The Closelly Breach Gave Hackers Corporate Emails for Targeted Phishing
HEROIC analysts identified a database breach affecting Closelly, an AI-powered gamification platform used by companies for employee training and onboarding. The breach is dated November 2024, though it was first observed surfacing on a dark web forum on January 6, 2025. The exposed dataset contains 2,930 records consisting of email addresses, first names, and last names. Because Closelly serves a business-to-business market, many of the affected email addresses are likely work accounts tied to corporate environments, making this breach particularly relevant for organizations whose employees used the platform.
Why the Closelly Breach Is a Risk to Corporate Employees
Email addresses and full names from a corporate training platform are exactly what an attacker needs to launch convincing spear-phishing campaigns. Unlike generic mass-phishing attempts, spear-phishing uses the victim's real name and is often crafted to appear as a legitimate message from their employer, a vendor, or a known service. An attacker who knows you used a platform like Closelly can impersonate that platform, send fake login prompts or renewal notices, and capture your credentials or install malware on your device. The more targeted the phishing email, the more likely a victim is to fall for it.
What Was Exposed in the Closelly Breach
- Email addresses (2,930 unique records, with the threat actor claiming up to 34,000 total)
- First names and last names, enabling personalized attack targeting
Why This Matters for Business Security
When corporate employee data is exposed through a third-party SaaS tool, it creates a security gap that the employer may not immediately know about. Attackers can use the names and emails from this breach to attempt credential stuffing against corporate email systems, to impersonate IT helpdesks in phishing attempts, or to build detailed profiles of employees at target organizations. The gap between when this breach occurred in November 2024 and when it appeared publicly in January 2025 also demonstrates how long compromised data can circulate privately before becoming widely accessible.
How Database Breaches Affect AI and SaaS Platforms
AI-driven tools and SaaS platforms often collect and store user profile data to personalize the experience, track progress, and generate reporting for corporate clients. This data is stored in databases that, if improperly secured, can be accessed by unauthorized parties through exposed APIs, misconfigured access controls, or compromised administrator credentials. Once an attacker extracts a user table from such a database, the data is typically compiled and sold or posted on dark web forums. The relatively small publicly available sample in this case (2,930 records compared to a claimed 34,000) suggests either a partial release or the full dataset being sold privately.
Check If You Are Affected by the Closelly Breach
HEROIC's free breach scanner covers more than 400 billion records, including database breaches from online tools and SaaS platforms. If you or your employees have used Closelly, enter your email address to check whether your information appears in this breach or any other known dataset. Organizations should also audit which third-party tools have access to employee data and verify that those platforms follow current security standards. Run a free check at HEROIC.com.
Breach Breakdown
2,930 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds