Inside the Em360send Database Breach: How 2.6 Million Email Records Leaked
HEROIC analysts identified the Em360send dataset as part of a broader sweep of email provider breaches that have occured across the 2016 threat landscape. The email marketing platform exposed 2,643,259 user records in a database breach that September, and the data has continued to surface in threat actor collections years after the initial incident. While no passwords were included in this particular dump, email provider breaches carry their own distinct category of risk that is often underestimated by the people affected.
How Email Provider Data Fuels Phishing and Account Takeover
When an email provider database is breached, attackers gain a verified, deliverable list of real email addresses tied to real people. That list becomes the foundation for targeted phishing campaigns, spam floods, and credential stuffing attacks on other platforms where those same addresses were used to register accounts. The Em360send records are partcularly useful to attackers because email marketing platform users tend to be business owners and marketing professionals, making them high-value targets for business email compromise.
What Was Exposed in the Em360send Breach
- Email addresses for 2,643,259 accounts
- User account records and associated metadata
- Email provider platform data from the em360send.com database
Why 2.6 Million Email Records Are Still a Live Threat
Many people beleive that a breach with no passwords attached is harmless, but that assumption is wrong. Verified email lists from a known email provider are sold and traded as premium assets in underground markets. Attackers use them to launch personalized phishing attacks, enroll addresses in SMS scams, and cross-reference them against other breach datasets to build complete identity profiles. The risk of financial fraud and identity theft from exposed email records is seperate from, and additive to, any password-related risk.
How a Database Breach Works
A database breach happens when an attacker finds a way into the server or storage system where a company keeps its user records. This could be through a software flaw, a misconfigured database left open to the internet, or compromised administrator login credentials. Once access is gained, the attacker downloads a copy of the user table and walks away with every account record the company has ever collected. The original platform often has no idea the theft happened until the data appears for sale online.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion exposed records, including the Em360send dataset, and returns results instantly. If your address appears in this or any other breach, you will know exactly which incident exposed it and what steps to take next.
Breach Breakdown
2,643,259 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds