If you were in the LimeLeads breach, your work email, direct phone number, job title and employer are circulating in a 17.8 million record B2B contact dump now indexed by Have I Been Pwned. Nothing financial was exposed, so the real risk is targeted phishing and business email compromise. Here is what to do.
What Happened in the LimeLeads Breach
LimeLeads was a B2B sales-intelligence company that sold searchable databases of business contacts to sales teams. In July 2019 it left an internal Elasticsearch server exposed to the open internet with no authentication, meaning anyone who found the address could read the whole database. The exposure was reported to the company in September 2019 and the server was secured the following day — but the data was already out.
The dataset resurfaced publicly and was added to Have I Been Pwned on September 22, 2026, listing 17,838,396 unique email addresses. LimeLeads itself is now defunct, which means there is no company to write to, no support queue to escalate through, and no breach notification letter coming.
What Data Was Exposed
- Names
- Email addresses, overwhelmingly work addresses
- Phone numbers, including direct dials
- Employers and job titles
- Geographic location — city, state and postcode
No passwords, payment details or government identifiers were included. That sounds reassuring and mostly is, but a verified name, title, employer and direct phone line is exactly the raw material a convincing impersonation attack needs.
You never signed up for LimeLeads
This is the part that catches people out. LimeLeads was a lead-generation database: it compiled business contacts and sold access to them. The people in those records were the product, and none of them opted in. You can be in this breach having never heard the company's name.
Step 1: Confirm Whether You Are Affected
Check your work email address, any previous work addresses, and personal addresses you have ever used professionally at haveibeenpwned.com. Roughly half of the records in this dump already appeared in earlier breaches, so a hit may reflect long-standing exposure rather than something new.
Step 2: Treat Every Work Email as Pre-Verified by Attackers
The practical consequence of this breach is that spear-phishing against you just got easier. An attacker knows your name, your employer, your title and your direct line. That is enough to write a message that references your actual reporting line and job function.
- Verify payment and banking change requests out of band. Call a known number, never one supplied in the email.
- Be suspicious of urgency from "executives" — a gift-card or wire request that has to happen in the next ten minutes is the oldest business email compromise play there is.
- Check sender domains character by character. Lookalike domains swapping "rn" for "m" still work.
- Expect vishing. Your direct dial is in the dump, so phone calls claiming to be IT support are a live risk.
Step 3: Lock Down the Accounts Tied to That Address
Even though no passwords leaked here, your exposed address is now a confirmed target for credential stuffing against every service where you reused a password.
- Turn on multi-factor authentication everywhere, preferring an authenticator app or hardware key over SMS
- Replace any password you have reused, starting with email and single sign-on accounts
- Move to a password manager so every account gets a unique credential
- Review active sessions and connected apps on your primary mail account
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Get Your Contact Details Out of the Other B2B Databases
This is the step most people skip, and it is the one that actually reduces future exposure. LimeLeads was one company in a crowded industry. The same profile — name, title, employer, work email, direct dial — sits in dozens of live sales-intelligence platforms right now, each one a future breach.
Every major B2B data provider is legally required to offer an opt-out. Work through them:
- ZoomInfo
- Apollo.io
- Lusha, Cognism and LeadIQ
- RocketReach and Seamless.ai
- Clearbit, 6sense and Demandbase
Expect each one to take 10 to 20 minutes, require identity verification, and need re-checking, because these platforms rebuild profiles from public sources and partner feeds.
Step 5: Watch for the Follow-On Scams
Old breach data gets recycled into new campaigns. In the months after a dump is indexed, expect a rise in recruitment scams referencing your real job title, fake invoice and vendor-update emails, LinkedIn connection requests from fabricated colleagues, and calls from people who already know where you work and what you do.
Check your exposure in 30 seconds
PrivacyOn's free scan shows which broker and people-search sites are publishing your details right now, including the personal address and phone data that turns a work-contact leak into a home-address problem.
How PrivacyOn Helps After a Breach Like This
PrivacyOn handles the part of this you cannot realistically keep up with. It submits and tracks removal requests across 100+ data broker and people-search sites, rescans continuously so profiles that reappear get resubmitted, and runs dark web monitoring that alerts you when your email or credentials surface in a new dump rather than years later. Plans start at $8.33/month and cover up to five family members.
Frequently Asked Questions
What was exposed in the LimeLeads data breach?
Names, email addresses (mostly work), phone numbers, employers, job titles and geographic location down to city, state and postcode. No passwords, payment card data or government identifiers were included. Have I Been Pwned lists 17,838,396 unique email addresses in the dataset.
When did the LimeLeads breach happen?
The underlying exposure dates to July 2019, when LimeLeads left an unsecured Elasticsearch server reachable from the internet. It was reported in September 2019 and closed the next day. The dataset was added to Have I Been Pwned on September 22, 2026, which is why notifications are arriving now for a seven-year-old incident.
I never used LimeLeads. Why is my email in the breach?
LimeLeads compiled business contact records and sold access to sales teams. The people in the database were the product, not customers, and were never asked for consent. Being listed required nothing more than having a findable work email and job title.
Do I need to change my password because of LimeLeads?
No password data was exposed, so there is no direct compromise. Change any password you have reused across multiple sites anyway, because a confirmed-valid email address makes you a better credential-stuffing target. Enabling multi-factor authentication matters more here than rotating one password.
How do I stop my details ending up in the next B2B breach?
Opt out of the live sales-intelligence platforms that hold the same profile — ZoomInfo, Apollo.io, Lusha, RocketReach, Seamless.ai, Cognism and the rest — and re-check them periodically, because they rebuild from public sources. PrivacyOn automates that across 100+ broker and people-search sites and adds dark web monitoring so you hear about the next exposure early.