← People Data Labs

2019 People Data Labs — exposed enrichment server (~179M rows in XON/HIBP backfill)

2019 622.0M records affected Share on X

Data compromised

Emails, names, phone numbers, locations, social profiles (enrichment/marketing fields)

Technical writeup

People Data Labs (PDL), a B2B data-enrichment vendor, left a Elasticsearch cluster exposed that security researchers discovered in October 2019. Troy Hunt and Have I Been Pwned documented roughly 622M email addresses in the broader leak corpus with about 1.2B unique person profiles across duplicate rows; XposedOrNot’s H1 2026 backfill indexes 179,117,119 records with emails, names, phones, locations, and social profiles. PDL acknowledged the server was exposed and said the data largely mirrored marketing-oriented fields rather than consumer passwords. Indexed as historical verified exposure/backfill, distinct from 2026 fresh breaches.

Root cause

Misconfigured/public Elasticsearch server (2019)

References