Breach Intelligence Report 06 Jan 2025

The Closelly Breach Gave Hackers Corporate Emails for Targeted Phishing

HEROIC
HEROIC Threat Intelligence Team
Email Address First Name Last
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,930
Source Type Database
Origin Darkweb
Password Type No Passwords

HEROIC analysts identified a database breach affecting Closelly, an AI-powered gamification platform used by companies for employee training and onboarding. The breach is dated November 2024, though it was first observed surfacing on a dark web forum on January 6, 2025. The exposed dataset contains 2,930 records consisting of email addresses, first names, and last names. Because Closelly serves a business-to-business market, many of the affected email addresses are likely work accounts tied to corporate environments, making this breach particularly relevant for organizations whose employees used the platform.


Why the Closelly Breach Is a Risk to Corporate Employees

Email addresses and full names from a corporate training platform are exactly what an attacker needs to launch convincing spear-phishing campaigns. Unlike generic mass-phishing attempts, spear-phishing uses the victim's real name and is often crafted to appear as a legitimate message from their employer, a vendor, or a known service. An attacker who knows you used a platform like Closelly can impersonate that platform, send fake login prompts or renewal notices, and capture your credentials or install malware on your device. The more targeted the phishing email, the more likely a victim is to fall for it.


What Was Exposed in the Closelly Breach

  • Email addresses (2,930 unique records, with the threat actor claiming up to 34,000 total)
  • First names and last names, enabling personalized attack targeting

Why This Matters for Business Security

When corporate employee data is exposed through a third-party SaaS tool, it creates a security gap that the employer may not immediately know about. Attackers can use the names and emails from this breach to attempt credential stuffing against corporate email systems, to impersonate IT helpdesks in phishing attempts, or to build detailed profiles of employees at target organizations. The gap between when this breach occurred in November 2024 and when it appeared publicly in January 2025 also demonstrates how long compromised data can circulate privately before becoming widely accessible.


How Database Breaches Affect AI and SaaS Platforms

AI-driven tools and SaaS platforms often collect and store user profile data to personalize the experience, track progress, and generate reporting for corporate clients. This data is stored in databases that, if improperly secured, can be accessed by unauthorized parties through exposed APIs, misconfigured access controls, or compromised administrator credentials. Once an attacker extracts a user table from such a database, the data is typically compiled and sold or posted on dark web forums. The relatively small publicly available sample in this case (2,930 records compared to a claimed 34,000) suggests either a partial release or the full dataset being sold privately.


Check If You Are Affected by the Closelly Breach

HEROIC's free breach scanner covers more than 400 billion records, including database breaches from online tools and SaaS platforms. If you or your employees have used Closelly, enter your email address to check whether your information appears in this breach or any other known dataset. Organizations should also audit which third-party tools have access to employee data and verify that those platforms follow current security standards. Run a free check at HEROIC.com.

Breach Breakdown

Domain N/A
Leaked Data Email Address, First Name, Last Name
Password Types No Passwords
Date Leaked 06 Jan 2025
Check in 5 seconds

2,930 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,227 scanned today
Breach Rank #21,685 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $21.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance