Data Brokers

How Breach Data Ends Up on People Search Sites

By the RedactZero Team · September 8, 2026 · 8 min read

The short version

Mostly, it does not. Public people-search profiles are built from public records and commercial data feeds, not from hacked databases - the two industries look alike because they hold the same facts about you, not because one feeds the other. The genuine connections run in three directions: brokers get breached themselves, data-enrichment firms leak the profiles they sell, and criminals combine a broker profile with breach data to make fraud work. Only one half of that is removable, which is why opting out still matters.

The claim, and what the evidence actually supports

People often assume a public profile with their address on it must be the result of a hack. It usually is not. The claim that people-search sites resell breach dumps is popular, intuitive, and unsupported by public evidence. What is documented is messier and more interesting: two data supply chains that overlap heavily without one feeding the other.

That distinction matters practically. If your listing came from a breach, you would be waiting for a hacker to be arrested. Because it came from public records, you can file an opt-out today and it will work - for a while.

Where people-search profiles really come from

The information on a people-search profile is assembled from records that were already public or already for sale. Property deeds, voter registrations, court filings, business licences and marriage records supply the addresses and names. Commercial marketing feeds supply phone numbers, emails and household details. Nothing needs to be stolen for any of it to appear.

The FTC's 2014 report Data Brokers: A Call for Transparency and Accountability, built on orders to nine brokers including Intelius, found that brokers collect from extensive online and offline sources largely without consumers' knowledge, and that consumer data often passes through multiple layers of data brokers sharing data with each other. That layering is the important part - by the time a record lands on a public profile, its origin has been laundered through several hands.

We cover the mechanics in more depth in people-search sites explained.

Route one: the broker gets breached

The clearest real link between breaches and people-search data runs the opposite way to the myth. Brokers hold enormous consolidated files, which makes them targets. When one is hacked, a broker's profiles become breach data - the pipeline flows from public profile to dump, not the other way round.

National Public Data, a background-check broker, is the reference case. Have I Been Pwned records the April 2024 incident with 134 million unique email addresses and data classes covering names, dates of birth, phone numbers, physical addresses and government-issued IDs, while flagging the corpus as unverified. TechCrunch reported that researchers estimated the stolen database contained roughly 270 million Social Security numbers, and that the parent company, Jerico Pictures, filed for Chapter 11 bankruptcy in Florida in October 2024, citing class actions and the cost of notifying potentially hundreds of millions of people.

Nobody handed National Public Data their Social Security number. It had been assembled about them, then lost on their behalf. That is the uncomfortable feature of the broker model: the people in the database are not the customers, so they have no say in how well it is guarded and no warning when it fails.

Route two: enrichment firms leak the profiles they sell

Data enrichment companies sit one layer behind the sites you can search. They sell business customers an API that turns an email address into a full profile. They are not people-search sites, but they hold the same categories of data at much larger scale - and when their data escapes, it circulates permanently.

Two well-documented examples come from Have I Been Pwned. In October 2019, an unprotected Elasticsearch server holding 1.2 billion records was found to contain data sourced from the enrichment company People Data Labs, including 622 million unique email addresses alongside phone numbers, social profiles and job history. The server was not owned by People Data Labs; a customer is believed to have failed to secure it.

Earlier, in June 2018, the marketing data firm Exactis leaked 340 million records. The subset provided to Have I Been Pwned held 132 million unique email addresses, and the exposed fields ran to home ownership, income level, marital status, religion, personal interests and family structure.

Route three: the layers in between

The third route is not a single event but the industry's normal operation. Data moves between brokers, resellers and suppliers so often that no one downstream can say where a given record started. Once a leaked file is repackaged as a commercial list, it looks like every other commercial list.

The FTC has documented how little scrutiny that receives. In its September 2023 case against TruthFinder and Instant Checkmate, the agency alleged the companies advertised the most accurate information available to the public while their own third-party data suppliers expressly disclaimed accuracy, and the companies took no steps to verify it. A buyer who does not check accuracy is unlikely to be checking provenance either.

This is also why listings return after you remove them, a problem we unpack in why data brokers relist you. A record you deleted last spring can arrive back through a supplier that never knew you had objected.

What breach data usually becomes instead

Stolen data mostly does not go into public profiles because there is a more profitable use for it. It becomes criminal tooling: credential lists for account takeover, phone and email files for phishing, and identity kits for opening accounts in your name. That market moves faster and pays better than publishing a web page.

Scale gives a sense of the difference. Have I Been Pwned's ALIEN TXTBASE entry covers 23 billion rows of stealer logs pulled from a Telegram channel in February 2025, containing 284 million unique email addresses paired with the sites they were entered into and the passwords used. Nothing about that dataset is designed to be searched by the public - it exists to be fed into automated attacks. See what hackers do with your data for the full picture.

The numbers side by side

Comparing the big aggregator incidents shows what kind of company actually leaks profile data, and how the totals dwarf anything a single people-search listing contains. All four figures below are the unique email address counts published by Have I Been Pwned, not the vendors' own estimates.

