Feeds2.Feedburner Aura Data Breach Exposes 900,000 Customer Records via Phishing Attack
Article Content
- •Aura confirmed a breach affecting 900,000 records due to a voice phishing attack.
- •The exposed data includes names, email addresses, and phone numbers, but no sensitive financial data.
- •ShinyHunters claimed responsibility for the breach, stealing 12GB of files.
Aura, an identity protection company, confirmed a data breach affecting nearly 900,000 customer records due to a voice phishing attack that compromised an employee's credentials. The breach involved data from a marketing tool acquired by Aura in 2021, with the threat group ShinyHunters claiming responsibility and stating they stole 12GB of files. The exposed information includes names, email addresses, physical addresses, and phone numbers for approximately 20,000 current and 15,000 former customers. However, Aura reported that sensitive data such as Social Security Numbers, passwords, and financial information were not accessed. The Have I Been Pwned service indicated that 90% of the exposed email addresses were already known from previous incidents. Aura is conducting an internal review and has notified law enforcement, with affected individuals set to receive personalized notifications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…