• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
MENUMENU
MENUMENU
  • Home
  • About
    • Contact Us
    • FlaglerLive Board of Directors
    • Comment Policy
    • Mission Statement
    • Our Values
    • Privacy Policy
  • Live Calendar
  • Submit Obituary
  • Submit an Event
  • Support FlaglerLive
  • Advertise on FlaglerLive (386) 503-3808
  • Search Results

FlaglerLive

No Bull, no Fluff, No Smudges

MENUMENU
  • Flagler
    • Flagler County Commission
    • Beverly Beach
    • Economic Development Council
    • Flagler History
    • Mondex/Daytona North
    • The Hammock
    • Tourist Development Council
  • Palm Coast
    • Palm Coast City Council
    • Palm Coast Crime
  • Bunnell
    • Bunnell City Commission
    • Bunnell Crime
  • Flagler Beach
    • Flagler Beach City Commission
    • Flagler Beach Crime
  • Cops/Courts
    • Circuit & County Court
    • Florida Supreme Court
    • Federal Courts
    • Flagler 911
    • Fire House
    • Flagler County Sheriff
    • Flagler Jail Bookings
    • Traffic Accidents
  • Rights & Liberties
    • Fourth Amendment
    • First Amendment
    • Privacy
    • Second Amendment
    • Seventh Amendment
    • Sixth Amendment
    • Sunshine Law
    • Third Amendment
    • Religion & Beliefs
    • Human Rights
    • Immigration
    • Labor Rights
    • 14th Amendment
    • Civil Rights
  • Schools
    • Adult Education
    • Belle Terre Elementary
    • Buddy Taylor Middle
    • Bunnell Elementary
    • Charter Schools
    • Daytona State College
    • Flagler County School Board
    • Flagler Palm Coast High School
    • Higher Education
    • Imagine School
    • Indian Trails Middle
    • Matanzas High School
    • Old Kings Elementary
    • Rymfire Elementary
    • Stetson University
    • Wadsworth Elementary
    • University of Florida/Florida State
  • Economy
    • Jobs & Unemployment
    • Business & Economy
    • Development & Sprawl
    • Leisure & Tourism
    • Local Business
    • Local Media
    • Real Estate & Development
    • Taxes
  • Commentary
    • The Conversation
    • Pierre Tristam
    • Diane Roberts
    • Guest Columns
    • Byblos
    • Editor's Blog
  • Culture
    • African American Cultural Society
    • Arts in Palm Coast & Flagler
    • Books
    • City Repertory Theatre
    • Flagler Auditorium
    • Flagler Playhouse
    • Flagler Youth Orchestra
    • Jacksonville Symphony Orchestra
    • Palm Coast Arts Foundation
    • Special Events
  • Elections 2024
    • Amendments and Referendums
    • Presidential Election
    • Campaign Finance
    • City Elections
    • Congressional
    • Constitutionals
    • Courts
    • Governor
    • Polls
    • Voting Rights
  • Florida
    • Federal Politics
    • Florida History
    • Florida Legislature
    • Florida Legislature
    • Ron DeSantis
  • Health & Society
    • Flagler County Health Department
    • Ask the Doctor Column
    • Health Care
    • Health Care Business
    • Covid-19
    • Children and Families
    • Medicaid and Medicare
    • Mental Health
    • Poverty
    • Violence
  • All Else
    • Daily Briefing
    • Americana
    • Obituaries
    • News Briefs
    • Weather and Climate
    • Wildlife

‘No Breach’ Says CEO of Exactis, Palm Coast Company at Heart of Reported Massive Data Leak of Personal Information

June 29, 2018 | FlaglerLive | 5 Comments

Exactis's nondescript office in the Katz building on Florida Park Drive in Palm Coast. (© FlaglerLive)
Exactis’s nondescript office in the Katz building on Florida Park Drive in Palm Coast. (© FlaglerLive)

Exactis is an obscure data aggregation company based in Palm Coast’s Katz building on Florida Park Drive. It has records on just about every American, individual or business–a total of some 340 million records. On Wednesday, Wired reported that the records had been exposed to potential theft, and were in fact accessed by a security expert who discovered the vulnerability–and contacted Exactis’s CEO in Palm Coast.


