Risk level: low. Can you change it: no. Found in 6 breaches in this directory.
What this data is
A broad bracket such as 25 to 34 or 65 plus, stored for marketing segmentation rather than identification. It is deliberately less precise than an age or a date of birth.
The risk on its own
This is genuinely low risk and it would be dishonest to say otherwise. A bracket cannot identify you, cannot open an account and cannot answer a security question. At worst it confirms that the account belongs to an adult.
The risk combined with other data
Its only real value is as a filter. Combined with your name and contact details it lets a scammer pick who to target with age specific approaches: pension reviews for older brackets, student debt offers for younger ones. It also helps data brokers merge your records across leaks with more confidence.
How criminals use it
Scam campaigns filter the stolen list to the 65 plus bracket before sending pension or grandparent scam messages.
Marketing spam becomes noticeably better matched to your life stage, which makes it easier to believe.
A broker uses the bracket as a matching signal to join two otherwise separate records into one profile on you.
What to do now
Do not lose sleep over this field on its own. Focus on the password and email address in the same breach.
Check what else that company held, since an age group is usually stored beside far more sensitive marketing fields.
Where a site asks for an age bracket and does not need it, leave it blank or choose the vaguest option available.
If you are in an older bracket, expect more age targeted calls and set your phone to silence unknown callers.
Frequently asked questions
Is an age group dangerous on its own?
No. It is one of the least useful fields a criminal can get. It matters only as a targeting filter beside your contact details.
Why do companies store an age bracket instead of my birthday?
Advertising segments need the bracket, not the exact date, so storing the range is the privacy friendlier choice they made for once.
Should I still act on this breach?
Yes, but act on the sensitive fields in it. Change the password, check for reuse, and see whether an email address or phone number leaked alongside.
Breaches that exposed this data
Addi: 2026-03-25, 35M accounts, Age groups, Credit scores, Device information, Email addresses, Government issued IDs, Income levels
Travel Oklahoma: 2020-12-17, 637K accounts, Age groups, Dates of birth, Email addresses, Genders, Names, Physical addresses
Ralph Lauren: 2026-06-11, 140K accounts, Age groups, Email addresses, Genders, Names, Phone numbers
The Fly on the Wall: 2017-12-31, 84K accounts, Age groups, Credit cards, Email addresses, Genders, Names, Passwords
Muslim Directory: 2014-02-17, 38K accounts, Age groups, Email addresses, Employers, Names, Passwords, Phone numbers
The Club Penguin Experience: 2024-10-14, 6.3K accounts, Age groups, Email addresses, Password hints, Passwords, Usernames
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.