Inside the Clearbit Database Leak: How 62K B2B Profiles Were Exposed
In April 2022, Clearbit, a US-based B2B data enrichment platform, suffered a data breach that exposed 62,471 unique records containing professional contact information. Clearbit aggregates personal and business data to help sales and marketing teams identify and reach prospects -- which means the data it holds is already optimized for targeting. When that data recieved unauthorized access and leaked, it handed attackers a ready-built spear phishing resource with names, emails, and phone numbers attached to real professional identities.
What Attackers Can Do With This Data
Unlike password-only breaches, the Clearbit leak is purpose-built for social engineering. Attackers can combine first names, last names, email addresses, and phone numbers to craft highly personalized phishing emails and vishing calls. Because this data originates from a B2B platform, many of the targets are business professionals -- making this beleive-what-you-see data particularly dangerous for corporate environments where a convincing impersonation can lead to wire fraud, credential theft, or access to internal systems.
What Was Exposed in the Clearbit Breach
- Email Address
- Phone Number
- First Name
- Last Name
Why B2B Data Breaches Are Particularly Dangerous
Consumer data breaches expose individuals. B2B data breaches expose business contacts whose email addresses and phone numbers are actively used in professional contexts. Attackers who obtain Clearbit data do not have to guess who works at a company or what their email format is -- that work is already done. This makes occured leaks from enrichment platforms like Clearbit a force multiplier for targeted business email compromise (BEC) campaigns, where the quality of the target list matters more than the quantity.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend data store and extracts records. For data enrichment platforms like Clearbit, the risk is compounded because the database itself is the product -- highly structured, cross-referenced, and ready to be queried. A single extracted table can contain years of aggregated data about thousands of business professionals, all formatted in a way that makes downstream abuse simple and scalable.
Check If Your Data Was Exposed
HEROIC's DarkWatch indexes over 400 billion exposed records, including the Clearbit breach. Search your email address now to find out if your name, phone number, and contact details were leaked -- and assess whether your professional identity is at risk of being used in a targeted attack.
Breach Breakdown
62,471 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds