[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3v0xz16k5p5dw":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825338","QuestionPro","QuestionPro Data Breach","questionpro","questionpro.com","2022-05-21T00:00:00.000Z","2022-08-05T00:05:34.000Z","2022-08-05T23:24:27.000Z","2026-07-19T18:03:42.897Z","Verified third-party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-try-to-extort-survey-firm-questionpro-after-alleged-data-theft\u002F",[16,18,19,20,21],"https:\u002F\u002Fwww.questionpro.com\u002F","https:\u002F\u002Fwww.questionpro.com\u002Fsecurity\u002F","https:\u002F\u002Fwww.questionpro.com\u002Finfo\u002FcontactUs.html","https:\u002F\u002Fcdn.questionpro.com\u002Fuserimages\u002Fsite_media\u002Fquestionpro-logo-nw.svg",22229637,"known",null,"unknown","Critical",[28,29,30,31],"Browser user agent details","Email addresses","IP addresses","Survey results","\u003Cp>\u003Cstrong>The QuestionPro data breach\u003C\u002Fstrong> exposed survey and technical usage data associated with 22,229,637 unique email addresses in May 2022.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The validated data classes are email addresses, IP addresses, browser user-agent details and survey results. The impact of survey results depends on the survey: ordinary product feedback may carry limited risk, whereas answers that identify a respondent or reveal private preferences can support more targeted fraud. Passwords, payment cards and government identity documents are not validated classes in this record and should not be assumed to have been exposed. Combining an email address, IP address and browser detail can help an attacker prepare convincing research invitations, fake reward notices and personalised phishing messages.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The recorded date of 21 May 2022 is the download date claimed by the person who said they obtained the dataset; QuestionPro did not publicly confirm that exact date or the technical method of access. The incident emerged with a claim involving roughly 100 GB of data and more than 22 million unique email addresses. QuestionPro confirmed that it had received an extortion attempt and said it was investigating with law enforcement, but its initial statement did not confirm that a data breach had occurred. The dataset was therefore first labelled uncertain. Later, people who received notifications confirmed their own information and QuestionPro connection, supporting the record's move to verified status. The figure of 22,229,637 is the count of unique email addresses in the corpus; because some appeared to have been generated by the platform, it should not be read as an exact count of unique individuals. Dataset verification supports an association with the service, not a public corporate admission of a breach.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The dataset may include not only people with direct QuestionPro accounts but also respondents who completed a survey run by another organisation through the platform. This distinction matters: a matching address does not by itself prove that the person was a paying customer or platform administrator. Research participants, employees answering engagement surveys, customers completing experience questionnaires, recipients of market-research invitations and people submitting forms should be alert. Corporate email users may be targeted by fake employee surveys or messages impersonating their organisation. Public metadata does not classify the detailed content of every response, so health, financial or other sensitive answers should not be assumed to exist for every record.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>Verify the sender before opening links in unexpected survey, reward or research invitations.\u003C\u002Fstrong> If a message claims to come from an employer, customer or research organisation, confirm it through the organisation's official website or a known contact rather than details supplied in the message. Enable multi-factor authentication on email, and review active sessions and forwarding rules. Passwords are not a validated class in this incident, so the record alone is not proof that every password was exposed; however, change a password immediately if you entered it into a suspicious form or notice an unfamiliar session. Stop if a survey asks you to make a payment, provide a security code or install remote-access software. Corporate users should report fake employee surveys and unusual data-collection requests to their security team.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Organisations creating surveys should avoid collecting personal fields they do not need, use anonymous or pseudonymous response options where possible, and delete results after a defined retention period. Invitations should use verifiable sender domains, clear privacy notices and a method for participants to confirm the request through an independent channel. Multi-factor authentication and role-based access should be required for administrator accounts, while large exports and unusual download behaviour should be monitored. Participants should provide only information necessary for the survey and avoid placing passwords, identity numbers, payment data or information about other people in free-text fields. Organisations should train staff with targeted phishing examples that use real brands, survey topics and technical details. Data minimisation, access limits and shorter retention reduce the lasting impact of any future exposure.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>\u003Cstrong>Check your email address with LeakData\u003C\u002Fstrong> to see whether it matches the QuestionPro record or another known breach. A match does not mean your password or payment information appeared in this incident; it indicates that the address was present in a dataset associated with survey and technical usage data. Because some addresses may have been generated by the platform, do not interpret a result as an exact person count or proof of a direct QuestionPro account. If there is a match, review recent survey invitations, reward notices and research links, and verify the sender through an official channel before opening anything suspicious. If a corporate address is affected, notify the security team and check whether colleagues have received similar messages. Keep multi-factor authentication and careful link verification as continuous safeguards.\u003C\u002Fp>","","QuestionPro Data Breach (22.2 Million Reported Records)","QuestionPro Data Breach. 22.2 Million reported records were reported. Reported data: Browser user agent details, Email addresses, IP addresses. Review the…","\u002Fuploads\u002Flogo\u002Fquestionpro_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":24},"QuestionPro Inc.","Technology","United States"]