Aura (identity management company)
2026 breach of American company
From Wikipedia, the free encyclopedia
Aura is a digital security company that suffered a significant data breach in 2026 that compromised approximately 900,000 records. The 2026 Aura data breach refers to a security incident disclosed in March 2026 affecting the Burlington, Massachusetts-based consumer digital safety company that sells identity theft protection, credit monitoring, and online security services. An unauthorized third party gained access to an employee account via a targeted voice phishing attack and accessed approximately 900,000 records, including names, home addresses, telephone numbers, email addresses, and additional data from a marketing database.[1][2][3] The cybercriminal group ShinyHunters claimed responsibility. The incident drew widespread attention partly due to its irony: a company selling identity protection had itself been breached.[4][5][6][7]
Background
Aura is a consumer-facing cybersecurity company based in Burlington, Massachusetts, that provides identity theft protection, fraud monitoring, credit monitoring, anti-virus and device security services.[8][9]
Founder and SEC charges
The company was founded by CEO Hari Ravichandran in 2017 under the name "iSubscribed."[8] Ravichandran had been charged by the SEC with over-stating the number of subscribers at his prior company, Endurance International Group, while selling his own shares into the market.[10][11] Endurance paid $8 million to settle the complaint, while Ravichandran additionally agreed to personally pay $1.38 million to the SEC. Neither admitted wrongdoing.[12]
Acquisitions and CFPB charges
In 2019, iSubscribed acquired the company "Intersections Inc", which had previously been sued by the Consumer Financial Protection Bureau.[citation needed] The CFPB alleged that Intersections charged consumers for credit reports that it knew it could not deliver.[13] Intersections settled by signing a consent order in which it paid a penalty of approximately $1.2 million, plus restitution to consumers.[14] The Intersections product is now known as Aura's Identity Guard product line. The company rebranded as "Aura" after the merger.[15]
In 2021, Aura acquired Circle Media Labs, Inc. ("Circle"), a company whose sales and marketing database was central to the 2026 data breach. Following the acquisition, Aura retained some of Circle's marketing tools and associated contact lists.[16]
2026 data breach
An Aura employee was targeted by a highly targeted voice phishing (vishing) attack. The attack enabled an unauthorized party to gain access to the employee's account for approximately one hour before Aura's security team removed them. Threat intelligence services logged ShinyHunters claiming the Aura breach on or around March 16, 2026, including the appearance of Aura data on the group's dark web leak site.[17]
According to Aura's investigation and confirmed by Have I Been Pwned (HIBP), approximately 900,000 records were stolen.[2]
The hackers
ShinyHunters is a prolific cybercriminal extortion group associated with a series of high-profile data theft campaigns.[18][19][20]
Response
Security researchers noted that the combination of names, email addresses, home addresses, and phone numbers created meaningful risk for targeted phishing and vishing attacks. Attackers with this data could craft highly credible social engineering attempts against affected individuals — a particular concern given that many Aura customers sought the service precisely for protection against such threats.[21][22]
The Aura incident occurred during a concentrated period of ShinyHunters activity in early 2026.[23] A point of significant public confusion arose from the coincidental naming of ShinyHunters' broader March 2026 campaign: the group dubbed their large-scale Salesforce attack the "Salesforce Aura Campaign" — a reference to the Salesforce Aura framework, not the company Aura. In that campaign, running since September 2025 but only publicly disclosed in March 2026, ShinyHunters exploited misconfigured Salesforce Experience Cloud guest user profiles across an estimated 300–400 organizations. The campaign exploited the /s/sfsites/aura API endpoint on misconfigured Salesforce Experience Cloud instances and used a weaponized version of Mandiant's open-source AuraInspector tool, which had been released in January 2026 to help administrators detect misconfigurations.[24][25][26]