The Aura data breach, disclosed in March 2026, exposed approximately 900,000 records after a voice phishing (vishing) attack tricked an employee into handing over account credentials. The stolen data lived in a legacy marketing database from Aura's 2021 acquisition of Circle Media Labs — not the core identity protection product — and hit fewer than 20,000 active Aura customers. No Social Security numbers, passwords, or financial data were exposed, but names, addresses, phone numbers, and emails were. If you received a notification letter, here are the exact steps to lock down your identity in 2026.
What Happened
Aura is a Burlington, Massachusetts-based consumer digital safety company that sells identity theft protection, credit monitoring, and online security services. In March 2026 the company disclosed that an unauthorized third party had accessed an employee account through a targeted voice phishing attack and pulled roughly 900,000 records from a marketing database. The cybercriminal group ShinyHunters — the same crew behind the Salesloft Drift wave that took down TransUnion and 700+ other Salesforce customers in 2025 — claimed responsibility.
The breached database traces back to Circle Media Labs (parent of the parental-control app Circle), which Aura acquired in 2021. Aura confirmed that the affected data was primarily associated with Circle's legacy sales and marketing systems, and that fewer than 20,000 active Aura customers were among those exposed. The bulk of the 900k records belonged to former Circle prospects and customers whose data Aura inherited when it bought the company.
The Irony Isn't Lost on Anyone
Aura sells identity theft protection — and got popped by a phone call. The incident is a case study in why identity protection services should keep marketing data separate from customer security systems, and why acquired-company databases are a top target for social-engineering crews like ShinyHunters.
What Data Was Stolen
According to Aura's public disclosure and Have I Been Pwned's indexed dataset, the exposed fields include:
- Full name
- Home address
- Telephone number
- Email address
- Additional marketing-database fields (varies by record)
Aura has stated that the following data was not exposed:
- Social Security numbers
- Account passwords
- Financial account information
- Credit reports or credit-monitoring data
The stolen fields on their own are not enough to open credit accounts, but they are more than enough to fuel targeted phishing, robocalls, SIM-swap attempts, and physical harassment. Because ShinyHunters combines every breach into a single searchable identity graph, your Aura record will be cross-referenced with your TransUnion, Snowflake-era, and older breach exposures.
Who Is Affected
You are likely in the affected group if any of the following are true:
- You were an active Aura customer whose marketing profile was migrated from Circle systems
- You ever signed up for Circle (the parental control device or app) before or after Aura's 2021 acquisition
- You entered your email into a Circle or Aura marketing form, quiz, or promotional page in the past several years
- You received a notification letter from Aura in March or April 2026 referencing the incident
- Your email address shows up on haveibeenpwned.com tagged with the Aura breach
Step 1: Confirm Your Exposure
Go to haveibeenpwned.com and enter every email address you have ever used. If the Aura breach appears in the results, your record is confirmed exposed. Screenshot the results for your records.
Free PrivacyOn Scan
Beyond Have I Been Pwned, run a free PrivacyOn scan to see which data broker sites currently expose the same name and address combination that leaked in the Aura breach. Those broker listings are what let attackers turn the leaked email into a complete identity profile.
Step 2: Watch for Aura-Specific Phishing and Vishing
The attack that caused the breach was itself a vishing call. That same playbook now targets you. Expect an uptick in phone calls, emails, and texts referencing your Aura or Circle account.
Red Flags to Watch For
Legitimate Aura communications will never ask you to confirm your password, read a verification code out loud, or move money. Any inbound call claiming to be from Aura's fraud team, breach-response team, or refund department should be hung up on. Call Aura back at the number in your account dashboard, not the number you were called from.
Step 3: Rotate the Password You Used on Aura or Circle
Aura says passwords were not exposed, but it costs nothing to rotate a password that has now been tied to a leaked email address. If you reused the same password on any other service, change it there too. Use a password manager to generate a unique password per site going forward.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Enable Multi-Factor Authentication Everywhere
Turn on MFA — preferably app-based (Authy, Google Authenticator) or a hardware security key — on your email, banking, and Aura account itself. Skip SMS-based MFA where you can; SIM-swap attacks are trivial once your phone number is on a breach list.
