Data center firm leaks massive 38GB database containing thousands of personal records online
- Security researcher finds unsecured 38GB database containing 10,820 records
- Names, postal addresses, and more were leaked to the open internet
- The archive, owned by IMDataCenter is now shut down
IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, has been found leaking thousands of sensitive personal records to the open internet.
Security researcher Jeremiah Fowler discovered an unencrypted and non-password-protected database, containing 10,820 records. It was 38 GB in size, with the majority of files being .CSV spreadsheets with “many thousands or hundreds of thousands of rows of PII.”
There is no evidence of abuse in the wild just yet, but the PII (Personally Identifiable Information) included people’s names, postal addresses, email addresses, phone numbers, and lifestyle or ownership information.
Locking down the database
“The records appeared to be a storage repository for client orders labeled “reports” and “results”,” Fowler told Website Planet.
“Files names indicated these lists were used for multiple purposes, including sales and marketing leads for industries such as insurance, solar, elections, car warranties, hospitals, healthcare providers, and more.”
IMDataCenter is a Florida-based division of Brooks Integrated Marketing, offering a platform for marketing data improvement, including identity resolution, phone and email appending, Complete Integrated Marketing Append (CIMA), and more.
The platform’s data library spans 260 million individuals, 130 million households, 600 million emails, 550 million phone numbers, and more.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Fowler reached out to the company to warn them about the leaking information, and the database was locked down soon after.
“Data security is really important to us too and we really appreciate you sharing this information with us,” they told the researcher. “We are working to secure the information ASAP”.
The researcher also stressed that many companies hire third-party service providers to own and manage such databases. It is unknown who maintains IMDataCenter’s one. It is also unknown if any malicious actors found the database in the past, or abused it for phishing, identity theft, or similar impersonation attacks.
You might also like
Security researcher finds unsecured 38GB database containing 10,820 records Names, postal addresses, and more were leaked to the open internet The archive, owned by IMDataCenter is now shut down IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, has been found leaking thousands of sensitive personal records to the…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023