惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
人人都是产品经理
人人都是产品经理
L
LINUX DO - 最新话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
Arctic Wolf
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Jina AI
Jina AI
The Cloudflare Blog
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
NISL@THU
NISL@THU
G
GRAHAM CLULEY
Project Zero
Project Zero
博客园_首页
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Spread Privacy
Spread Privacy
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
Latest news
Latest news
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tor Project blog
S
Securelist
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
IT之家
IT之家
Google DeepMind News
Google DeepMind News
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Last Watchdog
The Last Watchdog
T
Tenable Blog
宝玉的分享
宝玉的分享
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
量子位
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic

Consumer Insights

South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025 European Space Agency's cybersecurity in freefall as yet another breach exposes spacecraft and mission data European Space Agency Confirms New Data Breach; Classified Info May Have Been Stolen Rainbow Six Siege Servers Offline After Massive Breach Floods Accounts with Billions of R6 Credits 21,000 Nissan Customers Exposed After Third-Party Server Breach Spotify Catalog Scraped, 300TB Music and Metadata Dumped via Torrent University of Sydney Confirms Data Breach Affecting Thousands Leroy Merlin Breach Alert: French Customers Notified After Cyberattack Exposes Personal Data CodeRED Emergency Alerts Disrupted Across US After Ransomware Breach
Aura data breach exposes 900,000 records after phishing attack
Vlad CONSTANTINESCU · 2026-03-19 · via Consumer Insights

Aura says a phishing attack led to a data breach affecting nearly 900,000 records, including names, emails, addresses and phone numbers.

Phishing attack led to major data breach

Aura has confirmed a data breach that exposed nearly 900,000 records after an employee was targeted by a voice phishing (vishing) attack. The company said the incident involved a marketing platform inherited through a 2021 acquisition, not its core account systems.

According to the company’s disclosure, the exposed data included full names, email addresses, home addresses and phone numbers. About 20,000 current customers and 15,000 former customers were affected, and the broader dataset also contained a much larger pool of marketing contacts, the company said.

ShinyHunters leak claim puts Aura breach in the spotlight

The disclosure followed claims by ShinyHunters, which listed Aura on its extortion site and said it had stolen 12GB files containing customer information and internal corporate data. Data breach monitoring services later reported a leaked CRM dataset containing more than 900,000 email records.

Aura has confirmed the breach itself but has not validated every claim made by the threat group. Public reporting also notes unresolved questions around the attackers’ broader allegations, including separate claims tied to single sign-on access.

What data was exposed and what was not

Aura said Social Security Numbers (SSNs), passwords, and financial information were not exposed. That limits the immediate risk of direct account takeover, but the stolen contact data could still be used in follow-up phishing, impersonation or fraud campaigns.

Have I Been Pwned has already added the breach to its service, and breach trackers say the leaked data may include IP addresses and customer service comments. One monitoring report said most exposed email addresses had already appeared in earlier breaches.

Notifications, investigation and a familiar M&A risk

Aura said it is working with external cybersecurity experts, has notified law enforcement and plans to notify affected individuals directly. That puts the case squarely in the now-familiar pattern of phishing-led compromise followed by extortion and public leakage.

The incident also spotlights a persistent acquisition risk, demonstrating how inherited tools and datasets can expand exposure years after a deal closes.

Why digital identity monitoring matters after a breach

Even if the most sensitive financial details are not exposed, leaked contact information can still create real risk. Names, email addresses, home addresses, phone numbers and service-related notes can give scammers a trove of precious data to craft convincing phishing messages, impersonation attempts and fraud schemes to catch victims off guard.

In these situations, solutions like Bitdefender Digital Identity Protection can come in handy by helping users monitor whether their personal information appears in known breaches or on dubious corners of the public or Dark Web. For people concerned about how exposed data could be reused over time, this kind of oversight can make it easier to spot risks early and react before a follow-up scam turns into a bigger problem.