LimeLeads, a San Francisco B2B lead-generation provider that is now defunct, exposed an internet-accessible Elasticsearch server without password protection in 2019. The server, reportedly discoverable through Shodan from at least July 2019, was secured after researcher Bob Diachenko notified the company in September, but threat actor Omnichorus allegedly obtained and offered the database for sale on an underground forum.
The exposed dataset contained roughly 49 million business-contact records, including 17.8 million unique email addresses, phone numbers, employers, job titles, and location details such as cities, states, and postcodes. The breadth of corporate identity and organizational data creates material risk of targeted spear-phishing, business-email compromise, and other social-engineering campaigns against affected individuals and companies.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
A threat actor using the name Omnichorus reportedly began selling LimeLeads data on an underground forum, advertising a database of approximately 49 million business contacts. The exposed information included contact, employer, job-title, phone, and geographic details.
LimeLeads secured its publicly accessible Elasticsearch server one day after receiving Diachenko's notification.
Security researcher Bob Diachenko identified LimeLeads' exposed Elasticsearch server and notified the company. The exposure made a large database of business-contact records accessible.
LimeLeads' internal Elasticsearch server, which lacked password protection, had been indexed by Shodan as publicly accessible since at least July 27, 2019.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.