Skip to content

CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies

Breach Report Multi-Region Media Intelligence / SaaS Data for Sale

CARMA Client Data Allegedly for Sale, Configurations for 3,500+ Organisations Including Government Bodies

A seller posting as 2019 is advertising what they describe as data from CARMA, a global media intelligence firm providing media monitoring, social listening, and PR measurement to more than 3,500 organisations, among them Fortune 500 companies, communications agencies, and government ministries and public sector agencies. The listing covers two tables: a contact table with names, email addresses, phone numbers, and street addresses, and a client configuration table holding account codes, country, active projects, selected industries, documents, subscription state, internal comments, and an API token field. Sample records show client accounts including a defence contractor. Price is by offer. The claim is unverified.

Organisations3,500+
Tables2
PriceBy offer
Actor2019

Post details

TargetCARMA
RegionsGlobal client base
SectorMedia intelligence / Analytics
ListingOne-time sale, crypto
Clients3,500+ organisations
DataContacts and client configs
Observed
Actor2019

!Allegedly included

  • Contact names
  • Email addresses
  • Phone numbers
  • Street addresses
  • Contact type flags
  • Client account names
  • Account codes & identifiers
  • Country
  • API tokens
  • Active project records
  • Selected industries
  • Subscription status
  • Attached documents
  • Internal account comments

Screenshot

Potential impact

The distinctive exposure is not contact details but what a media monitoring configuration reveals about its owner. Selected industries, active projects, competitor lists, and internal account comments describe what each organisation is watching and worried about, which for a government ministry or defence contractor is strategic information in its own right. The presence of an API token field is the second concern, since tokens would reach client accounts directly, though sample records carry dates several years old and any credentials of that vintage may well have been rotated. The contact table appears to hold communications and PR professionals, a natural target for approaches aimed at influencing published messaging.

iStatus

Unverified

Samples are published from both tables and the column structures are internally consistent with a platform export rather than an assembled list. Dates within the client sample cluster around 2019 and 2020, suggesting the data may be considerably older than the listing date. Dark Web Informer is not reproducing the contact routes. Named client organisations are customers of the platform, not the breached party. The same account published an unrelated database two days earlier. The claim is unverified and CARMA has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest