[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2jvwhjp70jkm3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":10,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":10,"seoTitleEn":8,"seoDescription":10,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488251a3","elasticsearch-sales-leads","Elasticsearch Instance of Sales Leads on AWS Data Breach","elasticsearch-instance-of-sales-leads-on-aws","","2018-10-29T00:00:00.000Z","2018-11-17T09:04:54.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:06.325Z","Third party breach",[],5788169,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","Employers","Names","Physical addresses","\u003Cp>An Elasticsearch Instance of Sales Leads on AWS is a record associated with the exposure of a sales potential data repository whose exact owner cannot be clearly determined, rather than a specific company account breach. One of the data sets discovered by security researcher Bob Diachenko in October 2018 contained approximately 5.8 million unique email addresses and business contact fields.\u003C\u002Fp>\u003Cp>It should not be written as a single company violation due to the inability to definitively identify the owner of this record. The data should be considered as sales lead information linked to the companies that individuals work for. Since it does not contain a password or account secret, the risk is more related to B2B targeting and social engineering.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the Elasticsearch Instance of Sales Leads on AWS record should be considered as email addresses, employer information, full name information, and physical addresses. Email addresses can be used for targeted phishing, password reset scenarios, and account matching across different services. Employer information can be used for corporate phishing, fake supplier messages, and targeted sales pressure. Full name information makes fake support, fake delivery, fake invoice, and customer service messages more convincing. Physical addresses can be used in delivery, invoice, subscription, and local service-themed social engineering messages.\u003C\u002Fp>\u003Cp>When the employer's name and email information are present together, fake sales, offers, meetings, partnership, or supplier messages become more convincing. A physical address strengthens the company or individual context, increasing the risk of targeted communication.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with an open Elasticsearch sales lead dataset and should not be presented as a user database for a specific domain. The scope is limited to email addresses, employer information, full name, and physical addresses. Password, payment, or private account content has not been verified for this record.\u003C\u002Fp>\u003Cp>Areas not present in this record should not be described as if they have leaked. Full payment cards, official identification, private messages, health data, bank information, device content, or data belonging to other platforms should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Employees with corporate email addresses on the list, sales and purchasing teams, individuals associated with the company address, and roles open to external offer messages are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, reuse their old passwords, keep their nicknames the same across many communities, or do not separate their work and personal accounts are at higher risk. The risk in profile and data broker records arises from the combination of very different domains from a single account, creating detailed context about the person.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the positive match field should check unexpected offer, meeting, supplier change, and payment request messages through internal verification processes. Since there is no password in this record, the priority is corporate phishing risk.\u003C\u002Fp>\u003Cp>Users in the positive match area should renew their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. Records that do not contain passwords but include contact, billing, address, or profile data should be monitored for unexpected calls, offers, support, billing, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Companies should regularly review how employee communication data appears in public and third-party datasets. Corporate email users should perform additional verification for proposal messages containing external links and files.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address appears in the Elasticsearch Sales Leads dataset. This result does not mean that the personal account has been compromised; however, it does indicate a risk of corporate targeting.\u003C\u002Fp>","Elasticsearch Instance of Sales Leads on AWS Data Breach. 5.8 Million reported records were reported. Reported data: Email addresses, Employers, Names. Review…","\u002Fuploads\u002Flogo\u002Felasticsearch_sales_leads.webp",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":19},"Elasticsearch Instance of Sales Leads on AWS","Sales Leads \u002F B2B Data","Unknown"]