Skip to content
Data breachResolved

Apollo data exposure (2018)

Sales-engagement startup Apollo left a database of 9 billion data points and over 200 million contact records exposed without a password in 2018; a subset of 126 million unique email addresses was loaded into Have I Been Pwned after researcher Vinny Troia found it.

Victim
Apollo
records
125.9M
users
125.9M

In July 2018, the San Francisco sales-engagement and lead-generation startup Apollo (apollo.io) left an enormous marketing database publicly accessible on the internet with no password. Security researcher Vinny Troia of Night Lion Security discovered the exposure, which encompassed roughly 9 billion data points and over 200 million contact records.

What happened

Apollo's product is a "revenue acceleration platform" that aggregates contact and company intelligence to help sales teams prospect. To build that product, Apollo combined data scraped from public web sources โ€” including LinkedIn and Twitter profiles โ€” with information imported by customers from their own CRM and Salesforce accounts.

A misconfiguration left the underlying database reachable from the open internet. Troia, who at the time was researching the separate Exactis exposure, came across the Apollo trove and verified its contents. He later sent a subset containing 126 million unique email addresses to Have I Been Pwned, where 125,929,660 addresses were indexed.

Data exposed

Because Apollo is a data aggregator, the exposed records were unusually rich:

  • Names and email addresses
  • Employer / company names, job titles and roles
  • Geographic location
  • Phone numbers and other business contact details
  • Social media handles harvested from LinkedIn and Twitter

Notably, the dataset did not contain passwords or financial account credentials โ€” it was a contact and business-intelligence database, not a consumer login store. The risk was therefore weighted toward targeted phishing, business-email-compromise and social-engineering rather than account takeover.

Impact and response

Apollo confirmed the incident in an email to customers, framing it as unauthorised access to contact and business information. Because much of the data was scraped from public profiles, Apollo characterised the bulk of it as non-sensitive โ€” but the aggregation of professional details, employer mapping and contact data into a single queryable corpus is precisely what makes such leaks valuable to attackers building targeting lists.

Why it matters

The Apollo exposure sits alongside Exactis and similar incidents as a case study in the risks posed by data brokers and aggregators. No system was "hacked" in the classic sense; a configuration error simply exposed a corpus assembled from scraping and customer uploads. It underscored that organisations whose entire business is accumulating personal and professional data at scale carry an outsized responsibility โ€” a single misconfiguration turns a marketing asset into a mass-scale privacy incident, and the scraped origin of the data offers little legal or ethical cover.

Timeline

  1. Security researcher Vinny Troia discovers Apollo's database publicly accessible online without any password.

  2. Troia notifies Apollo; the company secures the exposed database.

  3. Apollo emails customers to disclose that contact and business data was accessed by an unauthorised party.

  4. Have I Been Pwned loads 125,929,660 unique email addresses from the Apollo dataset.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/breach/Apollo
  2. vinnytroia.comhttps://vinnytroia.com/news/2018/apollo-io-leak-exposes-billions-of-data-points/
  3. privacyinternational.orghttps://privacyinternational.org/examples/2580/breach-data-aggregator-apollo-exposes-information-212-million-people
  4. en.wikipedia.orghttps://en.wikipedia.org/wiki/Vinny_Troia

Related incidents

Data breachResolved

Hot Topic data breach (2024)

In October 2024, retailer Hot Topic suffered a data breach that exposed 57 million unique email addresses. The impacted data also included physical addresses, phone numbers, purchases, genders, dates of birth and partial credit data containing card type, expiry and last 4 digits.

Victim
Hot Topic
Records
56.9M