[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsus2b6egcb8m":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825179","DemandScience","DemandScience by Pure Incubation Data Breach","demandscience-by-pure-incubation","demandscience.com","2024-02-28T00:00:00.000Z","2024-11-13T09:53:35.000Z","2024-11-13T10:00:34.000Z","2026-07-18T23:49:15.187Z","Verified breach record","https:\u002F\u002Fwww.troyhunt.com\u002Finside-the-demandscience-by-pure-incubation-data-breach\u002F",[16,18],"https:\u002F\u002Fsiliconangle.com\u002F2024\u002F11\u002F14\u002Fdata-breach-exposes-122m-records-demandscience-following-initial-denials\u002F",121796165,"known",null,"unknown","Critical",[25,26,27,28,29,30,31],"Email addresses","Employers","Job titles","Names","Phone numbers","Physical addresses","Social media profiles","\u003Cp>DemandScience by Pure Incubation is a data and marketing company operating in the field of B2B demand generation and business communication data. The dataset, which was put up for sale at the beginning of 2024 and later reported to have leaked from an old system, affected approximately 122 million unique corporate email addresses along with employers, titles, names, phone numbers, addresses, and social media profiles.\u003C\u002Fp>\u003Cp>The DemandScience registry should be evaluated mainly in the context of business communication data that is publicly available and collected from third parties. It does not contain password or payment data; however, a person may not know that their data is present in this company. Therefore, the risk is more about B2B profiling and corporate targeting rather than account takeover.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the DemandScience by Pure Incubation record should be considered as email addresses, employer information, job titles, first and last names, phone numbers, physical addresses, and social media profile links. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Employer information can be used for corporate phishing, fake supplier messages, and targeted sales pressure. Job titles can help understand authority level, department, and decision-making roles. First and last name information makes fake support, fake delivery, fake invoice, and customer service messages more convincing.Phone numbers allow the creation of personalized fraud scenarios through SMS, calls, and messaging applications. Physical addresses can be used in social engineering messages related to delivery, billing, subscriptions, and local services. Social media profile links can bridge a person's real identity, work, and online accounts.\u003C\u002Fp>\u003Cp>When the employer, job title, phone, address, and social media profile link are together, fake supplier, sales, recruitment, conference, invoice, or executive impersonation messages become more realistic. A corporate email address can move the attack surface from a personal account to the company.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The DemandScience record is associated with the domain demandscience.com, the history of Pure Incubation, and the B2B dataset that emerged at the beginning of 2024. The scope is limited to corporate email, employer, job title, full name, phone, physical address, and social media profile links. It should be assumed that there is no password, bank, or private account content.\u003C\u002Fp>\u003Cp>Fields that are not present in the DemandScience record should not be described as if they have leaked. Areas such as full payment card, official ID, private message, health data, bank information, or device content should only be included in the risk assessment if they are explicitly present within the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Employees whose corporate email addresses are listed, people in sales, marketing, finance, management, human resources, and procurement roles; users whose LinkedIn profiles match their work email, and teams open to external offer messages are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, repeat old passwords, do not separate work and personal accounts, or share phone and address information on multiple platforms are at higher risk. In data collection or B2B profile registrations, the risk should also be assessed based on the profile effect consolidated from different sources rather than a single account.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the positive match field should verify unexpected job offers, sales, invoices, meetings, supplier changes, and payment approval messages through internal validation processes. Since there is no password in the DemandScience record, the priority is social engineering and corporate phishing awareness.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. For records that do not contain passwords but include communication or profile data, caution should be exercised against unexpected calls, offers, returns, partnerships, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Companies should reduce the public visibility of employee communication data, use a second approval mechanism in finance and procurement transactions, and train employees against title-targeted phishing attempts. Individual users should maintain a separation between work and personal accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check shows whether the queried email address is found in the DemandScience record. A positive result does not necessarily mean that all data fields certainly belong to that user; however, it is sufficient warning for protective measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is present in the DemandScience\u002FPure Incubation-linked B2B dataset. This result does not mean that the password has been leaked; however, it should be taken into account in terms of corporate targeting and social engineering risk.\u003C\u002Fp>","","DemandScience by Pure Incubation Data Breach (121.8 Million Reported Records)","DemandScience by Pure Incubation Data Breach. 121.8 Million reported records were reported. Reported data: Email addresses, Employers, Job titles. Review the…","\u002Fuploads\u002Flogo\u002Fdemandscience_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":21},"DemandScience by Pure Incubation","B2B data \u002F Demand generation","United States"]