Business services giant Dun & Bradstreet's 52GB database exposed, containing 33M+ government and corporate employee records
Exclusive: The database contains more than 33 million records, including government departments and large corporate clients, which gets sold onto marketers.
Context & Ripple Effects
Dun & Bradstreet is a business-data broker by trade, so the exposure of a 52GB trove of 33M+ government and corporate employee records is a breach of its core product, not an adjacent system — and the description notes the data gets sold onto marketers, meaning copies were already circulating commercially before it surfaced unprotected.
The story fits a recurring pattern in the corpus: marketing-adjacent datasets left open on cloud infrastructure, from an email validation firm's 150GB plaintext database of 763M email addresses to 80M US household demographic records sitting unsecured on a Microsoft cloud service and an ad agency's 150K-record leak. The scale here is smaller than the largest cases but the sensitivity is higher, because the named subjects are identifiable employees of government departments and large corporates.
First-order effects
- Government departments and large corporate clients named in the database now have employee-level records — names, roles, employer affiliations — circulating outside their control, a ready-made targeting list for phishing and social engineering against those organizations.
- Dun & Bradstreet faces immediate reputational damage to the trust its brokerage model depends on: clients pay for curated business data, and the same asset has now been demonstrated to be both leakable and already resold to marketers.
Second-order effects
- Marketers who bought slices of this dataset inherit the exposure — their own customer and prospect files are compromised through a supplier they never secured, pushing buyers to demand security attestations from data vendors.
- Rival data brokers and cloud-hosted marketing firms get pulled into the same audit cycle seen after the household-records and email-validation leaks, where researchers' disclosures force every similar unsecured bucket offline and raise procurement scrutiny across the sector.
Third-order effects
- If the pattern holds — brokered marketing data repeatedly surfacing unprotected years after collection — the data-broker industry moves toward contractual liability for downstream leaks, with regulators treating resold datasets as a standing attack surface rather than a one-off incident.
- The recurring root cause, misconfigured cloud storage holding data long past its active use, points to retention limits and default-private storage becoming baseline requirements for any company whose product is personal data.
The trend: Commercially aggregated marketing databases keep surfacing unprotected on cloud infrastructure, turning the data-broker supply chain into a persistent breach vector that outlasts any single disclosure.