[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fa1zgn6inygrh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825391","Straffic","Straffic Data Breach","straffic","straffic.io","2020-02-14T00:00:00.000Z","2020-02-27T19:28:29.000Z","2026-07-18T23:58:35.770Z","Verified breach record","https:\u002F\u002Fwww.bankinfosecurity.com\u002Fisraeli-marketing-company-exposes-contacts-database-a-13785",[15,17,18],"https:\u002F\u002Fwww.tripwire.com\u002Fstate-of-security\u002Fmore-than-140gb-of-data-exposed-by-israeli-marketing-company","https:\u002F\u002Fsecurityaffairs.com\u002F98733\u002Fdata-breach\u002Fstraffic-data-leak.html",48580249,"known",null,"unknown","Critical",[25,26,27,28,29],"Email addresses","Genders","Names","Phone numbers","Physical addresses","\u003Cp>The Straffic data breach is a large-scale personal data leak associated with the Israel-based marketing and performance network service. The incident came to light through a publicly accessible search database in February 2020. The verified record contains 48,580,249 unique email addresses; in addition to email addresses, the dataset also included names, phone numbers, physical addresses, and gender information. For this reason, the incident is significant not as a password-focused account takeover case but in terms of risks related to phishing, phone scams, fake marketing messages, and social engineering conducted using contact information and profile data.\u003C\u002Fp>\n\u003Cp>The Straffic incident is a typical data collection risk that shows that personal data can be held even in marketing networks where users have never directly opened an account. The fact that the dataset consists of communication records compiled for marketing purposes increases the likelihood that affected individuals do not know the company. This situation brings two separate issues for user security: the person may have difficulty understanding how their data was collected, and the same data can be repeatedly used in different campaigns, calls, messages, or fraud scenarios. This page explains the real risks of the Straffic breach and the steps to be taken by limiting verified fields.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data fields are email addresses, gender information, names, phone numbers, and physical addresses. Having a name along with an email address provides sufficient ground to generate messages that appear targeted and personalized. When a phone number is added, the risk is not limited to email alone; it extends to channels such as SMS, automated calls, fake customer representative interactions, and delivery notifications. A physical address can be used in fake invoices, fraudulent subscriptions, local service offers, or attempts to deceive based on location information.\u003C\u002Fp>\n\u003Cp>Gender information alone may not seem sensitive; however, when combined with name, email, phone, and address, it carries profile enrichment value. Attackers can combine such fields to create more persuasive messages about a person's residential area, communication habits, and possible interests. In this incident, confirmed data classes do not include password, payment card, bank account, or official identification number. This distinction is important; the risk narrative should not be presented as a scenario of a compromised password account, but should focus on the fraud and privacy risks arising from communication and address information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified accounts for the sTraffic violation is 48,580,249 unique email addresses. The incident date is recorded as February 14, 2020, and the verified addition date is February 27, 2020. The incident is associated with the accessibility of communication records found in a large volume search data repository. The reported data volume is at the 140 GB level, and the total number of rows may be higher than the number of unique emails; however, in user security searches, basic person matching should be handled based on the number of unique emails.\u003C\u002Fp>\n\u003Cp>Verified data fields are limited to email addresses, gender information, names, phone numbers, and physical addresses. Not every field is expected to be filled for each person; in marketing data sets, some individuals may only have an email, while others may also have phone or address information. Fields such as passwords, financial accounts, payment cards, health data, or government IDs are not within the verified scope for this breach. Therefore, users should be advised to check communication channels, address visibility, and social engineering risks rather than causing unnecessary financial panic.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Those at the highest risk are people who have been using the same email and phone number for many years. Because marketing data can match with different lists over time, an old contact record can be reused in current fraud messages. The risk is even higher for people whose email address belongs to a work account; a work email combined with name, phone, and physical address can be used for professionally appearing attacks such as fake supplier, fake offer, fake invoice, or meeting invitation.\u003C\u002Fp>\n\u003Cp>Individuals whose phone number and physical address are included in the dataset should also be careful against scenarios such as SMS fraud, fake shipment notifications, fake subscription alerts, and local service calls. It has been reported that communication records linked to Europe and America are included; therefore, users in different regions may face similar risks. Even users who have never heard of Straffic may be affected, as it could have been collected or transferred through the data marketing network. This means that notifications from unknown companies should not be automatically considered fake, but should be examined carefully.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If a Straffic match is seen, the first step is to develop a habit of stricter verification against suspicious messages received through email and phone channels. Messages coming under the name of a bank, cargo, subscription, public service, job offer, or local service should not have their links clicked directly. If the caller asks for personal information, a one-time code, card details, or remote access, the call should be terminated and verification should preferably be done through the institution's official communication channel. Messages that include your physical address may appear more convincing; therefore, knowing the address information alone should not be considered proof of security.\u003C\u002Fp>\n\u003Cp>This violation is not among the password-verified fields; however, people who use easily guessable parts such as address, place of birth, neighborhood, street name, or phone number in their passwords should update their passwords. Unknown forwarding rules, recovery addresses, and session history should be checked in the email account. If the phone number receives too many unwanted messages, operator blocking options, spam filters, and trusted call alerts can be activated. Public profiles containing address information and old listings should also be reduced.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The long-term goal is to make it more difficult for a single data leak to reach a person through different channels. Real phone numbers and primary email addresses should only be provided on registration forms when mandatory. Separate email aliases can be preferred for newsletters, campaigns, sweepstakes, and one-time services. Phone numbers should not be unnecessarily entered in unwanted fields, and physical addresses should only be shared when required for delivery or legal obligations. This approach reduces the chain risk arising from marketing lists.\u003C\u002Fp>\n\u003Cp>The appearance of employees' work emails from the corporate side on third-party marketing lists should be regularly monitored. Security teams should pay attention not only to password leaks but also to the exposure of personal data including phone numbers and addresses. Fake invoice and supplier frauds are often carried out with the correct person and contact information without requiring a password. Therefore, email security, phone verification procedures, employee awareness, and data minimization should be addressed together.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>You can check your email address on LeakData to see if there is a match with a Straffic violation. If there is a match, this means that your email address is included in this data set; it is not accurate to draw a definite conclusion for each of the phone, physical address, or other fields. Still, a match indicates that your contact information may have been found in a marketing-derived data set. Therefore, you should examine suspicious messages using your email, phone, and address more carefully.\u003C\u002Fp>\n\u003Cp>Straffic violations should not be expanded to password or payment card leaks; they are based on verified risk communication and profile data. The most appropriate actions for this incident are to check for fake requests using your email address, phone number, and physical address, reduce unnecessary data sharing, keep spam filters active, and close old exposed profiles. If your information appears in other breaches as well, the data fields of each incident should be evaluated separately; a single match does not mean that the passwords of all your accounts have been stolen.\u003C\u002Fp>","","Straffic Data Breach (48.6 Million Reported Records)","Straffic Data Breach. 48.6 Million reported records were reported. Reported data: Email addresses, Genders, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fstraffic_io.webp",false,{"name":7,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":21},"Marketing technology and lead generation","Israel"]