Identity-Protection Firm Aura Discloses Breach of 900,000 Records

9 sources·Updated 9 Sep 2026·How we verify

Aura, a Burlington, Massachusetts-based identity-theft and fraud-monitoring company, confirmed in mid-March 2026 that an unauthorized party accessed roughly 900,000 contact records after tricking an employee with a phone-based phishing attack. Aura says the intrusion lasted about one hour before its security team cut off access, and that the exposed data came primarily from a marketing database the company inherited through a 2021 acquisition rather than from its core identity-protection product. The company has notified affected individuals and denies that Social Security numbers, passwords, or financial data were involved.

On this article you will find

What happened, and when

According to Aura’s own account, an employee was targeted by a voice-phishing (“vishing”) call that convinced them to hand over access to their corporate account. The unauthorized party used that access for approximately one hour before Aura’s security team detected and revoked it. Aura issued its first public statement on the incident around March 17, 2026, and Have I Been Pwned added the breach to its database on March 18, 2026, listing 903,100 unique email addresses. Aura followed up on March 26, 2026, with a more detailed update explaining the scope and origin of the exposed data.

The cybercriminal extortion group ShinyHunters claimed credit for the intrusion and, according to CyberInsider’s reporting, posted roughly 12GB of files to its extortion site. Separately, BleepingComputer reported that ShinyHunters described a different technique entirely: mass-scanning misconfigured Salesforce Experience Cloud sites using a modified version of a security tool called AuraInspector (a naming coincidence unrelated to the company), exploiting excessive “guest user” permissions to pull data from Salesforce CRM objects without authentication. Salesforce has said the underlying issue is customer misconfiguration, not a platform vulnerability, and that this technique was used against roughly 100 organizations in a campaign dating back to September 2025. Aura’s own statements do not mention Salesforce, Experience Cloud, or OAuth abuse at all — its narrative is built entirely around a single employee’s compromised corporate account. That gap between the attacker’s claimed method and the victim’s disclosed method has not been publicly reconciled.

What data was exposed

Aura and Have I Been Pwned both describe the exposed data as: full names, email addresses, home addresses, phone numbers, IP addresses, and customer-service comments. Aura says the “vast majority” of the roughly 900,000 records came from a marketing tool operated by Circle Media Labs, the company Aura acquired in 2021, meaning most of the exposed contacts were not necessarily Aura customers at all — they were people in an older marketing database. Aura’s own security update states that fewer than 20,000 active Aura customers and fewer than 15,000 former customers had their contact information accessed. Aura has repeatedly emphasized what was not taken: Social Security numbers, account passwords, financial or payment information, and data inside the actual Aura product were, according to the company, unaffected. Aura’s update also notes that an internal review found roughly 90% of the exposed email addresses had already appeared in previous, unrelated data breaches — a detail Aura used to argue the incremental risk to most affected people is limited.

How it was discovered and disclosed

Aura’s account is that its own security team identified and terminated the unauthorized access within about an hour of the phishing attack succeeding, then activated an incident-response plan, brought in outside cybersecurity and legal specialists, and notified law enforcement. Public disclosure followed within days: Aura’s press release went up around March 17–19, 2026, and Have I Been Pwned logged the breach on March 18. Separately, the law firm Migliaccio & Rathod LLP announced on March 12, 2026 — several days before Aura’s own public statement — that it was investigating a “possible Salesforce Aura Data Breach” after data reportedly surfaced on dark-web monitoring sites. That timing gap between apparent dark-web visibility and Aura’s own disclosure is unexplained in the sources reviewed.

Aura’s response and remediation

Aura’s public statements describe a standard incident-response sequence: revoke the compromised access, engage outside cybersecurity and legal experts, notify law enforcement, and begin notifying affected individuals directly. The company has stated flatly that “Aura’s product was not hacked” and that customer data stored within the Aura app itself was not touched. Aura also pointed affected users to its Privacy Request Center for data-deletion requests, which it says are processed within 30 days, and published a support line and email for questions. Notably, in its press release, Aura’s leadership offered a direct acknowledgment of failure: “While we make every effort to ensure that our customers have peace of mind about their safety, we recognize that in this case we did not live up to that standard.”

Who is actually affected — and who isn’t

This is one of the more confusing aspects of the disclosure, and worth stating precisely because the “900,000” figure gets used loosely in secondary coverage. The roughly 900,000 number refers to unique email addresses across an old marketing database, not 900,000 Aura customers. Aura’s own figures put the number of current customers affected at under 20,000, plus under 15,000 former customers — together well under 40,000 people with any real relationship to Aura, out of the larger marketing-list total. Anyone unsure of their status can check their email against Have I Been Pwned’s Aura entry, though HIBP’s listing reflects the full marketing-database population rather than confirming customer status specifically.