Step 5: Freeze Your Credit at All Three Bureaus
Even though the Aura breach did not expose SSNs, your leaked email and phone number will be combined with data from other 2026 breaches (the first half of 2026 saw 471 million breach notices) to build a fraud-ready profile. A credit freeze is free and blocks new credit accounts from being opened in your name.
- Equifax: equifax.com/personal/credit-report-services
- Experian: experian.com/freeze
- TransUnion: transunion.com/credit-freeze
Also freeze at the two lesser-known bureaus criminals often exploit: Innovis (innovis.com) and NCTUE (nctue.com).
Step 6: Remove Your Data From People-Search Sites
The Aura breach handed attackers your name, address, phone number, and email. What makes those fields dangerous is what they connect to next — the address history on Spokeo, the relatives on BeenVerified, the neighbors on Whitepages. Removing yourself from those public people-search databases raises the cost of building a full attack kit around your leaked email.
PrivacyOn continuously removes your information from 100+ data broker sites, monitors the dark web for your exposed details, and covers up to 5 family members on a single plan starting at $8.33/month. Because PrivacyOn is not built on an acquired marketing database, it does not carry the legacy-surface risk that took Aura down.
Should You Cancel Aura?
That is a personal call, but here is the honest read: the March 2026 breach hit a legacy marketing system rather than the core identity protection product, and Aura's response and disclosure timeline were reasonable. If Aura's bundled protection (VPN, antivirus, password manager, credit monitoring, broker removal) still fits your needs, staying is defensible. If your priority is narrow, dedicated data broker removal — and you would rather not pay a vendor that was itself just breached — Aura alternatives like PrivacyOn are the safer swap.
Frequently Asked Questions
How do I know if I was affected by the Aura data breach?
Check your email address on haveibeenpwned.com — the Aura breach dataset has been indexed there. Aura also mailed written notifications to affected individuals in March and April 2026. If you were a Circle Media Labs customer before or after Aura's 2021 acquisition, assume you may be affected even before the letter arrives.
Were passwords or Social Security numbers stolen?
No. Aura confirmed that Social Security numbers, account passwords, and financial account information were not exposed. The breached data was limited to marketing-database fields like name, address, phone number, and email. That said, rotating any password you used on Aura or Circle is still a sensible precaution.
Should I trust Aura going forward?
The breach was contained to a legacy marketing database from the 2021 Circle Media Labs acquisition and did not touch the core identity protection systems that hold customer credit, credit-monitoring, or SSN data. If Aura's bundled feature set still fits your needs, staying is defensible. If you want narrower, dedicated protection with a smaller attack surface, PrivacyOn is the safest swap.
Is there a better alternative to Aura after this breach?
Yes — for pure data broker removal and privacy monitoring, PrivacyOn is the strongest swap. It covers 100+ broker sites, includes dark web monitoring, and covers up to 5 family members from $8.33/month — cheaper than Aura's $12/month individual plan. Crucially, PrivacyOn does not carry any legacy marketing databases from prior acquisitions, which is exactly the surface that was breached at Aura. Run a free scan before you decide.
Can I sue Aura over the breach?
Class action investigations were opened by consumer protection law firms shortly after the March 2026 disclosure. Whether a class is certified and whether it results in a settlement will take months to years. Watch your notification letter for opt-in details, or contact a consumer protection attorney if you have direct evidence of downstream fraud.
How did ShinyHunters get in?
ShinyHunters used a targeted voice phishing (vishing) attack against an Aura employee, tricking them into handing over credentials or approving a malicious authentication request. It's the same social-engineering pattern that fueled the 2025 Snowflake and Salesloft Drift waves — attackers phone the help desk, impersonate a real employee, and reset MFA. It works even when the underlying infrastructure is well hardened.
Protect Yourself Long-Term With PrivacyOn
The Aura breach is a reminder that any company holding your personal data — including one that sells identity protection — can be compromised. The best long-term defense is layered: unique passwords per service, hardware-key MFA on your most sensitive accounts, a permanent credit freeze at all five bureaus, and continuous removal of your data from the broker sites that turn a leaked email into a complete identity profile. PrivacyOn handles the broker-removal layer for you — 100+ sites, 24/7 dark web monitoring, and up to 5 family members on a single plan from $8.33/month. Start with a free scan to see exactly what's exposed today — no credit card required.