Aura Data Breach: 900,000 Marketing Contacts Exposed by ShinyHunters

by Anika Shah - Technology
0 comments

Aura Data Breach Exposes Nearly 900,000 Records After Voice Phishing Attack

Identity protection provider Aura has confirmed a data breach impacting approximately 900,000 customer records, including names and email addresses. The incident stemmed from a sophisticated voice phishing (vishing) attack targeting an employee, compromising data associated with both current and former customers.

Breach Details and Scope

Aura stated that the compromised data primarily originated from a marketing tool utilized by a company it acquired in 2021. Whereas the majority of affected records consisted of names and email addresses, contact information – including home addresses and phone numbers – for fewer than 20,000 active customers and 15,000 former customers was also exposed [PCMag]. Crucially, Aura confirmed that sensitive data such as Social Security numbers, passwords, and financial information were not accessed [PCMag].

ShinyHunters Claims Responsibility

The notorious hacking group ShinyHunters claimed responsibility for the breach, advertising the stolen data on their extortion site. They alleged to have stolen 12GB of files containing personally identifiable information (PII) and internal corporate data [Netcrook]. After negotiations with Aura failed, ShinyHunters proceeded to leak the stolen files [Netcrook].

Data Already Leaked and Potential Risks

Analysis by Have I Been Pwned (HIBP) revealed that the leaked data included IP addresses and customer service notes, in addition to the previously reported information [databreach.com]. HIBP also noted that approximately 90% of the exposed email addresses had already appeared in previous data breaches [databreach.com]. Security analysts warn that the combination of leaked data – including physical addresses and phone numbers alongside email addresses – is particularly valuable for crafting convincing vishing attacks and potential identity theft [databreach.com].

Aura’s Response and Investigation

Aura has initiated an internal review, partnering with external cybersecurity experts and has notified law enforcement authorities [Rankiteo]. The company is in the process of notifying affected individuals and offering support. Aura maintains that its core sensitive data stores remain secure [Rankiteo].

Alleged Okta SSO Vulnerability

ShinyHunters alleged that the attack exploited a vulnerability in Aura’s Okta single sign-on (SSO) system, still, Aura has declined to comment on these claims [Rankiteo].

Key Takeaways

  • Approximately 900,000 records were compromised in a data breach at Aura.
  • The breach was a result of a voice phishing attack targeting an employee.
  • Sensitive data like Social Security numbers and financial information were not exposed.
  • The stolen data has been leaked by the ShinyHunters hacking group.
  • Aura is notifying affected users and conducting an investigation.

Related Posts

Leave a Comment