Risk level: medium. Can you change it: no. Found in 44 breaches in this directory.
What this data is
The name of the company or organisation you work for, collected by professional networks, job sites, insurers, lenders and many signup forms.
The risk on its own
Your employer is often listed on public profiles, so the fact itself is rarely secret. The risk is that it tells criminals where to aim workplace scams. It can also reveal where you are during the working day.
The risk combined with other data
With your name and email, criminals can impersonate your HR team, IT desk or manager far more credibly. It supports payroll diversion, fake benefits enrolment and phishing for your work login, which can lead into your employer's systems. For people escaping harassment or abuse, it also shows where they can be found.
How criminals use it
A fake HR email about a pay review or benefits update asks you to log in to a lookalike company portal.
Someone posing as you asks payroll to send your salary to a new bank account.
A caller claiming to be the IT help desk asks you to approve a sign-in prompt on your phone.
A stalker or abusive former partner uses your employer to find where you spend your day.
What to do now
Tell your IT or security team your work details were in a breach so they can watch for targeting.
Approve only sign-in prompts you started yourself, and report unexpected ones to IT.
Ask payroll to verify any change to your bank details in person or by phone.
If you have a personal safety concern, hide your employer on public profiles and ask your workplace not to confirm your employment to callers.
Open HR and payroll systems from your own bookmarks rather than links in work themed emails.
Frequently asked questions
My employer is on LinkedIn anyway. Why does the leak matter?
Because the breach ties it to your email address and other details, which lets criminals send targeted scams instead of guessing.
What is MFA fatigue?
An attacker who has your password sends repeated sign-in approval prompts, hoping you tap approve to make them stop. Never approve a prompt you did not trigger.
Should I tell my employer?
Yes, if the breach included your work email or any work login. It helps them block attacks that use your details.
Breaches that exposed this data
Verifications.io: 2019-02-25, 763M accounts, Dates of birth, Email addresses, Employers, Genders, Geographic locations, IP addresses
Unverified Data Source: 2021-01-26, 11M accounts, Bank account numbers, Credit status information, Dates of birth, Email addresses, Employers, Health insurance information
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.