Salutations leaked: what it means and what to do

Risk level: low. Can you change it: yes. Found in 29 breaches in this directory.

What this data is

The title used before your name, such as Mr, Mrs, Ms, Mx, Dr or Rev, stored so letters and emails can address you formally.

The risk on its own

This is a very low risk field. A title cannot identify you or unlock anything. At most it hints at gender, marital status or profession.

The risk combined with other data

With your name and contact details, a title makes scam emails sound more formal and polished. A title like Dr can mark someone as a medical professional or high earner, and Mrs may suggest marital status. It rarely changes the overall risk of a breach.

How criminals use it

  • A phishing email addresses you correctly as Dr and pretends to be from a professional registration body.
  • Mrs in a record is used to tailor scams to married or widowed women.
  • A formal salutation makes a fake invoice or legal letter look more authentic.

What to do now

  1. Do not worry about this field on its own. Check the password, email address and phone number in the same breach.
  2. Remember that a correct title does not prove an email is genuine.
  3. Choose not to provide a title on forms where it is optional.
  4. Change the account password if it was exposed or reused.

Frequently asked questions

Is it dangerous that my title leaked?

No. It is one of the least sensitive fields in a breach, and it was usually printed on every letter the company ever sent you.

Why do companies collect salutations?

Mainly so letters, bills and marketing emails can address you formally. Most forms make it optional, so you can leave it blank next time.

Can a salutation reveal personal information?

Sometimes. Titles like Mrs or Dr can hint at marital status or profession, but the risk is still low.

Breaches that exposed this data

  • Apollo: 2018-07-23, 126M accounts, Email addresses, Employers, Geographic locations, Job titles, Names, Phone numbers
  • Hot Topic: 2024-10-19, 57M accounts, Dates of birth, Email addresses, Genders, Names, Partial credit card data, Phone numbers
  • Ticketek: 2024-05-31, 18M accounts, Dates of birth, Email addresses, Genders, Names, Passwords, Salutations
  • ixigo: 2019-01-03, 17M accounts, Auth tokens, Device information, Email addresses, Genders, Names, Passwords
  • Acuity: 2020-06-18, 14M accounts, Dates of birth, Email addresses, Genders, IP addresses, Names, Phone numbers
  • Carnival: 2026-04-18, 7.5M accounts, Dates of birth, Email addresses, Genders, Geographic locations, Loyalty program details, Names
  • TAP Air Portugal: 2022-08-25, 6.1M accounts, Dates of birth, Email addresses, Genders, Names, Nationalities, Phone numbers
  • Aditya Birla Fashion and Retail: 2021-12-01, 5.5M accounts, Email addresses, Genders, Income levels, Job titles, Marital statuses, Names
  • Hathway: 2023-12-17, 4.7M accounts, Device information, Email addresses, IP addresses, Names, Passwords, Phone numbers
  • MalindoAir: 2019-03-01, 4.3M accounts, Dates of birth, Email addresses, Genders, Loyalty program details, Names, Nationalities
  • Sport 2000: 2024-04-18, 3.2M accounts, Dates of birth, Email addresses, Names, Phone numbers, Physical addresses, Purchases
  • LDLC: 2024-02-28, 1.3M accounts, Email addresses, Names, Phone numbers, Physical addresses, Salutations

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.