Infutor data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
Infutor data breach (2026): what was exposed and what to doBy Delist Editorial Team · Updated September 28, 2026 · Corrections
September 28, 2026
What happened
In early March 2026, threat-intelligence firm SOCRadar reported discovering a publicly accessible Elasticsearch instance (no authentication) holding a large U.S. identity dataset. SOCRadar’s technical write-up (published around March 3, 2026, with later updates) described roughly 676.8 million indexed records (~91.7–92 GB) containing structured identity fields. SOCRadar explicitly noted that the unique-person count was unverified and that a total above the U.S. population strongly suggests aggregation, historical address retention, and duplicates—indexed records are not the same as unique Americans.
At first publication, SOCRadar said the data owner remained unidentified while analysts tried to contact the hosting provider and secure the exposure. Secondary coverage (Biometric Update, Security Info Watch, and others) repeated SOCRadar’s field schema and scale without independently naming a corporate owner in the primary technical post. Later secondary coverage, forum posts, and class-action marketing materials attributed the archive to consumer-identity data broker Infutor (also referenced with ActiveProspect / Verisk-related corporate naming in some press). Treat Infutor naming as secondary / contested attribution, not as a confirmed corporate admission in SOCRadar’s primary post.
Separately, at least one outlet (Decryption Digest) that had published Infutor-specific breach claims later retracted them on August 24, 2026, after Infutor said an independent review (Forvis Mazars, as reported by that outlet) found no evidence of unauthorized access to Infutor’s in-scope systems and could not substantiate the forum leak claims. This page does not invent a company admission. The solid, dated primary fact is SOCRadar’s open-Elasticsearch identity exposure; corporate ownership labeling remains hedged.
Press and forum reporting also described a subsequent dark-web / forum dump around March 8, 2026. Actor and forum claims are not company census figures—label them as reported. No CourtListener / PACER docket with a stable Infutor complaint PDF was locked on this pass.
Sources
- U.S. Elasticsearch Leak: 676M+ Identity Records & SSNs Exposed – SOCRadar (Mar 2026)
- Open Elasticsearch server exposes 676 million US identity records – Biometric Update
- Publicly Exposed Database Contains 676M U.S. Identity Records Including SSNs – Security Info Watch
- Correction: Infutor Data Breach Report Retracted – Decryption Digest (Aug 24, 2026)
- 2026 Infutor — 676.8M records — BreachHistory (secondary attribution page)
What data was exposed
Per SOCRadar’s field inventory from the open index (validated samples), records included combinations of:
- First and last names
- Full date of birth
- Street address, city, state, ZIP (including historical address patterns)
- Phone numbers
- Full Social Security numbers
Sampling described living and deceased individuals and multi-address histories. Exact fields in any one row vary. There is no official consumer mail from a confirmed owner that Delist can point you to as of this page’s last update—rely on any notice you actually receive, and on credit-freeze hygiene if your identifiers match this class of exposure.
Breach details
| Detail | Value |
|---|---|
| Breach name | Open Elasticsearch U.S. identity archive (SOCRadar discovery); Infutor naming via secondary/press/class-action sources — contested |
| Date | SOCRadar discovery ~March 3, 2026; forum dump reporting ~March 8, 2026 |
| Disclosed | SOCRadar public write-up March 2026; secondary Infutor attribution thereafter; at least one Infutor-named report later retracted (Aug 24, 2026) |
| Accounts affected | ~676.8M indexed records (SOCRadar; unique people unverified — not a unique-Americans count) |
| Domain | Not locked to a single consumer brand domain in SOCRadar’s primary post (hosting provider / owner unidentified at publication) |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by any named data broker or hosting party; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
Because this class of archive pairs SSNs with names, DOB, phones, and address history:
- Place a free credit freeze at Equifax, Experian, and TransUnion and keep the PINs somewhere safe. See how to freeze your credit.
- Monitor AnnualCreditReport.com for unfamiliar accounts; use IdentityTheft.gov if you see misuse.
- Treat cold calls or emails that recite your full SSN, prior addresses, or “broker breach help” as social engineering unless you initiated contact.
- Be skeptical of paid “Infutor removal” or “676M dump scrub” offers that arrive unsolicited—there is no Delist product that removes rows from a researcher-found archive or forum dump.
- If you receive a company or regulator notice that names you, keep it—that letter is the record of what applied to you.
Short checklist: first 48 hours after a data breach.
How this shows up on the open web
Broker-grade identity files overlap the same name / phone / address building blocks people-search sites already publish. After a large identity-archive exposure, tailored phishing can sound more plausible when someone can also look up your current listing online. Run a free open-web scan to see which people-search and data-broker sites expose your personal data. Delist does not claim to have scanned this Elasticsearch instance or any dump files, and it does not remove records from breach archives.
Related reading: how to remove yourself from data brokers, data broker opt-out guide, and what is people-search removal.
I heard about a 676M identity Elasticsearch exposure—what should I do first?
Freeze credit at all three bureaus if you are concerned about SSN exposure. Treat “broker breach help” cold outreach as social engineering. A free open-web scan checks people-search listings only—not the archive itself.
Frequently asked questions
Does ~676 million mean 676 million unique Americans?
No. SOCRadar labeled ~676.8 million as indexed records and said the unique count was unverified. A total above the U.S. population strongly suggests historical addresses, duplicates, and multi-source aggregation—not one record per person.
Did Infutor officially confirm it owned the open Elasticsearch?
SOCRadar’s primary post said the data owner was unidentified at publication. Infutor naming appears in secondary/press/class-action sources. Decryption Digest later retracted Infutor-specific claims (Aug 24, 2026) after the company cited a Forvis Mazars review that found no evidence of unauthorized access on its end. This page does not invent a corporate admission.
What fields did researchers say were in the index?
SOCRadar’s inventory included names, full DOB, street address/city/state/ZIP, phone numbers, and full SSNs, with historical address patterns in sampling.
Can Delist remove my record from this archive or dump?
No. Delist does not scrub Elasticsearch instances or breach dumps. A free scan checks open-web people-search and broker listings only.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- How to remove yourself from data brokers
- Data broker opt-out guide
- What is people-search removal?
- First 48 hours after a data breach
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.