People-Search Breaches: Records Are Not the Same as People
A breach’s record count is not automatically a count of unique people. For your own response, verify which information was exposed and use an appropriate recovery plan.
By ZoraSafe · Content reviewed
Read the unit before repeating the headline
A record, an email address and a person are different units. A dataset may contain repeated or historical entries. Without a reliable explanation of the dataset, do not infer how many people were affected from its size.
Sources: FTC: People search sites that sell your information
Why people-search exposure still matters
The FTC explains that people-search sites compile information from public records and other sources. Even familiar or older details can help an impersonator sound convincing; removal from one site does not erase every source or saved copy.
Sources: FTC: People search sites that sell your information
Choose actions you can verify
Use an organization’s official notice and IdentityTheft.gov to decide what to do. Do not upload more identity information to an unfamiliar site just to check a sensational breach claim.
- Confirm the notice outside an incoming link.
- Review accounts and credit protections appropriate to the information involved.
- Keep records of suspicious activity and reports.
- Use specialist safety planning if exposure creates a stalking or personal-safety concern.
Sources: FTC: IdentityTheft.gov data breach response; FTC: What to know about identity theft
Sources and product references
Reviewed 2026-10-08. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.
