Apparently, a new data leak could affect hundreds of millions of Americans and it could be worse than the Equifax data leak that affected almost 150 million people. A security researcher claims that Exactis, a Florida-based marketing and data collecting firm, leaked detailed information on individual adults and businesses. It is estimated that the leak involved about 340 million records that were on a publicly available server. The data leak exposed information included phone numbers, home addresses, and email addresses. Vinny Troia, the security researcher who discovered the leak and reported it to Exactis, stated,
It seems like this is a database with pretty much every U.S. citizen in it. I don’t know where the data is coming from, but it’s one of the most comprehensive collections I’ve ever seen.
There is no evidence so far that anyone with malicious intent actually obtained the Exactis data. The information leaked by Exactis didn’t include Social Security numbers like the Equifax breach did, but it did include some general financial information. Troia told Wired Magazine he was curious about the security of ElasticSearch and when he did a search on the database, he found the Exactis database, which was unprotected. He also told the Federal Bureau of Investigation about his findings. Hopefully something can be done to better protect people’s information from being accessed.