Security researchers found an unprotected server that exposed 1.2 billion records of personal data, including email addresses, employers, locations, job titles, names, phone numbers and social media profiles, according to a notification sent Friday to people affected by the exposure.
“In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server,” according to the email. “The exposed data included an index indicating it was sourced from data enrichment company People Data Labs and contained 622 million unique email addresses.”
The data had been aggregated by PDL, but the email added that PDL didn’t own the server. Rather, a customer likely “failed to properly secure the database.”
The exposure was dated Oct. 16.
PDL didn’t immediately respond to a request for comment. The company’s LinkedIn profile says it has a “dataset of 1.5 billion unique person profiles to build products, enrich person profiles, power predictive modeling/AI, analysis, and more.”
PDL is based in San Francisco and mentions working with companies including eBay and Adidas “as their engineering focused people data partner.”