Identity protection company Aura, based in Burlington, Massachusetts, has confirmed a data breach. An attacker used a voice phishing (vishing) call to get into an employee's account and took about 900,000 records from a marketing database. The ShinyHunters extortion group has reportedly claimed the attack. On timing: several reports say Aura disclosed the breach in March 2026, and CtrlAltNod gives the date as March 18, 2026. Articles dated August and September 2026 are follow-up coverage, not a new incident. The breach is about six months old, but it is still relevant because ShinyHunters has kept using the same social engineering approach against other companies through the summer. None of the sources available for this brief is a primary Aura statement or regulator filing. Every detail below comes from secondary reporting and is attributed.
What Happened
All the accounts tell the same basic story. An Aura employee was targeted by a phone call and handed over access to their account. CtrlAltNod, Morning Overview and Cybermaniacs (citing TechRadar) all report that the attacker held that access for about one hour before Aura's security team detected it and shut it down. Morning Overview, citing Aura's incident notice, says no malware, software exploit or brute-force attack was involved. The phone call was the whole intrusion.
The database that was hit came from a company Aura bought in 2021. PrivacyOn names it as Circle Media Labs, the parent company of the Circle parental control app, and says the records sat in Circle's old sales and marketing systems. Other sources describe it only as "a company acquired in 2021."
On what happened after the theft, CtrlAltNod reports that ShinyHunters listed the data on its extortion site after ransom talks broke down. Cybermaniacs says the group also claims it took a larger set of corporate and customer data than Aura has acknowledged. No other source confirms either claim, so treat both as the attacker's account. CtrlAltNod also reports that Aura hired outside incident response experts and told law enforcement.
What Was Taken
Volume: Every Aura-specific source puts the total at about 900,000 records. The number of people whose more detailed data was exposed is reported differently:
- CtrlAltNod: fewer than 35,000 customers had more sensitive data exposed.
- Morning Overview (citing Aura's statement): about 20,000 current and 15,000 former customers. That adds up to roughly 35,000, which matches CtrlAltNod.
- PrivacyOn: fewer than 20,000 active Aura customers. This appears to count only current subscribers.
The most likely reading is that about 35,000 current and former customers were affected, of whom about 20,000 are current subscribers. The rest of the 900,000 records are marketing contacts, such as former Circle prospects and customers.
Data types: Reports differ on how much sensitive data was involved:
- CtrlAltNod and Tom's Guide (via Cybermaniacs): mostly names and email addresses, with phone numbers and home addresses for the smaller customer group.
- PrivacyOn: names, addresses, phone numbers and emails.
- Morning Overview: the above plus customer service notes for the affected customers. Service notes are useful to an attacker preparing a convincing follow-up scam.
Not exposed, per Aura as relayed by several outlets: Social Security numbers, passwords, financial account data, or data from Aura's core monitoring platform. Morning Overview says that data is encrypted and has separate access controls from the marketing tool that was breached.
Why It Matters
The target makes the risk worse. Aura's customers already worry about identity theft. A list of those people, with names, phone numbers and service history, is ideal material for follow-up scams, such as a caller pretending to be Aura's fraud team.
Data from acquisitions is a weak spot. The records came from a marketing system Aura took over when it bought another company, not from its main product. Old systems from acquired companies often get less monitoring and weaker access controls, while employees can still reach them.
The Aura breach fits a wider ShinyHunters campaign:
- RingCentral: BleepingComputer reports the company was hit in July 2026 through what it called a "sophisticated social engineering campaign." ShinyHunters claimed 623GB of stolen data and leaked 280GB after RingCentral refused to pay. Have I Been Pwned counted 1.6 million affected accounts.
- McKesson: BleepingComputer reports the company disclosed a breach involving third-party applications on August 28, 2026, after ShinyHunters claimed 284 million patient records.
- Salesforce customers: ThreatPaper describes a campaign from mid-2025 to August 2026, tracked as UNC6040, UNC6240, UNC6395, UNC6661 and UNC6671. It combined phone phishing of admin staff, stolen OAuth tokens from third-party integrations (including roughly 760 tenants through Salesloft Drift), and misconfigured Salesforce Experience Cloud sites.
Attribution caveat: Wikipedia notes that other actors have used the ShinyHunters name without the group's approval. The April 2026 Vercel breach is one case where the group's leaders denied involvement. ShinyHunters' claim to the Aura breach is widely reported, but no source here offers independent technical confirmation. None of the sources says which platform the Aura marketing database ran on, so there is no basis for linking it to the Salesforce campaign specifically.
The Attack Technique
This was a phone scam aimed at a person, not an exploit against a system. ShinyHunters' known approach, as described by Wikipedia and ThreatPaper, is to call an employee while posing as IT support or a colleague and pressure them into giving up credentials, approving an MFA request, or authorizing a malicious app. The attacker then uses that access to pull data in bulk from business tools. One hour of access was enough to take 900,000 records, which suggests the compromised account could export large amounts of data with no rate limits or approval steps. The sources do not say whether MFA was bypassed or how the data was extracted.
What Organizations Should Do
- Make help desk identity checks harder to fake. Require callback to a number already on file, manager approval, or an in-person or video check before resetting credentials or re-enrolling MFA. Train staff that real IT will never ask them to read out a code or approve a push notification.
- Use phishing-resistant MFA. Move admin and data-access accounts to FIDO2 security keys or passkeys, which a caller cannot talk someone into handing over.
- Audit systems inherited through acquisitions. List every CRM, marketing tool and contact database that came with a purchase. Delete data you don't need, move what you keep into your main identity and logging setup, and remove access nobody uses.
- Limit and watch bulk exports. Set alerts for large exports, API queries or report downloads from SaaS tools, especially from new devices or IP addresses. Aura caught its intruder within an hour. Aim to catch exports in minutes.
- Review connected apps and OAuth tokens. Following ThreatPaper's reporting, remove unused connected apps, rotate integration tokens, require PKCE, and lock down guest-user permissions on public-facing SaaS sites.
- Warn affected customers about follow-up scams. Tell them exactly how you will and won't contact them, since stolen contact lists and service notes are used to make fake support calls more convincing.
Sources: Aura Data Breach: 900,000 Customer Records Exposed via Voice Phishing | RingCentral data breach exposed info of 1.6 million accounts | McKesson discloses breach after ShinyHunters claims patient data theft | Aura Data Breach 2026: What to Do (900K Records Exposed) PrivacyOn | A voice-phishing attack on an identity-protection firm exposed abou... | Aura Breach: Identity Protection Meets Human Risk | ShinyHunters | ShinyHunters Salesforce Data Extortion and SaaS Supply-Chain Campai...