logo
blogtopicsabout
logo
blogtopicsabout

BrowserStack Data Leak: User Emails Exposed via Apollo.io

Apollo.ioGDPRSecurityPrivacyBrowserStackData Leak
April 6, 2026

TL;DR

  • •BrowserStack appears to be leaking user email addresses to Apollo.io.
  • •Apollo.io initially claimed the emails were derived using a 'proprietary algorithm,' then admitted they came directly from BrowserStack.
  • •BrowserStack has not responded to inquiries about the data leak.

Security researcher Terence Eden recently discovered a concerning data leak involving BrowserStack and Apollo.io. Eden, who utilizes unique email addresses for each service he signs up for to track potential breaches, found his BrowserStack-specific email address appearing in Apollo.io's database.

Initially, Apollo.io attributed the acquisition of the email address to their "proprietary algorithm" which infers emails from publicly available information and corporate email structures. Eden rightly challenged this explanation, pointing out the specificity of the leaked address, which was only used during BrowserStack registration.

Upon further questioning, Apollo.io revealed the truth: the email address originated directly from BrowserStack. They stated that BrowserStack participates in a "customer contributor network" and shares business contacts with the Apollo platform, with the data being collected on February 25, 2026.

Despite multiple attempts to contact BrowserStack regarding this data sharing practice, Eden reports receiving no response. This silence raises serious questions about BrowserStack’s data handling policies and transparency.

Possible Explanations

Eden outlines several potential explanations for how Apollo.io obtained the data:

  • Data Selling/Sharing: BrowserStack may routinely sell or share user data with third parties.
  • Third-Party Service Leak: A third-party service integrated with BrowserStack might be siphoning off user information.
  • Internal Data Exfiltration: An employee or contractor at BrowserStack could be intentionally leaking user data.

While more severe scenarios are possible, Eden suspects the issue stems from a normalization of questionable data practices.

Implications for Developers

This incident highlights several crucial points for developers and users alike:

  • Data Privacy: Be mindful of the data you share with services, and understand their privacy policies.
  • Email Aliasing: Consider using email aliasing (generating unique email addresses for each service) to track potential breaches, as Eden does.
  • Vendor Risk Management: If you're integrating third-party services like BrowserStack into your development pipeline, understand their data handling practices and potential risks.
  • GDPR & Privacy Regulations: This leak raises significant concerns regarding compliance with data privacy regulations like GDPR. Companies must be transparent about how they collect, use, and share user data.

This situation serves as a stark reminder of the importance of data security and the need for companies to prioritize user privacy. The lack of response from BrowserStack is particularly concerning and warrants further investigation.

Source:

Hacker News Best ↗