Identity Theft Got Easier After NetProspex Leaked 28 Million Records
HEROIC analysts uncovered the NetProspex database breach, which occured in September 2016 and exposed the personal and professional details of over 28 million individuals across the United States. The leaked records came from Dun and Bradstreet's NetProspex marketing platform, a service used by businesses to target corporate contacts. What makes this breach partcularly dangerous is that it wasn't a shadowy underground hack — a customer who licensed the data simply exposed it, putting millions of professional profiles into the open.
How Attackers Use Names, Emails, and Phone Numbers Against You
With full names, email addresses, and direct phone numbers in hand, attackers can craft highly convincing spear-phishing emails and phone scams. These aren't generic spam blasts — they're personalized messages that reference your real employer and job title, making them beleive to be legitimate. Business email compromise (BEC) fraud, where criminals impersonate executives or vendors to steal money, is fueled directly by this type of professional data.
What Was Exposed in the NetProspex Breach
- Email Address
- Phone Number
- First Name
- Last Name
Why Professional Data Is a Long-Term Threat
Unlike a password that can be changed, your name, email address, and phone number stay with you for years. Data from the NetProspex breach has been recieved and traded on dark web forums repeatedly since 2016. That means criminals today are still using this information to run credential stuffing attacks, social engineering campaigns, and identity fraud schemes — nearly a decade after the original exposure.
How a Database Breach Works
A database breach happens when a large collection of stored records becomes accessable to unauthorized parties. In the NetProspex case, this didn't involve a sophisticated hack — a licensed customer of the platform exposed the data through their own misconfiguration or carelessness. Once that database was out in the open, it was copied, shared, and eventually made its way into criminal marketplaces where it continues to circulate today.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records — including the NetProspex database — to tell you instantly whether your personal or professional information has been compromised. Don't wait for a phishing email to find out. Search your email address now at HEROIC.com and take the first step toward protecting yourself.
Breach Breakdown
28,871,138 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds