← Aura

2026 Aura — ~900K marketing contacts confirmed; ShinyHunters claimed 2M+ (Mar)

2026 900.0K records affected Share on X

Data compromised

Names, emails, phones, addresses, IP addresses; no SSNs or passwords

Technical writeup

Identity protection company Aura was breached by ShinyHunters in March 2026. Attackers leaked over 2 million records (~12GB) after failed ransom negotiations. Included PII and internal company documents. Exposed: names, email addresses, phone numbers, physical addresses, IP addresses, customer service comments. SSNs, passwords, and financial info were not compromised. Fewer than 20K active and 15K former customers had contact info accessed. A separate voice phishing incident exposed ~900K records via Okta SSO. Aura revoked access, engaged cybersecurity specialists, and notified law enforcement.

Root cause

ShinyHunters; ransomware; failed ransom negotiations; voice phishing/Okta SSO

References