In 2019, B2B marketing leads company LimeLeads exposed an unsecured Elasticsearch server containing 17.8 million unique email addresses along with phone numbers, employers, job titles and locations. The breach affects professionals whose contact data was collected for sales outreach. Since LimeLeads is now defunct, affected individuals should check breach-tracking tools for their email and stay alert for phishing attempts referencing their job or employer.
| Company | LimeLeads |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Email Addresses, Phone Numbers, Employers, Job Titles, Geographic Locations |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unsecured Database Exposure |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the LimeLeads Data Breach?
LimeLeads ran a business-to-business marketing leads database that let customers search for corporate contact details. In 2019, the company left an Elasticsearch server exposed without basic security controls. As a result, anyone who found the server could view its contents without needing a password or any special access.
This type of exposure is different from a typical hacking incident. Instead of breaking through a firewall or stealing credentials, whoever accessed the data simply found an open door. Because the server was unsecured, the LimeLeads data breach did not require sophisticated techniques to pull large volumes of records.
The breach became known as researchers tracking exposed databases found the server and identified LimeLeads as the source. It has not been publicly disclosed exactly when LimeLeads first learned of the issue or when the server was secured. Similarly, the exact window during which the data remained accessible has not been publicly disclosed.
LimeLeads is reported to be defunct today, which limits what is publicly known about any internal investigation. However, the scope of the exposed dataset itself has been documented, giving a clear picture of what was at risk even without a formal breach report from the company.
Who was affected?
The LimeLeads data breach primarily affected people whose professional contact information was collected for B2B marketing and sales purposes. This means the exposed records are tied mostly to working professionals rather than private consumers in a typical retail sense.
In terms of scale, the exposed database contained 17.8 million unique email addresses. This points to a very large population of impacted individuals, spanning numerous companies, industries and locations.
Because LimeLeads marketed its database to sales and marketing teams, affected individuals likely span many states and countries. The geographic location data included in the breach, such as state, city and postcode, further suggests a broad and varied population of impacted professionals.
An exact number of affected individuals beyond the 17.8 million unique email addresses has not been publicly disclosed. It is also unclear whether any additional personal accounts beyond business contacts were included in the exposed records.
What Information Was Potentially Exposed?
The exposed Elasticsearch server contained a substantial amount of professional contact data. Unlike breaches involving Social Security numbers or medical records, this incident centered on information commonly used for sales outreach and networking.
- Email addresses
- Phone numbers
- Employers
- Job titles
- Geographic locations (state, city and postcode)
Although this data may seem less sensitive than financial or health records, it still carries real risk. For example, scammers often use accurate employer and job title information to craft convincing phishing emails. This is sometimes called business email compromise, and it depends heavily on exactly the kind of data exposed here.
In addition, combining email addresses with phone numbers and employer details makes it easier for criminals to impersonate colleagues, vendors or executives. As a result, affected individuals may face a higher risk of targeted phishing, vishing (voice phishing) calls, or fraudulent invoice schemes aimed at their workplace.
What is the company doing?
Because LimeLeads is reported to be defunct, there is no indication that the company issued a formal public statement regarding this incident. The available information about the breach comes from researchers who identified the exposed server rather than from a company-issued notification.
Therefore, it cannot be confirmed that LimeLeads conducted an investigation, notified affected individuals directly, or offered any remediation steps such as credit monitoring. Readers should treat any claims about LimeLeads taking corrective action with caution unless new information becomes available.
Given the company’s apparent closure, affected individuals may not receive any direct notification at all. This makes personal vigilance especially important for anyone who believes their professional contact information may have been included in this dataset.
What Should Affected Individuals Do?
Check Whether Your Information Was Exposed
Start by checking whether your email address appears in known breach-tracking databases. Several free tools let you search by email address to see if your data was part of the LimeLeads data breach or similar incidents.
If your work email turns up in the results, it’s worth alerting your employer’s IT or security team. This way, your organization can watch for suspicious activity tied to your professional contact details.
Watch for Phishing and Business Email Scams
Because job titles, employers and phone numbers were exposed, affected individuals should be especially alert to phishing attempts. Scammers often use this kind of detail to make fraudulent emails or calls appear legitimate.
Be cautious of unexpected messages referencing your job title, company, or direct phone line. If a message pressures you to act quickly or share sensitive information, verify the sender through a separate, trusted channel before responding.
Monitor Your Accounts and Credit Reports
Although this breach did not expose Social Security numbers, it’s still wise to monitor your financial accounts and credit reports. Criminals sometimes combine exposed contact data with information from other breaches to attempt identity theft.
You can request free credit reports from the major credit bureaus and review them regularly. If you notice unfamiliar accounts or inquiries, report them immediately to protect your credit standing.
Limit Future Data Exposure
Consider reviewing which companies and services hold your professional contact information. Where possible, opt out of marketing databases or request removal from lead-generation platforms you no longer use.
In addition, use unique passwords and enable multi-factor authentication on your work and personal accounts. This reduces the chance that leaked contact details can be used to compromise other accounts you own.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
