CORRECTIONS | INFUTOR DATA BREACH
2 min read

Correction: Our Report on an Alleged Infutor Data Breach

Sources:

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

On April 20, 2026, Decryption Digest published a report titled "676 Million Americans' SSNs Are on the Dark Web, Infutor Left 91.7 GB Exposed with No Password," based on a dark web forum post alleging a breach of Infutor (Lead Intelligence, Inc., d/b/a InfutorData), a consumer data broker owned by Verisk Analytics subsidiary ActiveProspect, Inc.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

What we are correcting

The forum post our report relied on has since been removed and its underlying claims could not be independently substantiated. Infutor has informed us that it engaged Forvis Mazars, LLP, an independent third-party cybersecurity firm, to investigate. Forvis Mazars' review did not identify evidence of unauthorized access to Infutor's in-scope systems, and did not find evidence that the data referenced in the original forum post was ever actually posted or otherwise substantiated as leaked.

We have removed the original report and all references to it elsewhere on this site. We regret publishing the claim without stronger independent verification and any confusion it may have caused.

The bottom line

We could not independently substantiate the original breach claim, and Infutor's third-party investigation found no evidence of unauthorized access on its end. We have retracted the report accordingly.

Sources & references

    Free resources

    25
    Free download

    Critical CVE Reference Card 2025–2026

    25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

    No spam. Unsubscribe anytime.

    Free download

    Ransomware Incident Response Playbook

    Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

    No spam. Unsubscribe anytime.

    Free newsletter

    Get threat intel before your inbox does.

    50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

    Unsubscribe anytime. We never sell your data.

    Eric Bang
    Author

    Founder & Cybersecurity Evangelist, Decryption Digest

    Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

    Related Questions: Answer Hub

    Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

    Details →
    Daily Briefing

    Subscribe to enter the giveaway

    Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

    Already subscribed? You're already entered.

    Giveaway

    Win a $3,895 InfoSec World 2026 pass.