2018 apollo-corp — Have I Been Pwned verified incident: Apollo
Data compromised
Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers, Salutations, Social media profiles
Technical writeup
In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password . The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation. BreachHistory indexes the Have I Been Pwned (HIBP) corpus for third-party breach disclosure and victim notification context; treat record counts and fields as disclosed in that source at time of indexing.
Root cause
Variations by incident; see HIBP narrative and linked disclosures where present.