TL;DR: Security researchers discovered a data broker’s Elasticsearch database sitting wide open on the internet, no password required. Inside: 676 million Americans’ full Social Security numbers, names, dates of birth, complete address histories, and phone numbers. That’s more records than there are living Americans. The company, Infutor, helps businesses verify customer identities. Instead, they handed attackers everything needed to steal those identities. A threat actor has already posted the data on criminal forums. Freeze your credit. Now.

What Happened

On March 3, 2026, threat intelligence firm SOCRadar discovered a massive Elasticsearch database exposed to the public internet. No authentication. No password. Just port 9200 open to anyone who knew where to look [1][2].

The database contained 676,798,866 records across 91.7 gigabytes of data. Every record included what identity thieves dream about: full names, complete Social Security numbers, dates of birth, address histories, and phone numbers [2][3].

Five days later, on March 8, a threat actor using the handle “Spirigatito” posted the dataset on BreachForums, making it available to the criminal underground [4][5].

The Numbers Don’t Make Sense (Until They Do)

676 million records. The US population is about 340 million. How does a database have twice as many records as living Americans?

Because Infutor doesn’t just track living people. Their consumer identity graph includes:

  • Current records for living adults
  • Historical records showing previous addresses and phone numbers
  • Records for deceased individuals
  • Multiple entries per person as their information changed over time

This is what 30+ years of consumer data collection looks like. Every address you’ve ever lived at. Every phone number you’ve had. All tied to your Social Security number [6].

SOCRadar noted that approximately 250 million related records had already been circulating on hacker forums before this discovery, meaning parts of this data were compromised even earlier [2].

Who Is Infutor?

You’ve never heard of Infutor. That’s by design.

Infutor is a data broker that sells consumer identity information to companies in insurance, consumer finance, higher education, real estate, and marketing. When a bank needs to verify your identity, when an insurer wants to assess your risk, when a marketer wants to find your phone number, they might buy that data from Infutor [6][7].

The company claims to maintain “privacy-compliant, individual-level profiles on 266 million U.S. adult consumers.” Their database includes:

  • Identity linkage: phone, email, consumer history
  • Property and automotive ownership details
  • Demographics and household attributes
  • Behavioral and life stage segments
  • Wealth indicators and in-market data

In January 2026 (just weeks before this exposure) Verisk Analytics sold Infutor (operating as Verisk Marketing Solutions) to ActiveProspect, a consent-based marketing company [8].

How This Happened

An Elasticsearch database running version 8.15.2 was exposed on port 9200 with no authentication required [2].

This is basic security 101 failure:

  • No password protection on a database containing SSNs
  • No network segmentation isolating it from the internet
  • No apparent monitoring that would have detected the exposure

SOCRadar tried to identify the data owner and hosting provider for remediation. At the time of their report, “the actual data owner had not been publicly identified,” though the instance appeared hosted by a third-party provider [2].

The threat actor Spirigatito isn’t new to this. The data-broker plumbing behind it is the same one that feeds the government data broker loophole. The same handle has claimed responsibility for breaching Tanzania’s Business Registrations Agency and Iran’s Shaparak payment network [5].

Why This Is Different

Most data breaches expose names and email addresses. Maybe passwords. Sometimes partial credit card numbers.

This breach exposed the complete identity package:

  • Full SSN: Not the last four digits. The whole number.
  • Complete address history: Every place you’ve lived.
  • Date of birth: The other half of identity verification.
  • Phone numbers: Current and historical.

This is everything needed to open credit cards, file fraudulent tax returns, take over existing accounts, apply for loans, or commit benefits fraud in your name.

And unlike a password, you can’t change your Social Security number. Once it’s out there, it’s out there forever.

Are You Affected?

If you’re an American adult, assume yes.

Infutor doesn’t have a customer relationship with you. They collected your data from public records, commercial databases, and other data brokers. You never signed up for their service. You never agreed to have your SSN stored on their systems. They just have it.

That’s how the data broker industry works. Companies trade your information without your knowledge or consent. And when one of them screws up security, everyone pays the price, as 26 million Americans learned in the Conduent government-services breach.

What to Do Right Now

Freeze your credit immediately. This is not optional. Do it today:

A credit freeze prevents anyone from opening new accounts in your name, including you, until you unfreeze. It’s free and takes about 10 minutes per bureau.

Get an IRS Identity Protection PIN. This prevents someone from filing fraudulent tax returns using your SSN. Apply at IRS.gov.

Monitor your credit reports. You’re entitled to free weekly reports from AnnualCreditReport.com. Check for accounts you didn’t open.

Consider a Social Security account lock. Create an account at SSA.gov to prevent someone else from creating one using your information.

The Data Broker Problem

This breach exists because companies like Infutor are allowed to collect and store your most sensitive personal information without your consent. They buy it, aggregate it, and sell it, and you have no say in the matter.

When they fail to protect it (and they always eventually fail) you bear the consequences.

Some states are pushing back. California’s Delete Act (SB 362) created a system where residents can request data brokers delete their information. It goes live April 1, 2026 [10]. Vermont requires data broker registration. But there’s no federal law requiring data brokers to protect your data or let you opt out.

Until that changes, companies will keep collecting everything about you, storing it with minimal security, and leaving it exposed for anyone to find.

References

  1. SOCRadar: U.S. Elasticsearch Leak: 676M+ Identity Records & SSNs Exposed (March 2026)
  2. Biometric Update: Open Elasticsearch server exposes 676 million US identity records (March 2026)
  3. ClassAction.org: Infutor Data Breach Reportedly Exposes 676M Records, Including SSNs
  4. Daily Dark Web: Infutor Data Breach Exposes 676 Million Consumer Records (March 2026)
  5. VECERT Analyzer: Infutor breach alert thread (March 8, 2026)
  6. Infutor: Consumer Identity Data
  7. Infutor: On-Premise Data Licensing
  8. GlobeNewswire: Verisk Announces Sale of its Marketing Solutions Business to ActiveProspect (January 2026)
  9. Chimicles Schwartz Kriner: Infutor Data Breach Investigation
  10. California Attorney General: Data Broker Registry