[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f31stjvaapf55y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":10,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":39,"seoTitle":10,"seoTitleEn":40,"seoDescription":10,"seoDescriptionEn":41,"logoUrl":42,"isVerified":43,"isSensitive":4,"isSpamList":43,"isMalware":43,"company":44},"68e3266eda11adda48825176","data-enrichment","Data Enrichment Records","data-enrichment-records","","2016-12-23T00:00:00.000Z","2017-06-08T16:23:07.000Z","2026-07-02T12:29:03.590Z","2026-07-18T23:49:13.825Z","Third party breach",[],8176132,"known",null,"email_identifiers","Critical",[23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38],"Buying preferences","Charitable donations","Credit status information","Dates of birth","Email addresses","Family structure","Financial investments","Home ownership statuses","Income levels","Job titles","Marital statuses","Names","Net worths","Phone numbers","Physical addresses","Political donations","\u003Cp>Data Enrichment Records are extensive personal profile records reported to be sold as data enrichment profiles, not a single user account breach. In December 2016, it was reported that more than 200 million profiles were put up for sale, with over 8 million unique email addresses in the records and numerous economic, family, and political profile fields.\u003C\u002Fp>\u003Cp>The seller claimed that the data came from a specific major credit bureau, but the relevant company denied this claim. Therefore, the record should be kept unverified and a definitive source should not be attributed to any particular company. Nevertheless, the structure of the data fields indicates that the record carries high sensitivity in terms of identity and profile security.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>In the Data Enrichment Records entry, tracked data categories should be treated as purchase preferences, charitable donation information, credit status information, dates of birth, email addresses, family structure information, financial investment information, homeownership status, income level information, job titles, marital status information, name and surname information, net wealth estimates, phone numbers, physical addresses, and political donation information. Purchase preferences can help create targeted advertising or fraud messages based on a user's interests and consumption behaviors. Charitable donation information can provide sensitive context regarding the institutions and values a person is interested in.Credit status information can lead to inferences about financial reliability and borrowing capacity. Dates of birth are permanent personal data that can be used in identity verification questions, age-based targeting, and profile enrichment. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Family structure information increases social engineering risk through household profile, parenting, or family relationships. Financial investment information can be used for fake investment offers, consultancy, or account verification messages. Homeownership status carries targeting value in mortgage, insurance, real estate, or credit-related frauds.Income level information can increase the risk of targeted fraud by making inferences about a person's financial capacity. Job titles can help understand authority level, department, and decision-making role. Marital status information can be used in targeted messages based on family and personal life. Name-surname information makes fake support, fake delivery, fake invoice, and customer service messages more convincing. Net wealth estimates can be used to distinguish high-value targets and personalize financial fraud. Phone numbers allow for personalized fraud scenarios through SMS, calls, and messaging apps. Physical addresses can be used in delivery, billing, subscription, and local service-themed social engineering messages.Political donation information can lead to sensitive inferences about a person's political tendencies.\u003C\u002Fp>\u003Cp>Areas such as credit status, income level, net worth, home ownership, family structure, donations, and political donations can lead to very strong inferences about a person's financial and social profile. Even if it does not contain a password, this type of profile data is highly valuable for targeted fraud and manipulation.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is a profile data collection referred to as Data Enrichment Records. Its scope is limited to purchase preferences, donations, credit status, date of birth, email, family structure, investments, homeownership, income, job title, marital status, name, net worth, phone, physical address, and political donation fields. Specific source companies should not be described as confirmed.\u003C\u002Fp>\u003Cp>Areas not included in this record should not be described as if they have leaked. Fields such as full payment card, official ID, private message, health data, bank information, or device content should only be added to the risk assessment when they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Individuals who may be listed in data broker records, users whose address and phone information has not changed for a long time, individuals vulnerable to fraud targeting financial profile data, and people who can be targeted based on political or donation information are at high risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, repeat their old passwords, do not separate work and personal accounts, or share their phone and address information on multiple platforms are at higher risk. In data collection or B2B profile registrations, the risk should also be assessed through the profile effect combined from different sources rather than just a single account.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Since there is no password in this record, the first action is not a password change. Users should carefully verify searches and emails themed around credit, donations, investments, real estate, insurance, and political campaigns; requests for identity, income, or bank information should be checked through official channels.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. For records that do not contain passwords but include communication or profile data, caution should be exercised against unexpected calls, offers, returns, partnerships, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Since profile data cannot be easily changed, the risk is long-term. Users should regularly review data broker opt-out processes, the visibility of public address and phone numbers, credit report checks, and social media profile details.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address appears in Data Enrichment Records. This result does not mean that a specific company account has been compromised; however, it requires high attention due to economic, family, and political profile areas.\u003C\u002Fp>","Data Enrichment Records (8.2 Million Email Identifiers)","Data Enrichment Records. 8.2 Million email identifiers were reported. Reported data: Buying preferences, Charitable donations, Credit status information…","\u002Fuploads\u002Flogo\u002Fdata_enrichment.webp",false,{"name":8,"sector":45,"country":46,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":19},"Data Broker \u002F Data Enrichment","Global"]