Aura confirmed a data breach affecting nearly 900,000 records after an attacker used a voice phishing tactic against an employee to gain unauthorized access. Reporting indicates the exposed information included email addresses and, in some cases, names, phone numbers, physical addresses, IP addresses, and customer service notes. Aura said the incident did not expose Social Security numbers, passwords, or financial information.
Additional breach details indicate the compromised data was largely tied to a marketing tool associated with a previously acquired company, and that fewer than 20,000 active Aura customers were affected despite the much larger total record count. The incident is a substantive security event rather than promotional or advisory content, and the available sources align on the same breach while differing mainly in emphasis: one focuses on the social engineering intrusion vector, and another on the scope and data types exposed.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Aura said it was conducting an internal review with cybersecurity experts, had notified law enforcement, and planned to send personalized notifications to affected individuals. These actions were reported after the company confirmed the breach.
The threat group ShinyHunters claimed responsibility for the Aura intrusion and said it exfiltrated 12GB of files. This attribution was reported alongside Aura's confirmation of the breach.
Have I Been Pwned listed the Aura breach and reported that about 90% of the exposed email addresses were already present in its database from prior breaches. The listing identified 900,000 unique email addresses in the incident.
Aura said the compromised information included names, phone numbers, physical addresses, IP addresses, and customer service notes. The company stated that Social Security numbers, passwords, and financial information were not exposed.
In March 2026, Aura disclosed a data breach affecting about 900,000 records, including 900,000 unique email addresses according to Have I Been Pwned. Aura said most exposed data came from the acquired marketing tool, while fewer than 20,000 active customers were impacted.
Aura said a targeted voice phishing attack against an employee allowed an unauthorized party to gain access to company data. SC Media reported the intrusion involved compromised employee credentials.
Aura said the exposed data was primarily tied to a marketing tool from a company it acquired in 2021. This system later became the main source of the compromised records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceteiss.co.uk
Open sourcehaveibeenpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.