In a long interview with FlaglerLive today, Steve Hardigree, Exactis’s CEO and a resident of the Hammock for the past 10 years, said there had been no “leak” or “breach,” in the sense that no data had been stolen. “According to log reports there was no breach,” Hardigree said. “We’ve been working diligently not only with the folks who discovered the leak, but we’ve been working with the Attorney general’s office,” among others.

“We’re considered enemy number one by the cyber community,” he said. “I don’t think it’s going to amount to anything because there’s not been any damage done to anyone.”

Exactis is working with Vinny Troia, the cyber security consultant who discovered the breach while conducting a search that led to exposed IP addresses through which he was able to access Exactis’s mass of data–what Hardigree described as a “port” that in essence had been unknowingly left open on the company’s cloud-based servers, which are provided by UrNode and hosted by GoDaddy. A firewall was immediately restored. Troia, according to Hardigree, will provide an independent review that will result in an eventual press release on the company’s website informing the public that there’s no risk of data being released.

Nevertheless what Hardigree described as the “firestorm” that followed Wired’s report resulted in a torrent of calls to him, requests from individuals and businesses to be removed from the database or, in the case of two or three partners, to have their logos removed from Exactus’s website. Hardigree got at least one death threat–a man who told him he’d shoot him on sight if he saw him–and is worried for the safety of his wife and children, one of whom graduated from Matanzas High School, with another set to graduate from Flagler Palm Coast High next year.

And the fallout from the crisis, which has been reported across the nation, may spell the end of Hardigree’s business, which he says was generating $350,000 a year in sales. “Unfortunately the damage is done to my company,” Hardigree said. “I’m not sure if there’s a way for us to come back. I was getting ready to start hiring here in Palm Coast. I’m not sure we’re going to have the resources because I’m starting to lose clients.”

Also, he faces a lawsuit filed in federal District Court in Florida by the Chicago-based DiCello Levitt and Case law firm, on behalf of a complainant in Pinellas County. “The data compromised by Exactis’ breach is even more severe than financial information, such as credit card or bank account numbers,” Adam Levitt, one of the lawyers in the case, is quoted as saying in media reports. (Levitt did not respond to a call and an email.) “Exactis’ database included email and postal addresses, whether a person had a pet, whether the person is a smoker and a number of other personal interests. This type of information is frequently used by hackers to steal identities and break into your accounts.”

Hardigree said he’s had conversations with Levitt and is hoping the lawsuit won’t go forward. “There’s really nothing here. In a class action there’s got to be damages,” Hardigree said. He claims there were no damages, and insisted repeatedly that what information was aggregated did not involve personally-identifying data such as social security numbers or driver’s license numbers, but publicly available records including emails, addresses, phone numbers, Facebook and other social media profiles. 

The line has been blurring however between strictly personally identifying information and aggregated information that, however public, can amount to equally identifying data, especially when overlaid with other information that includes age, family status, gender, geography–all publicly available but no less personally identifying.

That, in effect, is one of the services Exactis provides, particularly, for example, through a portal called Autoappend. There, a user can input his or her own customer data and generate a whole set of overlay data based on what Exactis can provide. Exactis explains it this way: “Append consumer contact data, such as email address, phone number and postal address, household financial data and demographic insights as well as business email addresses to your customer or prospect lists with match rates as high as 85%.”

According to Wired, Troia found data on almost every random person he searched. Wired’s Andy Greenberg wrote of the breach lucidly, in laymen’s terms: “While it’s far from clear if any criminal or malicious hackers have accessed the database, Troia says it would have been easy enough for them to find. Troia himself spotted the database while using the search tool Shodan, which allows researchers to scan for all manner of internet-connected devices. He says he’d been curious about the security of ElasticSearch, a popular type of database that’s designed to be easily queried over the internet using just the command line. So he simply used Shodan to search for all ElasticSearch databases visible on publicly accessible servers with American IP addresses. That returned about 7,000 results. As Troia combed through them, he quickly found the Exactis database, unprotected by any firewall.” (Marketwatch has a good explanation of what Exactis does and what consumers can do in response to data breaches.)

Exactis’s Palm Coast office is at the end of a non-descript corridor on the third floor of the Katz building on Florida Park Drive, also known as the SunTrust building–past offices for WholisticKneads Massage Therapy, Preferred Shipping, Flagler County NAACP and New Construction Concepts. No one answered the door. Hardigree said he hadn’t been to the office because of the threats. He described it as “three small desks in there and my laptop.” He has three partners in three different states, all working from home offices. The Palm Coast operation alone has a separate office.

