Data leaks can feel distant until your own email address appears in one.
At Futureproof, we see the real impact of data breaches through the people we protect.
Over the past three years, our users’ email addresses have appeared in leaks connected to financial services, social media platforms, retailers, investment websites, and news subscriptions.
Some incidents exposed only contact details. Others included passwords, home addresses, financial information, and Social Security numbers. In every case, the leaked email address gave scammers a starting point.
Here are five significant email data leaks that affected our users — and what each one means for you.
Table of Contents
Twitter 200M Data Breach
In early 2023, a hacker published more than 200 million Twitter records on a hacking forum.
The data had been collected in 2021 by taking advantage of a bug that allowed people to match email addresses with Twitter accounts.
The leak connected users’ email addresses to public Twitter information, including names and usernames.
Why This Breach Matters
This incident did not expose detailed financial information. However, connecting a private email address to a public social media profile can still create serious risks.
Attackers can use this connection to learn more about a person’s:
- Interests
- Work
- Location
- Friends or professional contacts
- Opinions
- Online habits
- Other usernames
This information can then be used to create personalized phishing messages.
For example, a scammer may pretend to be someone you follow, a company you have mentioned, or Twitter support team. They may also search for other accounts connected to the same email address or username.
If you have a Twitter account, update your password, review active sessions, and turn on two-factor authentication.
If you have never used Twitter before, still be careful with messages that mention your name, username, interests, or other personal details. Your email may have been connected to public information collected from another person’s profile, contact list, or online source.
The Post Millennial Data Breach
In May 2024, the conservative news website The Post Millennial suffered a breach that changed parts of its website without permission and exposed several groups of data.
One group contained information about hundreds of writers and editors, including email addresses, home addresses, and IP addresses.
Another included tens of thousands of subscribers. The exposed information included names, email addresses, usernames, phone numbers, and passwords.
A third dataset contained tens of millions of email addresses from mailing lists connected to the website, although this part has not been fully verified.
Why This Breach Matters
The passwords were exposed in a readable form, so attackers could use them immediately without having to crack them first.
This becomes especially dangerous when someone has reused the same password for their email, social media, shopping, or financial accounts.
The exposed subscriber information could also help scammers create convincing messages about:
- News subscriptions
- Political content
- Account problems
- Password resets
- Subscription payments or renewals
A fake message may include your real name, username, or phone number and look familiar.
Anyone who had an account should reset the password and change it anywhere else it was reused.
If you never used this website, watch for suspicious emails about news subscriptions, political content, account alerts, or password resets anyway. This is important because your email may still have appeared in a mailing list connected to the breach.
Prosper Data Breach
In September 2025, financial services company Prosper reported that someone had gained unauthorized access to its systems.
The breach affected customers and people who had applied for Prosper services. It included approximately 17.6 million unique email addresses, as well as other personal information. Some exposed records included US Social Security numbers.
Why This Breach Matters
An email leak is already enough to increase the risk of targeted scams. But when that email is connected to financial and identity information, the possible damage becomes much more serious.
Scammers may use the exposed details to:
- Pretend to be Prosper or another financial company
- Send fake loan, payment, or account alerts
- Try to reset passwords on other accounts
- Open accounts or apply for credit using stolen information
- Make calls or emails sound more believable by mentioning real personal details
Anyone affected by this breach should change their Prosper password, especially if it was reused elsewhere. It is also important to review credit reports and bank statements for unfamiliar activity because Social Security numbers were involved too.
And even if you’ve never used this exact site before, your email may have still ended up in it through a partner, data broker, or another service behind the scenes. So take a minute to change your email password.
Neiman Marcus Data Breach
In May 2024, luxury retailer Neiman Marcus suffered a data breach that included approximately 31 million unique email addresses.
The exposed information also included names, phone numbers, dates of birth, physical addresses, and partial credit card data.
Why This Breach Matters
Retail scams are common because they are easy to fake as ordinary customer messages.
After a breach like this, scammers may send emails or texts about:
- An order you did not place
- A refund waiting to be claimed
- A problem with your payment
- A delivery that needs confirmation
- A loyalty reward or special offer
- A request to update your account
Because the exposed data included names, addresses, phone numbers, and partial payment information, a fake message could look very personal.
For example, a scammer may mention your real location or show part of a payment card number to make the message appear trustworthy.
Do not use links in unexpected emails about orders, refunds, or account problems from Neiman Marcus. Open the retailer’s website yourself or use its official app instead.
Zacks Data Breach
In June 2024, investment research company Zacks was breached, with data later published on a popular hacking forum.
The incident followed a separate breach confirmed by Zacks in 2023. The 2024 dataset reportedly included approximately 12 million unique email addresses, along with names, usernames, phone numbers, IP addresses, and physical addresses.
Why This Breach Matters
Financial and investment-related information can make someone a more attractive target for scammers.
Even when account balances or payment details are not exposed, criminals may use the connection to Zacks to create targeted messages about:
- Investment accounts
- Market alerts
- Subscription renewals
- Stock recommendations
- Account verification
- Unusual login activity
- Refunds or failed payments
A scammer could combine an email address with a real name, username, phone number, or home address to make the request seem real. The goal may be to steal a password, collect more financial information, or convince the person to send money.
Anyone affected should be especially careful with unexpected investment messages and avoid making financial decisions directly from an email or text.
Even if you never used Zacks, be careful with unexpected investment messages and avoid making financial decisions directly from an email or text.
How to Respond to These Data Leaks
Each breach from this list needs a different response. Our help center explains what information was exposed in more detail and provides clear steps you can take to protect yourself.
There you’ll also find the full list of other data breaches that affected our users, and how to respond to them as well.

Know Exactly When Your Email Is Leaked
Most people do not know their email has appeared in a data leak until they get suspicious messages, login attempts, or unfamiliar account activity.
Futureproof helps you prevent the damage.
It monitors your email for data leaks 24/7 and alerts you as soon as your address appears in one. You can also contact a security specialist anytime to understand what happened, what information may be at risk, and what to do next.
Remember: the sooner you know where your email has appeared, the sooner you can protect your email account and personal information connected to it.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
