Aura Data Breach Exposes 900,000 Customer Records via Phishing Attack

Aura Data Breach Exposes 900,000 Customer Records via Phishing Attack

First seen 19 Mar 2026, 11:27 UTC GbhackersFeeds2.FeedburnerGizmodoScworldAura 51.8

Article Content

Browse articles
ThreatCluster

Aura, an identity protection company, confirmed a data breach affecting nearly 900,000 customer records due to a voice phishing attack that compromised an employee's credentials. The breach involved data from a marketing tool acquired by Aura in 2021, with the threat group ShinyHunters claiming responsibility and stating they stole 12GB of files. The exposed information includes names, email addresses, physical addresses, and phone numbers for approximately 20,000 current and 15,000 former customers. However, Aura reported that sensitive data such as Social Security Numbers, passwords, and financial information were not accessed. The Have I Been Pwned service indicated that 90% of the exposed email addresses were already known from previous incidents. Aura is conducting an internal review and has notified law enforcement, with affected individuals set to receive personalized notifications.

Key Points: • Aura confirmed a breach affecting 900,000 records due to a voice phishing attack. • The exposed data includes names, email addresses, and phone numbers, but no sensitive financial data. • ShinyHunters claimed responsibility for the breach, stealing 12GB of files.

Timeline

2021-01-01
Aura acquires marketing tool linked to the data breach
2026-03-19
Aura confirms data breach affecting 900,000 records
2026-03-19
ShinyHunters claims responsibility for the breach