic. Evidence points to ClearVoice Surveys backup data being left externally accessible, not to a compromise of an unrelated supplier, so the technical source is classified as a configuration exposure. The description stays within the confirmed backup exposure and redistribution. The 2021 added date is not the date on which the records were created; users assessing their risk should focus on contact details and passwords used around 2015.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Risk is highest for people who reused their 2015 password on email, social media, shopping or workplace accounts. Even if the original password was changed years ago, small variations of the same pattern on other services can remain vulnerable to automated sign-in attempts. The combination of address, telephone number, birth date and gender can help an attacker prepare messages suited to a person's age, location or survey membership. A match does not by itself prove identity theft, current account takeover or exposure of financial information. A sound assessment considers password reuse, recent email sessions, unexpected reset messages and suspicious calls that use personal details together. Someone who knows an address or birth date should not be trusted without independent verification.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>If you reused the password or a close variation from your 2015 ClearVoice Surveys account, create a unique password on every affected service.\u003C\u002Fstrong> Secure the primary email account, password manager, financial services and other identities capable of resetting accounts first. Review active sessions, end access from unknown devices, verify recovery email and telephone details, and enable a passkey or multifactor authentication where available. Do not treat small character or number changes to an old password as safe. Avoid following links in messages that use surveys, rewards, gift cards or account verification as a pretext; open the service through its known address instead. A caller's knowledge of your name, physical address or birth date does not prove their identity. If you see an unfamiliar reset, forwarding rule or new-device alert, begin the email provider's official recovery process immediately.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>A password manager that generates a separate random credential for every service prevents an old plaintext password from causing a chain of account takeovers. Move to passkeys where supported and use phishing-resistant authentication on the primary email account. Keep recovery codes offline and review connected applications and email-forwarding rules regularly. Long-lived details such as a birth date, telephone number and physical address should never be used as passwords or security-question answers. Organisations monitoring employee addresses should assess suspicious sessions, password reuse and social-engineering reports together instead of relying only on a match count. Service providers should keep backups outside public web roots, restrict access under least privilege, continuously review storage permissions and never retain plaintext passwords. Old backups require the same protection as production data and should be securely deleted when their retention period ends.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address through the secure search field to learn whether it appears in the ClearVoice Surveys record and prioritise password changes after a match.\u003C\u002Fstrong> A result does not mean your current password is unchanged or that an account has definitely been taken over; it reports that the address exists in the verified 2015 backup. Recall password patterns used at that time, replace the same or similar password everywhere it remains active and review recent sessions on the primary email account. Treat unexpected messages containing a telephone number, address or birth date as potentially personalised fraud. No result cannot guarantee that the address was absent from every other incident. Continued monitoring, unique passwords and strong authentication provide effective protection if this old dataset is reused years later.\u003C\u002Fp>","","ClearVoice Surveys Data Breach (15.1 Million Reported Records)","ClearVoice Surveys Data Breach. 15.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fclearvoice-surveys-official.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"ClearVoice Surveys","Market research survey platform","United States"]