Job titles leaked: what it means and what to do

Risk level: low. Can you change it: no. Found in 52 breaches in this directory.

What this data is

Your role or position, such as accounts payable officer, nurse or IT administrator, recorded by professional networks, business software, event registrations and marketing lists.

The risk on its own

Low risk on its own. A job title does not open accounts or prove identity, and many people publish it on professional profiles. It says what you do, not how to reach you.

The risk combined with other data

With your name, employer and work email it becomes a targeting tool. People in finance, payroll and IT roles are singled out because they can move money or grant system access. Scammers also use your title to make fake invoices, vendor messages and IT alerts look routine.

How criminals use it

  • An accounts payable officer receives a fake supplier invoice with changed bank details.
  • A system administrator is sent a fake security alert asking them to log in to a lookalike admin console.
  • A payroll officer receives an email that appears to come from an employee asking to change their bank details.

What to do now

  1. If your role involves payments, follow a callback rule for any new or changed bank details.
  2. If your role involves system access, use phishing resistant sign-in such as passkeys or security keys where your employer supports them.
  3. Review what your professional profile shows to people outside your network.
  4. Report targeted phishing to your IT or security team so they can warn others in similar roles.

Frequently asked questions

Is my job title private information?

Not really. It becomes a risk when paired with your work email, because it tells criminals what you can approve or access.

Why are finance and IT staff targeted?

Because they can move money or grant access to systems. One successful message to them is worth far more to a criminal than random phishing.

What is phishing resistant sign-in?

Passkeys and hardware security keys that only work on the real website, so a fake login page cannot capture anything usable.

Breaches that exposed this data

  • Verifications.io: 2019-02-25, 763M accounts, Dates of birth, Email addresses, Employers, Genders, Geographic locations, IP addresses
  • Data Enrichment Exposure From PDL Customer: 2019-10-16, 622M accounts, Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers
  • Apollo: 2018-07-23, 126M accounts, Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers
  • LinkedIn Scraped Data (2021): 2021-04-08, 126M accounts, Education levels, Email addresses, Genders, Geographic locations, Job titles, Names
  • DemandScience by Pure Incubation: 2024-02-28, 122M accounts, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses
  • B2B USA Businesses: 2017-07-18, 105M accounts, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses
  • You've Been Scraped: 2018-10-05, 66M accounts, Email addresses, Employers, Geographic locations, Job titles, Names, Social media profiles
  • Modern Business Solutions: 2016-10-08, 59M accounts, Dates of birth, Email addresses, Genders, IP addresses, Job titles, Names
  • Data & Leads: 2018-11-14, 44M accounts, Email addresses, Employers, IP addresses, Job titles, Names, Phone numbers
  • NetProspex: 2016-09-01, 34M accounts, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses
  • Public Business Data: 2021-08-19, 28M accounts, Dates of birth, Email addresses, Job titles, Names, Phone numbers, Physical addresses
  • Mate1.com: 2016-02-29, 27M accounts, Astrological signs, Dates of birth, Drinking habits, Drug habits, Education levels, Email addresses

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.