Verifications.io — 763 Million Email Records Left on an Open Database (2019)
If you have an account with Verifications.io, here’s what’s now in circulation.
An email-validation firm most people had never heard of left 763 million records in a MongoDB instance with no password on it. Nobody in the data signed up for Verifications.io — the company held their details because other businesses paid it to check them.
What happened
In February 2019, researchers Bob Diachenko and Vinny Troia found a MongoDB instance belonging to the email validation service Verifications.io sitting on the public internet with no password protecting it. It held 763,117,241 unique email addresses — the largest single entry in the Have I Been Pwned catalogue. The company's website went offline during the disclosure process.
There was no hack, no ransomware group and no extortion note. The database was simply reachable by anyone who went looking, which is how both researchers found it. That distinction matters for what you should do about it, and we come back to it below.
What an email-validation firm was doing with your address
This is the part that surprises people, and it is the reason this page exists rather than a one-line entry in a list. You were almost certainly never a Verifications.io customer. Email validation is a business-to-business service: a company with a marketing list pays a firm like this one to check which addresses on it are real and deliverable before sending to them. Your address was in the database because somebody else uploaded it.
Many records carried far more than an address. The catalogue lists names, phone numbers, physical addresses, dates of birth, genders, employers, job titles, geographic locations and IP addresses. That is a marketing profile, assembled without your involvement, from sources you cannot enumerate.
No passwords were in the data. There is nothing here to rotate, and any advice telling you to change your Verifications.io password is advice about an account you never had.
Why a 2019 leak still matters
Credentials decay — a password you changed in 2020 is worthless to an attacker today. The fields in this dataset do not decay in the same way. Your date of birth is permanent. Your name is close to it. Phone numbers and physical addresses turn over on a scale of years, not days, and employers and job titles stay useful long enough to make a convincing pretext.
A dataset like this one is most valuable not on its own but as glue. It carries the email address that appears in credential dumps and the real-world identifiers that appear in people-search listings, so it is the record that joins the two together.
The identity-chain implication
This is the clearest example in the whole catalogue of the pattern GalaxyWarden exists to map. An attacker who starts from a leaked gaming handle and finds the matching email address gets, from this dataset alone, a probable real name, employer, rough location and date of birth. Each of those is a query into the next source — a broker listing, a voter file, a social profile.
The chain does not need any single catastrophic leak. It needs several mediocre ones that overlap on a shared key, and the shared key is nearly always an email address.
What to do now
Because there is no account and no password here, the useful actions are all about the downstream copies rather than this database, which has been offline for years.
What You Should Do
- Check which of your addresses appear — a free scan queries HIBP directly, and this breach is in it
- Treat your date of birth and phone number as public when a service offers them as security questions or account-recovery factors
- Assume any "we noticed your details on file" cold outreach citing your employer or job title is a pretext, not a coincidence
- Remove the downstream people-search listings this data feeds — those are live and legally removable, unlike the leak itself
- Move newsletter and shopping signups to a forwarding alias so future validation uploads cannot join them to your main identity
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)
Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import wea…
Exactis — 340 Million Records of Profiling Data Nobody Consented To (2018)
A marketing data broker left an ElasticSearch node exposed with no firewall. It held about 340 milli…
Deezer — 229 Million Records a Partner Was Supposed to Have Deleted (2019, disclosed 2022)
The music service was not breached. A third-party partner kept a mid-2019 backup after its contract …