Aura confirms data breach exposing 900,000 marketing contacts
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内。首先,我需要快速浏览文章,抓住主要信息。 文章讲的是身份保护公司Aura的数据泄露事件。泄露了近90万条客户记录,包括姓名和电子邮件地址。起因是语音钓鱼攻击,导致20,000名现有客户和15,000名前客户的敏感数据被暴露。 接着,数据来自2021年收购的一家公司使用的营销工具。威胁组织ShinyHunters声称窃取了12GB的文件,包括个人身份信息和公司数据,并泄露了这些文件。 Aura强调没有泄露社保号、密码或财务信息。HIBP分析后发现,90%的电子邮件地址之前已经出现在数据库中。Aura正在与外部专家合作进行内部审查,并通知执法部门,计划向受影响者发送个性化通知。 现在需要把这些信息浓缩到100字以内。重点包括: Aura的数据泄露、原因、受影响人数、数据内容、未泄露的关键信息、HIBP的分析结果以及公司的应对措施。 可能的结构: Aura公司遭遇数据泄露,近90万客户记录被获取,涉及姓名和邮箱等信息。起因是语音钓鱼攻击导致员工账户被入侵。虽然没有泄露社保号等关键信息,但90%的邮箱之前已曝光。公司正在调查并通知执法部门。 </think> 身份保护公司Aura确认近90万客户记录被未经授权的第三方获取,涉及姓名和邮箱等信息。此次事件由针对员工的语音钓鱼攻击引发,导致2万现有客户和1.5万前客户的敏感数据外泄。虽然未泄露社保号等关键信息,但90%的邮箱地址此前已曝光于其他安全事件中。 2026-3-18 23:0:28 Author: www.bleepingcomputer.com(查看原文) 阅读量:16 收藏

Aura confirms data breach exposing 900,000 marketing contacts

Identity protection company Aura has confirmed that an authorized party gained access to nearly 900,000 customer records containing names and email addresses.

The company states that the incident was caused by a voice phishing attack targeting an employee, which exposed the sensitive data of 20,000 current and 15,000 former customers.

In a communication this week, Aura states that the data originated from a marketing tool used by a company acquired by Aura in 2021, which exposed limited information.

Aura is a consumer digital safety firm that sells identity theft protection, credit and fraud monitoring, and online security tools for phishing protection, positioning itself as an all-in-one service for online protection.

Earlier this week, the threat group ShinyHunters claimed the attack on their data extortion site, stating that they stole 12GB of files containing personally identifiable information (PII) on customers, as well as corporate data.

The threat actor leaked the stolen files, saying that the company “failed to reach an agreement with them despite all the chances and offers” they made.

Leaked Aura data on the ShinyHunters site
Leaked Aura data on the ShinyHunters site
Source: BleepingComputer

According to Aura, the compromised customer information includes full names, email addresses, home addresses, and phone numbers. The company emphasizes that Social Security Numbers (SSNs), account passwords, and financial information were not compromised.

The Have I Been Pwned (HIBP) service analyzed the leaked data and added it to its database, noting that customer service comments and IP addresses were also exposed. HIBP also stated that 90% of the email addresses exposed in this incident were already present in its database from past security incidents.

BleepingComputer has asked Aura about the discrepancy between HIBP reporting a little over 901,000 affected accounts, and the company said that their figure was accurate.

This is explained by the fact that the data collected through the marketing tool was inherited when acquiring the company in 2021. However, the database contained only 35,000 Aura customers. The company declined to comment further on ShinyHunters’ claims or the alleged Okta SSO compromise.

Currently, Aura is conducting an in-depth internal review in partnership with external cybersecurity experts and has confirmed to BleepingComputer that they have also informed law enforcement authorities.

Aura told us that it will soon send personalized notifications to all affected individuals.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/
如有侵权请联系:admin#unsafe.sh