WordPress VIP and Apollo.io Data Leak: How Personal Data Flows Through the Shadow Economy

Available in: 中文
2026-04-07T12:37:43.547Z·2 min read
Eden found his personal details being distributed by Apollo.io. When asked about the source, Apollo stated: "Your phone number came from Parsely, Inc (wpvip.com) one of our customers who participat...

Security researcher Terence Eden discovered that his personal phone number had been obtained by the data brokerage firm Apollo.io, which attributed the source to Parsely, Inc. (wpvip.com) — a WordPress VIP company. The case reveals how personal data flows through a shadow economy of data brokers with minimal consent or transparency.

The Discovery

Eden found his personal details being distributed by Apollo.io. When asked about the source, Apollo stated: "Your phone number came from Parsely, Inc (wpvip.com) one of our customers who participates in our customer contributor network by sharing their business contacts with the Apollo platform."

The problem: Eden had never done business with Parsely and had no reason to expect them to have his phone number, let alone share it with third parties.

The Data Trail

Parsely became part of WordPress VIP (Automattic) in 2021. When Eden contacted WordPress VIP about the GDPR violation, their investigation revealed:

The Bigger Problem

Even if the data originated from a business card or email signature, the chain of custody raises serious questions:

  1. Consent erosion — Personal data shared in one context migrates to completely unrelated uses
  2. Data broker opacity — The path from original source to final distribution is invisible to the data subject
  3. GDPR limitations — Despite regulatory frameworks, practical enforcement remains extremely difficult
  4. Corporate accountability — Companies can plausibly deny responsibility while data continues to flow

Eden's Take

"I don't care any more. I'm just so tired of shitty companies treating personal data as a commodity to be traded, sold, repackaged, and abused."

The case illustrates a fundamental tension in the modern data economy: the technical ability to aggregate and share personal information vastly outpaces the legal and ethical frameworks designed to control it.

↗ Original source · 2026-04-07T00:00:00.000Z
← Previous: AI Company Clones Musician's Voice Then Copyright-Strikes Her Own Songs on YouTubeNext: Firefox Extension Malware Deep Dive: Steganography, C2 Beacons, and Affiliate Hijacking in Plain Sight →
Comments0