[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1iz2o8gw8hd66":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825162","db8151dd","Covve Data Breach","covve","covve.com","2020-02-20T00:00:00.000Z","2020-05-15T08:06:11.000Z","2020-05-19T20:25:18.000Z","2026-07-19T16:52:58.315Z","Verified Covve contact-data exposure","https:\u002F\u002Fwww.troyhunt.com\u002Fthe-unattributable-db8151dd-data-breach\u002F",[16,18,19],"https:\u002F\u002Fcovve.com\u002Fopinion\u002Fsecurity-incident","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fcovve-contacts-app-data-breach-exposes-23-million-emails-addresses-and-other-private-details",22802117,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Email addresses","Job titles","Names","Phone numbers","Physical addresses","Social media profiles","\u003Cp>The db8151dd breach later attributed to Covve exposed 22,802,117 unique email addresses in February 2020. Approximately 90 GB of data found on a publicly accessible Elasticsearch server contained contact and professional-profile information belonging to Covve users and people in their address books. The verified \u003Cstrong>22,802,117 unique email addresses\u003C\u002Fstrong> were deduplicated from 103,150,616 rows and represent the searchable scope. This is not a count of Covve user accounts, and the same person or contact may have appeared in multiple rows.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified data classes are email addresses, names, phone numbers, physical addresses, job titles, and social-media profiles. Combining these fields can support targeted phishing, telephone scams, fake business correspondence, and the linking of a person's online profiles. Address-book data can affect not only an app user but also customers, colleagues, friends, or other contacts saved by that user. \u003Cstrong>Passwords are not a verified data class in this breach\u003C\u002Fstrong>, so the incident should not be represented as a direct password leak, password-cracking event, or payment-data loss. The social-media-profile field refers to profile identities or links; it does not prove that private messages or social-network credentials were exposed.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>According to the company disclosure, unauthorized access occurred before a system associated with the retired Covve web app was decommissioned in early January 2020. In February, the large dataset was found on an externally accessible Elasticsearch instance hosted by a cloud provider. Its source was initially unknown, so the record was named after the “db8151dd” identifier that appeared repeatedly in the data. The canonical reference date is 20 February. Although the dataset contained more than 103 million rows, deduplication produced 22,802,117 unique email addresses. The source was later confirmed as the legacy Covve system. The company said it learned of the incident on 15 May, launched an investigation, contacted the regulator, and informed users; the breach attribution was updated to Covve on 19 May.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The affected population is not limited to people who opened a Covve account. The company said data belonging to approximately \u003Cstrong>90,000 Covve users\u003C\u002Fstrong> was compromised, while the 22.8 million unique-email figure reflects the much larger population stored in those users' address books. Someone who never used the app may therefore appear because another person saved them as a contact. When job titles, social profiles, phone numbers, and email addresses are combined, executives, sales staff, and people in public-facing roles can receive more convincing social-engineering messages. Records containing physical addresses create additional privacy and unwanted-contact risk. Because passwords and financial data were not verified, direct account takeover and card fraud should not be presented as confirmed consequences of this incident.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Verify unexpected job offers, contact-update requests, address-book synchronization prompts, and Covve-themed messages through a separate trusted channel before following links. Do not treat knowledge of your name, job title, phone number, or address as proof that a caller is legitimate. Review publicly visible phone, email, and location fields on social profiles and remove information that is no longer necessary. If you use Covve, review the current app's contact permissions and delete synchronized address books that are no longer needed. This incident alone is not a password leak requiring an automatic reset, but if you notice suspicious activity, change the relevant account password through its official service and enable multi-factor authentication. Report threats or misuse of a physical address to the appropriate local authority.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Contact-management apps can copy data about people who are not users, so permissions and retention periods should be reviewed regularly. Deleting obsolete contacts, limiting address-book synchronization, and removing old app connections reduce future exposure. Multi-factor authentication on email and social-media accounts remains useful because it limits harm after social engineering even when no password was exposed in this incident. Service operators should retire not only an application but also its data stores, backups, and cloud access paths. Blocking public database access, restricting networks, minimizing retained data, continuously inventorying exposed assets, and communicating incidents promptly provide durable protection.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search your email address in LeakData to see whether it matches the Covve\u002Fdb8151dd breach record. Only query an address that belongs to you or that you are authorized to review. A match means the address appears in the verified dataset; it does not prove that you were a Covve user, that a password was exposed, or that every listed data type appeared in your record. Even if you never used the app, you may match as a contact stored in another person's address book. If there is a match, be particularly cautious with personalized email and phone messages, then review the visibility of your social profiles and public contact details.\u003C\u002Fp>","","Covve Data Breach (22.8 Million Reported Records)","Covve Data Breach. 22.8 Million reported records were reported. Reported data: Email addresses, Job titles, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fcovve_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Covve","Contact management and personal CRM","Cyprus"]