2026 Aura — ~900K marketing contacts confirmed; ShinyHunters claimed 2M+ (Mar)
Data compromised
Names, emails, phones, addresses, IP addresses; no SSNs or passwords
Technical writeup
Identity protection company Aura was breached by ShinyHunters in March 2026. Attackers leaked over 2 million records (~12GB) after failed ransom negotiations. Included PII and internal company documents. Exposed: names, email addresses, phone numbers, physical addresses, IP addresses, customer service comments. SSNs, passwords, and financial info were not compromised. Fewer than 20K active and 15K former customers had contact info accessed. A separate voice phishing incident exposed ~900K records via Okta SSO. Aura revoked access, engaged cybersecurity specialists, and notified law enforcement.
Root cause
ShinyHunters; ransomware; failed ransom negotiations; voice phishing/Okta SSO
References
- https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/
- https://undercodenews.com/massive-data-breach-shock-shinyhunters-leak-over-2-million-aura-records-after-failed-ransom-negotiations/
- https://cyberinsider.com/identity-protection-firm-aura-suffers-data-breach-exposing-900000-records/
- https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-aura-group-inc-aura-com/