Unverified claim — On June 23, 2026, a threat actor advertised a database allegedly containing more than 110 million Notion user records on a darkweb marketplace. The listing claims to include email addresses, password hashes, and IP addresses. As of publication, Notion had not confirmed any breach, unauthorized access, or infrastructure incident. This post covers what is known and what to do while verification is pending.
What the Actor Claims
The listing, flagged by threat-intelligence accounts DailyDarkWeb and MonThreat on June 23, 2026, alleges:
- 110 million+ unique user records
- Email addresses
- Password hashes
- IP addresses
- Comprehensive account metadata
The actor has not published a verified data sample that has been independently authenticated. No credible security researcher had confirmed the data's authenticity at time of writing.
Is This Real?
This listing is unverified. Darkweb marketplaces frequently carry recycled, fabricated, or compiled-from-previous-breaches datasets marketed as fresh. The 110M figure would represent a very large share of Notion's reported user base. Key uncertainties include:
- Whether the data is from a new Notion breach, an old breach, or a compilation
- Whether password hashes, if real, are recent or historical
- Whether Notion's infrastructure was actually compromised
Notion is a widely used collaboration and productivity platform with hundreds of millions of accounts. A confirmed breach of this scale would be among the largest of 2026. Until Notion confirms or independent researchers validate a sample, treat this as an unconfirmed claim.
What to Do Now (Even Unconfirmed)
- Change your Notion password immediately — use a unique, strong password not used elsewhere.
- Enable two-factor authentication (2FA) on your Notion account — use an authenticator app, not SMS where possible.
- Check Have I Been Pwned (haveibeenpwned.com) — your email may appear from other breaches too.
- Watch for phishing targeting Notion users — actors with your email + Notion account knowledge may craft convincing lures.
- If you reused your Notion password elsewhere, change it on every site immediately.
Note on a Separate Notion Incident
This is distinct from a separate 2026 matter involving Notion in EU consumer litigation concerning AI training data use practices. That case does not involve a credential or account-data breach.
We will update this post when Notion issues a statement or independent verification is published.
Full breach record: breachhistory.com/notion/notion-110m-claim2026
Sources: DailyDarkWeb (June 23, 2026) | MonThreat (June 23, 2026)