What affected users should do

Security researchers and Aura itself converge on similar guidance here. Because names, addresses, phone numbers, and email addresses were exposed — even without passwords or financial data — the primary follow-on risk is targeted phishing, vishing, and social-engineering attempts that use this real personal information to appear credible. Recommended steps include: treating unsolicited calls or emails referencing personal details with skepticism, especially any that claim to be from Aura itself; enabling multi-factor authentication on important accounts; watching for unusual account or credit activity even though Aura says financial data wasn’t taken; and, for anyone who wants their contact information removed from Aura’s marketing systems, using Aura’s Privacy Request Center. Because Aura states passwords were not exposed, a mandatory password reset was not part of its guidance, though changing passwords tied to the exposed email address is a reasonable precaution regardless.

The bigger picture: when identity-protection companies get breached

An identity-protection company getting breached carries a particular irony, and it is not unprecedented — LifeLock, Equifax’s post-breach identity-monitoring arm, and other players in this space have faced their own security incidents and regulatory scrutiny over the years. Aura itself was built partly through acquisition: it bought Intersections Inc. in 2019 (whose product became Identity Guard) and Circle Media Labs in 2021, and it was the Circle Media marketing database — not Aura’s original infrastructure — that held most of the exposed records here. That pattern, where breached data traces back to an acquired company’s legacy systems rather than the parent’s core product, is a recurring feature of breaches at firms built through consolidation, and it complicates simple statements about how “secure” the acquiring company’s own systems are.

What Smashology verified

Claim Evidence reviewed Assessment
The breach exposed contact data for roughly 900,000 people Aura’s press release and March 26 update; Have I Been Pwned listing (903,100 unique emails) Confirmed by Aura’s own statements and corroborated by Have I Been Pwned
Social Security numbers and passwords were stolen Aura’s official statements explicitly deny this; no reviewed source contradicts Aura on this point Not substantiated — all available evidence says this data type was not exposed
The intrusion came through a misconfigured Salesforce Experience Cloud instance ShinyHunters’ claims as reported by BleepingComputer and Help Net Security describe this method; Aura’s own statements describe only an employee vishing attack and never mention Salesforce Disputed/unconfirmed — attacker’s claimed method and Aura’s disclosed method do not match in the sources reviewed
Nearly all 900,000 affected people were current Aura customers Aura’s own update states fewer than 20,000 active and fewer than 15,000 former customers were affected; most records came from an acquired marketing database False as commonly stated — the large majority of exposed records were not tied to active customers
Aura has been sued in a class-action lawsuit over the breach Migliaccio & Rathod LLP announced an active investigation on March 12, 2026; no confirmed filed complaint was found in the sources reviewed Premature — an investigation has been publicly announced; no filed lawsuit was confirmed at time of research

Evidence limits and unresolved questions

  • Aura’s account (a single employee’s vishing-compromised corporate account) and ShinyHunters’ claimed method (mass exploitation of misconfigured Salesforce Experience Cloud sites) have not been reconciled in any source reviewed — it is unclear whether both describe the same incident or whether reporting has conflated two separate things.
  • A law firm’s breach investigation was publicly announced on March 12, 2026, citing dark-web monitoring sites — several days before Aura’s own public disclosure around March 17–19 — and no source reviewed explains that gap.
  • Figures vary slightly by source and by unit of measurement (“900,000 records” vs. “903,100 unique email addresses” vs. “under 35,000 actual customers”), and no single authoritative accounting reconciles all three.
  • No dedicated coverage from Krebs on Security or TechCrunch was located at the time of this research, limiting independent security-community scrutiny beyond the trade outlets cited below.
  • No confirmed regulatory action (state attorney general notice, FTC inquiry, or SEC filing) specific to this breach was found in the sources reviewed, though Aura says law enforcement was notified.

Sources

Method note: This article was compiled by cross-referencing Aura’s own published statements against independent security-trade reporting and the Have I Been Pwned breach database. Where Aura’s account and third-party or attacker claims diverged — notably on the technical method of intrusion — both versions are presented explicitly rather than reconciled, and that divergence is flagged as an open question rather than resolved by assumption. Figures are attributed to their originating source rather than presented as a single verified total, because the sources reviewed did not agree on a single unit of measurement.

Edin Pula

Edin Pula is the editor responsible for reviewing and publishing content at Smashology Media. He oversees sourcing, fact-checking, corrections, and editorial standards across coverage of internet culture, technology, entertainment, news, and crime.

Enjoyed this story? Share it with your friends!

Leave a Reply

Your email address will not be published. Required fields are marked *

Comments are reviewed before publication. Keep the discussion factual and respectful.

Smashology

Fact-checked explainers of viral claims, internet culture, and practical technology.