Picture the office manager at a thirty-person heating and cooling company in Ohio. She has one work email address, and she uses it for invoices, supplier orders and the payroll portal. She has never heard of LimeLeads. Last week a message arrived that greeted her by job title, named her employer correctly, and asked her to confirm a bank change for a supplier she really does use. The LimeLeads data breach is why that message was so accurate. Her name, title, employer, city and direct phone number were sitting in a sales database she never signed up for.
Confirmation: reported by ZDNet in January 2020 and documented by security researcher Bob Diachenko. LimeLeads is now defunct, so no company notice exists.
What happened in the LimeLeads data breach
LimeLeads sold business contact records to sales teams. Customers paid to search the database and export lists of people to cold-call. The people in those lists were the product, and nobody asked them.
On July 27, 2019, LimeLeads left an internal Elasticsearch server open to the internet, where Shodan indexed it. It carried no authentication, so anyone who found the address could read it. Diachenko reported the exposure to LimeLeads on September 16, 2019, and the company secured the server the following day.
But the server had been reachable for roughly seven weeks by then. In October 2019, a seller using the handle Omnichorus began offering 49 million records from the database on underground forums. ZDNet first reported that sale.
The figures differ because they count different things. The seller counted 49 million raw records. Have I Been Pwned loaded the data on September 22, 2026 and counted 17,838,396 unique email addresses after removing duplicates. Both numbers are accurate for what each describes.
What the LimeLeads data breach exposed, and what it is worth to a scammer
Each record held a fairly complete professional profile:
- Full name and job title — so a message can address you by role, which reads as legitimate.
- Work email address — the delivery route, and often the username for other systems.
- Employer, company address, city, state and ZIP — local detail that makes a lure specific.
- Direct phone number — the opening for a voice or text follow-up after the email.
- Company revenue and headcount — this is the targeting field. It lets a scammer sort millions of people by how much money sits behind them.
No passwords were in the file. That matters, because it changes the shape of the risk. This data does not get you into an account directly. Instead it tells an attacker exactly who you are, what you do, and what you might plausibly be asked to approve. In short, it is raw material for a convincing message rather than a key.
The part that makes this breach different
Most breach stories start with an account you opened. You signed up, you agreed to something, and then the company lost your data. You can at least point to the moment you took the risk.
Nobody in this file did that. LimeLeads collected these details from public sources and other data sellers, then packaged them for sale. The 17.8 million people involved were not customers, users or members. They had not created an account, so they had no account to close, no settings page to visit, and no notice to expect. The company is gone now, so there is nobody left to ask.
This is how the data broker industry works, and the LimeLeads data breach is a clean example of it. Brokers copy, combine and resell your contact details many times over. Each copy is one more server somebody can leave open.
What to do now
Most of the answer to the LimeLeads data breach has nothing to do with us, because most of it is just good practice.
Check whether you are in it. Search your work address and any old ones on Have I Been Pwned. It now carries the LimeLeads record.
Treat accuracy as a warning sign, not a credential. A message that knows your title and your employer is not therefore genuine. That information was for sale. So when a message is unusually well informed and also wants something urgent, slow down instead of speeding up.
Verify money requests on a second channel. If an email asks you to change bank details or approve a payment, call the supplier on a number you already had. Never use the number in the message, because that number may be the one from this file.
Use a password manager, and turn on the strongest sign-in each account offers. Passkeys where you can get them, an authenticator app otherwise. Text-message codes are better than nothing.
Expect the follow-up phish. Attackers read breach coverage too. Because of that, a wave of “your data was exposed, click here to check” emails usually follows any news like this. Go to the site yourself rather than clicking through.
Opt out where you can. Several US states require brokers that are still trading to honor deletion requests. It is slow work, but it shrinks the next copy.
How OptMsg changes this exposure
We should be straight about the limits here. OptMsg would not have prevented this breach. It happened at another company, to data that company had collected without asking. Nothing on our side reaches into someone else’s Elasticsearch server.
What it changes is what the stolen details can do to you afterwards, and there are two specific mechanisms.
Your OptMsg account has no password, so a password stolen from another site cannot be tried on your inbox. In a file like this one there were no passwords anyway. But your email address travels with you across every breach, and it is the reset route into most of your other accounts. Credential stuffing needs a password to try, and your OptMsg account does not have one.
The second mechanism is the one that fits this breach better. Mail from a sender you have not approved goes to Trash, not your Inbox, and it auto-deletes after 30 days. The whole value of a harvested contact list is that it lets a stranger reach you. That is the step this changes.
What this does not cover: a compromised device, a live phishing page you type your details into, or somebody with your unlocked phone. It also does nothing about the phone number in that record, and a scammer can still call it. This is a smaller claim than “you are protected,” and we would rather make the smaller true one.
If you want the version of this that starts clean, you can create a new address on the private-first plan and give it only to people you choose. Then the brokers have nothing new to copy.
Your Inbox. Your Rules.
Frequently asked questions
Q: I have never used LimeLeads. Why is my data in the LimeLeads data breach? A: LimeLeads was a business contact database, not a service people signed up for. It collected names, job titles and work emails from public sources and other data sellers, then sold access to that list. The people in the file were the product, so they never became customers and nobody asked them.
Q: How many people were affected? A: Have I Been Pwned counted 17,838,396 unique email addresses when it loaded the data on September 22, 2026. A seller offered 49 million raw records in October 2019. The lower figure removes duplicates, so both are correct for what each counts.
Q: Did the breach expose passwords? A: No. The records held names, job titles, work email addresses, employers, company addresses, phone numbers, company revenue and headcount. The risk is targeted phishing and fraud rather than direct account takeover.
Q: Can I get my details deleted now? A: Not from LimeLeads, because the company is defunct and copies of the data already changed hands. You can still send deletion requests to brokers that currently trade, and several US states require them to comply.
Q: What is the most likely way this data gets used against me? A: Business email compromise. Because an attacker knows your role, your employer and your direct line, they can write a payment or invoice request that fits your actual job. So verify any money request on a channel you chose yourself.
Sources
- Have I Been Pwned — LimeLeads breach record, loaded September 22, 2026
- Security Affairs — Hacker offers for sale 49 million user records from US data broker LimeLeads
- Have I Been Pwned — check your own address
Previous in Breach Breakdown: BigCommerce Data Breach: A Store App Leaked Shoppers' Names and Addresses
Next in Breach Breakdown: FBI Data Breach: Hackers Say They Hold Agents’ and Job Applicants’ Home Addresses