IncidentDateUnique emailsType of company
ExactisJune 2018132 millionMarketing data aggregator
People Data Labs customer serverOctober 2019622 millionData enrichment
National Public DataApril 2024134 millionBackground-check broker
ALIEN TXTBASE stealer logsFebruary 2025284 millionCriminal log aggregation

Source: Have I Been Pwned breach entries for Exactis, PDL, National Public Data and ALIEN TXTBASE. The National Public Data entry is flagged unverified by HIBP.

Why the distinction changes what you should do

Treating the two pools as one leads people to the wrong conclusion, which is that nothing can be done. In reality one half is removable and the other is not, and knowing which is which tells you where to spend your effort.

Breach data cannot be recalled. Once a file is copied and traded, there is no form to submit and no company that can un-share it. Broker listings are the opposite: they are published by identifiable US companies that all offer a free opt-out, and the removal genuinely works until the next re-ingest cycle.

The harm usually comes from combining the two. A leaked password is far more dangerous when a public profile confirms your city, employer and relatives, because that is what makes a support-desk impersonation or a targeted phish believable. Removing the public half degrades the attack even though the leaked half stays out there. Our breaches and passwords section covers the credential side in detail.

How to check what is actually out there

Start by separating the two questions: what has leaked about you, and what is published about you. They need different checks, different fixes and different expectations about what success looks like, but you can answer both in about ten minutes and the answers together tell you where your real exposure sits.

For leaks, search your email addresses on Have I Been Pwned and read the data classes on each breach entry, which tell you what actually escaped. If Social Security numbers appear anywhere, follow our guide on what to do when your SSN is leaked. For publication, search your name plus your city and note which people-search sites return a profile that is really you.

RedactZero's free exposure scan does both at once - it checks your email against known breaches and lists the brokers most likely to publish a US adult - and stores nothing you enter.

Cutting the removable half

Once you know where you are listed, the work is mechanical. Each major people-search site has a free opt-out: find your listing, submit its URL, confirm by email. Most process within 24 to 72 hours. Expect listings to return within three to six months, because the public records feeding them never stop.

Our library of free, dated opt-out guides walks through the major brokers step by step. If you live in California, the state's DROP platform is a faster path: one request reaches over 500 registered brokers, and registered brokers must process those requests from August 1, 2026, per the California Privacy Protection Agency. Our California DROP guide has the steps.

Then set a reminder to re-check in a few months. Removal is maintenance, not a one-time fix - and it is the only half of this problem you have any leverage over.

Check both halves at once

Run a free exposure scan to see which breaches include your email and which data brokers are likely publishing your details - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Do people-search sites buy hacked data?

There is no public evidence that mainstream people-search sites knowingly buy breach dumps, and doing so openly would invite legal trouble. The more useful point is that they do not need to. Public records and commercial data feeds already give them your name, age, addresses, phone numbers and relatives.

Is my address on a people-search site because of a breach?

Almost certainly not. Addresses on people-search profiles usually come from public records such as property deeds, voter files and court filings, plus commercial marketing data. A breach can expose the same address, which is why the two feel connected, but they are separate supply chains.

What was the National Public Data breach?

National Public Data was a background-check data broker. In April 2024 a trove of its data was circulated online. Have I Been Pwned lists the incident with 134 million unique email addresses and flags it as unverified. TechCrunch reported that researchers estimated the stolen database held around 270 million Social Security numbers, and the parent company later filed for bankruptcy.

Does opting out of people-search sites help after a breach?

Yes, but for a different reason than most people expect. Opting out does not delete anything from a breach dump. It removes the free, current, public half of the picture - the address and relatives a scammer would otherwise pair with a leaked password or phone number.

Can I get my data removed from a breach dump?

No. Once a dataset is copied and traded there is no takedown to file and no one to file it with. That is the key asymmetry: broker listings are removable, breach data is not. Change the passwords, freeze the credit, and treat the leaked details as permanently public.

How do I find out which breaches include me?

Have I Been Pwned is the standard free database for checking whether an email address appeared in a known breach, and each entry lists the data classes that leaked. RedactZero's free scan checks the same database and stores nothing you type.

Are data enrichment companies the same as people-search sites?

No. Enrichment firms sell profile data to businesses through an API rather than publishing pages the public can search. They matter here because they hold the same kind of information at far greater scale, and when one leaks, that data enters circulation permanently.

If a data broker is breached, do they have to tell me?

Usually yes. According to the National Conference of State Legislatures, all 50 states have security breach notification laws requiring disclosure to consumers when personal information is compromised. What triggers notice, how quickly it must be sent, and which data types are covered vary considerably by state.

Sources: Have I Been Pwned breach entries for National Public Data, People Data Labs, Exactis and ALIEN TXTBASE Stealer Logs; TechCrunch on the National Public Data bankruptcy (October 2024); Federal Trade Commission, "Data Brokers: A Call for Transparency and Accountability" (May 2014) and the FTC's September 2023 action against TruthFinder and Instant Checkmate; National Conference of State Legislatures on state security breach notification laws; California Privacy Protection Agency on the Delete Act and DROP.