Two large spam-related datasets, Special K Data Feed and SC Daily Phone, were added to Have I Been Pwned after exposing personal information tied to nearly 64 million identities in total. The records surfaced from 2015-era spam list activity and appear to have been compiled for use in unsolicited marketing or spam operations rather than from a single corporate intrusion.
The exposed data in both lists included names, physical addresses, IP addresses, genders, birth dates, and phone numbers, creating a broad privacy risk for affected individuals. Special K Data Feed contained nearly 31 million identities, while SC Daily Phone exposed nearly 33 million, highlighting how large-scale spam ecosystems can aggregate and circulate detailed personally identifiable information for abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In mid to late 2015, the Special K Data Feed spam list was discovered, containing nearly 31 million identities. The exposed data included names, physical addresses, IP addresses, genders, birth dates, and phone numbers, and appears to have been used in spam operations.
In early 2015, a spam list identified as SC Daily Phone emerged, exposing nearly 33 million identities. The dataset reportedly included names, physical addresses, IP addresses, genders, birth dates, and phone numbers.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.