ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

183 million business contacts stolen from DemandScience listed for sale by hacker

In a significant data exposure, a hacker known as ‘KryptonZambie’ has listed a database containing the contact details of 183 million individuals, including email addresses, phone numbers, job titles, and social media links, on a hacking forum for $6,000.

 

This trove of information was reportedly stolen from DemandScience, a data brokerage firm previously known as Pure Incubation. DemandScience confirmed the breach, stating the data was collected from publicly available sources and included only business-related information.

 

The data leak has raised concerns about the potential misuse of phishing and spam campaigns. Although the dataset contains business emails and job-related information, which is often easier to access than private data, the sale of such a large, organized archive provides malicious actors a significant tool for fraudulent activities. Email addresses and employment details can be used in Business Email Compromise (BEC) schemes, spam marketing, and phishing attacks, which could harm affected individuals and companies.

 

DemandScience responded to the breach, clarifying, “We process publicly available business contact information and do not collect, store, or process consumer data or any credential information or sensitive personal information, including accounts, passwords, home addresses, or other personal, non-business information.” This distinction underscores that while the dataset may have initially been public, the organized, accessible nature of the archive amplifies its potential for misuse.

 

The database, identified as originating from a “decommissioned legacy system” by the security tracking website HaveIBeenPwned?, surfaced on a hacking forum earlier this year. DemandScience’s legacy system vulnerability reportedly exposed the business contact information, which the company describes as part of an outdated system that is no longer active use. HaveIBeenPwned? has attributed this leak to DemandScience’s retired infrastructure, indicating the risk associated with unmonitored or legacy systems.

 

At the time of reporting, there was no evidence that the data had been purchased or exploited in ongoing malicious campaigns. However, cybersecurity experts caution that the potential remains high for abuse, especially as the database continues circulating in underground markets.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543