[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fntjvsk07p93u":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":10,"seoTitleEn":29,"seoDescription":10,"seoDescriptionEn":30,"logoUrl":31,"isVerified":32,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda488252e4","NotAcxiom","Not Acxiom Alleged Data Exposure","not-acxiom","","2020-06-21T00:00:00.000Z","2022-11-22T19:17:40.000Z","2026-07-18T23:55:13.049Z","Unverified breach record","https:\u002F\u002Fwww.troyhunt.com\u002Fdata-breach-misattribution-acxiom-live-ramp\u002F",[15],51730831,"known",null,"email_identifiers","Critical",[23,24,25,26,27],"Email addresses","IP addresses","Names","Phone numbers","Physical addresses","\u003Cp>Not Acxiom data breach concerns a large-scale personal data set that circulated in 2020 and was initially misattributed to a major marketing data company. The verified scope includes 51,730,831 accounts. Data classes include email addresses, IP addresses, names, phone numbers, and physical addresses. The incident is not considered a confirmed corporate breach; since the true source of the data set cannot be determined with certainty, the event should be considered a misattributed and unverified marketing data leakage.\u003C\u002Fp>\u003Cp>This distinction is important to provide the user with accurate risk information. Although the data appears to be associated with real individuals, it has not been proven to have been obtained from the systems of a specific company. Therefore, the incident is not presented as a direct violation of any brand. Nevertheless, when fields such as name, email, phone, IP, and physical address are found together, they can pose serious user risks in terms of targeted fraud, identity association, and exploitation of communication channels.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>Verified data categories are email addresses, IP addresses, names, phone numbers, and physical addresses. An email address can be associated with online accounts, a phone number with direct contact, a physical address with identity association, and an IP address with geographic or network context. The presence of these fields together makes it easier for attackers to prepare personalized messages and calls.\u003C\u002Fp>\u003Cp>Password, payment card, bank account, official ID number, health data, or private message content are not among the verified data fields. Therefore, the incident should not be directly interpreted as a requirement to change the account password. The risk is more concentrated on marketing profiles, identity matching, fake customer support communications, delivery pretexts, and phone scam attempts.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope is limited to the dataset dated June 21, 2020, and 51,730,831 affected accounts. The record addition and last modification time is verified as November 22, 2022. The domain field is left empty because the incident is not linked to a specific website account or a verified company system. The verified flag is off, and the public source field is also used to reflect this status.\u003C\u002Fp>\u003Cp>Due to the risk of incorrect attribution, the statement does not repeat unconfirmed claims of company ownership. The term is used to illustrate the distinction that the dataset does not belong to a company. The important point for the user is that even if the data source is uncertain, the listed personal fields can be used for fraud and identity association purposes.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The first group at risk consists of individuals whose email address, phone number, and physical address are visible. These users can be targeted with fake delivery, subscription, customer support, bank alert, or promotional messages. Name and address information adds credibility to messages; phone information can be used directly for call and SMS fraud.\u003C\u002Fp>\u003Cp>The second group consists of people who have used the same email address for many years across different services. When this dataset is matched with other leaks, even if the password is not found, an attacker can better estimate the person's identity, communication channels, and possible location information. When combined with IP address history, address, and phone information, the risk of profiling increases.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who see a match should first pay attention to unexpected messages received via email and phone. Messages that appear to be delivery, account verification, subscription renewal, payment alert, or support request should be confirmed through a second channel. Unknown callers should not be given address, card information, one-time code, or account recovery information.\u003C\u002Fp>\u003Cp>Even if the password is not verified in this incident, the email account is a fundamental security point. Users should use a strong and unique password for their email account, enable multi-factor authentication, and check forwarding rules and recovery options. Extra caution should be taken against fake shipping and public service notifications due to address and phone information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The long-term goal is to reduce the unnecessary scattering of permanent personal fields across different services. Fields such as phone number, physical address, and birth information should only be shared on platforms where they are truly necessary. Users should close old accounts, reduce publicly visible profile fields, and consider using different email addresses for different purposes.\u003C\u002Fp>\u003Cp>The fundamental lesson for organizations is that when the source of datasets becomes unclear, the risk of misattribution can undermine user trust. Data inventories, retention periods, third-party sharing, and access control should be kept regularly. On the user side, verifying suspicious communications, strengthening the email account, and reducing the sharing of personal data are the most effective defenses.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If a user sees a match, they should first evaluate which fields are listed. The email address can be used for phishing messages, the phone number for fake calls, the physical address for identity linking, and the IP address for additional profile extraction. When these fields are connected to the same person, fraud messages become more personal.\u003C\u002Fp>\u003Cp>The Not Acxiom incident should not be ignored from the user's perspective, even though it involves an unverified and misattributed source. Even if the data source is unclear, the combination of name, email, phone, and address creates practical risk. When the user strengthens email security, verifies suspicious messages through a secondary channel, and reduces unnecessary personal data visibility, the long-term risk arising from this incident decreases significantly.\u003C\u002Fp>","Not Acxiom Alleged Data Exposure (51.7 Million Email Identifiers)","Not Acxiom Alleged Data Exposure. 51.7 Million email identifiers were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fnot_acxiom.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":19},"Not Acxiom","Misattributed marketing data","Global"]