The untapt Inc. Breach Means Someone Has Your Professional Profile
HEROIC analysts identified the untapt Inc. database breach while monitoring dark web channels that trade legacy tech-sector data dumps. The breach occured in September 2016, exposing 7,022 records from untapt.com, a US-based platform that matched technology professionals with employers. What makes this breach partcularly relevant is the nature of the platform: job-matching services collect detailed professional profiles, and that kind of data is highly useful to attackers who want to craft convincing phishing messages or impersonate recruiters.
How Leaked Professional Profiles From untapt Inc. Enable Targeted Attacks
Unlike a simple email and password dump, professional profile data from a platform like untapt Inc. gives attackers rich context about real people. Attackers can use job titles, employer history, and contact details to construct spear phishing emails that look like they came from a recruiter, a hiring manager, or a colleague. These targeted messages are far more convincing than generic spam and are accessable to even low-skill attackers who simply purchase the data in bulk. Business email compromise and social engineering campaigns are both realistic threats for anyone whose data was recieved into this breach. The information can also be merged with credentials from other leaks to build a more complete profile of potential victims.
What Was Exposed in the untapt Inc. Breach
- Email addresses
- Usernames
- Professional profile data (job titles, skills, employment history)
- Contact information
Why Professional Data Is More Dangerous Than You Think
Many people seperate their concern about data breaches to situations involving passwords or financial information. But professional profile data carries its own serious risks. A threat actor who knows your job title, current employer, and work email can send you a message that appears entirely legitimate. Credential stuffing, identity theft, and targeted fraud all become easier when an attacker knows not just who you are, but where you work and what you do. The untapt breach represents exactly the kind of quiet, long-tail threat that organizations and individuals often overlook until it is too late.
How a Database Breach Works
A database breach happens when an attacker finds a weakness in a company's website or server and uses it to copy records directly from the backend database. Technology and employment platforms like untapt Inc. store large amounts of structured user data, making their databases attractive targets. Once the attacker has the data, they compress it and distribute or sell it through underground channels. Breaches from 2016 were often not discovered immediately, giving attackers a long window to use or sell the stolen information before the company or affected users were even aware something had happened.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records to tell you whether your email address appears in known breach databases, including the untapt Inc. leak. Visit HEROIC.com to run a free check and find out exactly what information about you may already be in the hands of attackers, along with clear steps you can take to reduce your risk right now.
Breach Breakdown
7,022 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds