People search Notion data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 2 Notion-linked incidents, with headline counts up to 110M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Notion breach history matters
Notion operates in Technology (United States). Across indexed rows, recurring themes include unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — unverified darkweb listing; 110M+ user records alleged for sale (June 23)
Unverified claim — treat actor counts cautiously. Unverified darkweb listing — June 23, 2026. A threat actor advertised a dataset allegedly linked to Notion on a darkweb marketplace, claiming 110 million+ unique user records comprising email addresses, password hashes, IP addresses, and account metadata. The listing was reported by DailyDarkWeb and MonThreat on June 23, 2026. Notion had not acknowledged any breach, infrastructure incident, or unauthorized data access at catalog time. The actor-cited 110M figure is used as the unverified recordsAffected per BreachH Exposed categories include Actor-claimed records include email addresses, password hashes, IP addresses, and comprehensive account data—unverified; Notion has not confirmed any breach. BreachHistory cites approximately 110M+ affected records in this row. See the notion-110m-claim 2026 record and canonical BreachHistory entry.
2026 — EU consumer litigation alleging unlawful AI training use of user content (Reuters)
Unverified claim — treat actor counts cautiously. Reuters reported European consumer groups sued Notion alleging it processed user workspace content to train AI models without adequate lawful basis, framing privacy and consumer-protection claims rather than a criminal intrusion narrative. Exposed categories include User-generated workspace content referenced in litigation summaries and press. No attested victim count is published for this row yet. See the notion2026man7 and canonical BreachHistory entry.
Patterns and analysis
- Unverified actor or scraping claims — appears across multiple Notion catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Notion company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/notion · Latest: notion-110m-claim2026.
Sources: BreachHistory catalog (2 rows for Notion), company and regulator disclosures cited in individual breach records.