[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2odzn5k5b6zkp":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488251cd","factual","Factual Data Breach","factual.com","2017-03-22T00:00:00.000Z","2019-12-24T10:56:18.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:31.882Z","Business location data aggregator exposure","",[],2461696,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","Employers","Phone numbers","Physical addresses","\u003Cp>The Factual data record refers to the file of business and point-of-interest data associated with the data collector Factual on March 22, 2017, which was later shared as an alleged breach. The file contains approximately 8 million rows, while the verified search scope is 2,461,696 unique email accounts. The verified data types are email addresses, employer or business names, phone numbers, and physical addresses. In the assessment carried out with Factual, it was stated that the data consists of publicly available information on websites and provided to customers about businesses and points of interest. Therefore, the record should not be presented as a personal account password or financial data leak; the primary risk is the reuse of business contact data for spam, sales targeting, and social engineering.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types listed in this record are Email addresses, Employers, Phone numbers, and Physical addresses. When email, phone, and physical addresses are found together, a business, branch, employee, or point of interest can be targeted more easily. Business names and addresses can lay the groundwork for fake supplier, fake map entry, fake advertising service, fake invoice, or fake directory update messages. This record does not contain passwords, payment cards, bank accounts, or private customer profiles; however, the widespread circulation of business contact information increases the risk of B2B spam and targeted sales fraud. The risk is more pronounced for small business owners using personal email addresses because business communication and personal accounts may converge at the same address.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main metric is 2,461,696 unique email accounts. The total number of rows is approximately 8 million; this number is not the number of unique individuals and may include duplicate business\u002Flocation records. Data types are limited to email, employer or business name, phone, and physical address. Password, username, payment card, official ID, date of birth, private customer file, or consumer account history have not been verified in this record. Although it is stated that the data consists of publicly available business and point-of-interest information, its circulation in bulk poses a risk. This distinction is important: the record should not be considered completely harmless, but it also should not be described as if individual user accounts have been compromised. The impact is more on business communication, data broker visibility, and targeted messaging.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk consists of business owners, local business employees, branch contact addresses, sales and customer support teams, and publicly visible contact points in map and location data. Small business owners who use their personal email address for business registration are at higher risk. Records with phone and address fields can be used for fake directory updates, fake listings, fake ad packages, fake invoices, and fake vendor calls. If the business location and phone information are accurate, attackers appear more credible. Sales and support mailboxes in corporate teams may receive heavy spam. Business communication channels are affected more than consumer accounts; however, in single-person businesses, the distinction between business and personal identity is blurred, so privacy impact may also occur.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, first determine whether it is being used as a business, branch, support, or personal email address. Do not panic and assume a password breach since the password field has not been verified; however, if the same email appears with a password in other leaks, secure the account. Before making any payment for unexpected business directory updates, advertising packages, map verifications, invoices, supplier registrations, or subscription renewal messages, verify the request through an independent channel. Do not place extra trust in people who call and know your business name and address; this information may have been obtained from public or bulk data sets. Small businesses should evaluate incoming invoice and directory listing requests not based on a single person's approval, but with a second check.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Although business communication data is often publicly available, circulating it in bulk data sets reduces targeting costs. Businesses should keep publicly available email and phone addresses role-based and avoid using personal email addresses in business records as much as possible. It should be regularly checked what information is published in directories, maps, advertisements, and supplier records. Sales and support mailboxes should be protected with spam filters, invoice verification rules, and supplier approval processes. On the data provider side, bulk access to publicly available information, download limits, customer data usage conditions, and misuse monitoring controls are important. Regularly monitoring how the same business email appears in different data sets reduces the risk of targeted fraud.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>LeakData check shows whether your email address is included in this business and interest point dataset associated with Factual. A positive result does not mean your password, payment card, or personal account history has been exposed; it means that verified risk emails, business\u002Femployer names, phone numbers, and physical address information have been circulated in bulk. User actions include carefully checking incoming business verification and invoice messages, separating personal email from business records, strengthening filters against spam and sales targeting, and regularly monitoring whether the same email address appears in other leaks combined with passwords or financial data. This record should be considered particularly as a practical social engineering alert for small business and local service owners.\u003C\u002Fp>","Factual Data Breach (2.5 Million Reported Records)","Factual Data Breach. 2.5 Million reported records were reported. Reported data: Email addresses, Employers, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffactual_com.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Factual","Data Services","United States"]