Skip to main content

PUBLIC STATEMENT

Alleged Senzing Data Breach - Public Statement and FAQ

Statement

In May 2026, a false claim was posted online that Senzing suffered a data breach exposing sensitive personal information. We want to address this directly.

The claim is false and the source of the claim is a known scam operator.

No Senzing systems were compromised, and no customer or production data was exposed. It originated with VECERT Analyzer, an account with a track record of publicizing sensationalistic breach claims that don’t hold up. Earlier this year, the same account publicized a false claim that 1.5 million Binance accounts had been breached. Binance’s former CEO publicly called that claim fake, noting the sample data was just plaintext passwords taken from malware-infected devices, not the kind of data VECERT described (see Incrypted’s coverage).

The dataset referenced in these posts appears to be Senzing’s own publicly available demo and test data, known as our “truth sets.” This is synthetic, non-production data that we publish openly on GitHub so developers and customers can test entity resolution results, run tutorials, and evaluate our software. It was never private, it does not belong to any real customers, and it does not contain real identities.

We looked into this directly rather than ignore it, and we’ve reached out to the sites republishing the claim to request corrections. We’re sharing this statement publicly so anyone researching the claim finds accurate information.

Our Policy on Data Protection and Privacy: Not storing personally identifiable information (PII) has been an intentional design choice for Senzing from the beginning. Our entity resolution software runs inside each customer’s own environment, so their data, including PII, stays there rather than on our systems, an approach that matters more every year as data becomes harder to protect.

Questions can be directed to [email protected].

FAQ

Is this a real data breach?

No it is not. No Senzing systems were accessed without authorization, and no customer data was involved. Our software also runs inside each customer’s own environment, so we don’t hold customer entity data on our own systems to begin with.

Where did this data actually come from?

It matches Senzing’s publicly downloadable demo dataset, the “truth sets” on our GitHub, which we distribute openly for testing and tutorials. It contains synthetic, fictional records, not real people’s information.

Why does this show up when I search “Senzing security breach”?

An IT security content site republished an unverified forum claim, and Google’s AI Overview picked up that article as a source. We’ve requested a correction and are working to get accurate information indexed in its place.

Was any customer information involved?

No. The referenced dataset is not connected to any customer account, system, or production environment. Because our software is deployed inside each customer’s own environment rather than on Senzing’s own servers, we don’t hold customer entity data in the first place.

What should I do if I saw the original claim and I’m a Senzing customer?

No action is needed. If you have specific concerns, reach out to [email protected] and we’ll walk through it with you directly.