As of Friday afternoon, Hardigree said he was still analyzing the fallout from the controversy but would soon provide additional details on the breach, posting the company’s findings on its website–which was the subject of a brute-force attack on Thursday.

Support FlaglerLive's End of Year Fundraiser
Thank you readers for getting us to--and past--our year-end fund-raising goal yet again. It’s a bracing way to mark our 15th year at FlaglerLive. Our donors are just a fraction of the 25,000 readers who seek us out for the best-reported, most timely, trustworthy, and independent local news site anywhere, without paywall. FlaglerLive is free. Fighting misinformation and keeping democracy in the sunshine 365/7/24 isn’t free. Take a brief moment, become a champion of fearless, enlightening journalism. Any amount helps. We’re a 501(c)(3) non-profit news organization. Donations are tax deductible.  
You may donate openly or anonymously.
We like Zeffy (no fees), but if you prefer to use PayPal, click here.

Reader Interactions

Comments

  1. RP says

    June 29, 2018 at 3:24 pm

    What a huge fail. Wait till I file my GPDR lawsuit :)

  2. Technical Junkie says

    June 29, 2018 at 3:29 pm

    Data mining companies are the scum of the internet. They gather up all sorts of information on us on a daily basis only to sell them to anyone who wants to market us. They are the core of what’s wrong with the internet today. Forgive me for not feeling an ounce of sadness for Mr. Hammock Dunes in his fancy house.

    Not only is he constantly gathering information on millions of people without giving anyone the opportunity to OPT OUT but he isn’t properly securing this information from those who could use it to harm millions of people as well. Please throw this man in jail.

  3. Stretchem says

    June 29, 2018 at 5:18 pm

    Hardigree is a pathetic hack with zero knowledge of what he’s doing, zero business ethics, incapable of effectively managing employees and vendors. “Port” opened? Ha! That’s the least exposed.

    Unfortunately, the data aggregation business has no real compliance and oversight, thus allowing losers like Hardigree to profiteer off of other people’s privacy.

    Europe has jumped on the issue with GDPR (https://www.eugdpr.org), but the likelihood of the US doing anything with the current capitalist pigs in control is slim to none.

  4. Richard says

    June 30, 2018 at 6:24 am

    People in California think that Data Collection and what it means to their privacy protection is VERY important and may even affect the rest of the country. More news at 5!

  5. JRZ says

    November 16, 2018 at 12:52 am

    Poor Hardigree. He is scum, and now everyone who reads knows it.. Since he has no problem with “sensitive personal exposure” I say we strip him naked and put him in stocks and pillory, in various very public places.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Conner Bosch law attorneys lawyers offices palm coast flagler county
  • grand living realty
  • politis matovina attorneys for justice personal injury law auto truck accidents

Primary Sidebar

  • grand living realty
  • politis matovina attorneys for justice personal injury law auto truck accidents

Recent Comments

  • Blake Neal on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • Janene Neal on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • Deborah Coffey on DeSantis Stands By Attorney General’s Defiance of Federal Court Order Halting Cops’ Arrests of Migrants
  • Laurel on The Daily Cartoon and Live Briefing: Tuesday, May 6, 2025
  • Ed P on The Daily Cartoon and Live Briefing: Friday, May 9, 2025
  • Jay Tomm on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • Judy Scardano on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • John on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • William Hughey on Mayor Mike Norris’s Lawsuit Against Palm Coast Has Merit. And Limits.
  • Robert Hougham on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • JC on Mayor Mike Norris’s Lawsuit Against Palm Coast Has Merit. And Limits.
  • Gina on Metronet Contractor Punctures Flagler Beach Water Main for 2nd Time in 24 Hours, Again Affecting City’s Water
  • Laurel on Metronet Contractor Punctures Flagler Beach Water Main for 2nd Time in 24 Hours, Again Affecting City’s Water
  • Laurel on The Daily Cartoon and Live Briefing: Friday, May 9, 2025
  • Laurel on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents
  • T on Without a Single Question, Bunnell Board Approves Rezoning of Nearly 1,900 Acres to Industrial, Outraging Residents

Log in