Apollo data exposure (2018)
Sales-engagement startup Apollo left a database of 9 billion data points and over 200 million contact records exposed without a password in 2018; a subset of 126 million unique email addresses was loaded into Have I Been Pwned after researcher Vinny Troia found it.
- Victim
- Apollo
- records
- 125.9M
- users
- 125.9M
In July 2018, the San Francisco sales-engagement and lead-generation startup Apollo (apollo.io) left an enormous marketing database publicly accessible on the internet with no password. Security researcher Vinny Troia of Night Lion Security discovered the exposure, which encompassed roughly 9 billion data points and over 200 million contact records.
What happened
Apollo's product is a "revenue acceleration platform" that aggregates contact and company intelligence to help sales teams prospect. To build that product, Apollo combined data scraped from public web sources โ including LinkedIn and Twitter profiles โ with information imported by customers from their own CRM and Salesforce accounts.
A misconfiguration left the underlying database reachable from the open internet. Troia, who at the time was researching the separate Exactis exposure, came across the Apollo trove and verified its contents. He later sent a subset containing 126 million unique email addresses to Have I Been Pwned, where 125,929,660 addresses were indexed.
Data exposed
Because Apollo is a data aggregator, the exposed records were unusually rich:
- Names and email addresses
- Employer / company names, job titles and roles
- Geographic location
- Phone numbers and other business contact details
- Social media handles harvested from LinkedIn and Twitter
Notably, the dataset did not contain passwords or financial account credentials โ it was a contact and business-intelligence database, not a consumer login store. The risk was therefore weighted toward targeted phishing, business-email-compromise and social-engineering rather than account takeover.
Impact and response
Apollo confirmed the incident in an email to customers, framing it as unauthorised access to contact and business information. Because much of the data was scraped from public profiles, Apollo characterised the bulk of it as non-sensitive โ but the aggregation of professional details, employer mapping and contact data into a single queryable corpus is precisely what makes such leaks valuable to attackers building targeting lists.
Why it matters
The Apollo exposure sits alongside Exactis and similar incidents as a case study in the risks posed by data brokers and aggregators. No system was "hacked" in the classic sense; a configuration error simply exposed a corpus assembled from scraping and customer uploads. It underscored that organisations whose entire business is accumulating personal and professional data at scale carry an outsized responsibility โ a single misconfiguration turns a marketing asset into a mass-scale privacy incident, and the scraped origin of the data offers little legal or ethical cover.
Timeline
Security researcher Vinny Troia discovers Apollo's database publicly accessible online without any password.
Troia notifies Apollo; the company secures the exposed database.
Apollo emails customers to disclose that contact and business data was accessed by an unauthorised party.
Have I Been Pwned loads 125,929,660 unique email addresses from the Apollo dataset.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/breach/Apollo
- vinnytroia.comhttps://vinnytroia.com/news/2018/apollo-io-leak-exposes-billions-of-data-points/
- privacyinternational.orghttps://privacyinternational.org/examples/2580/breach-data-aggregator-apollo-exposes-information-212-million-people
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Vinny_Troia