Aura's March 2026 breach exposed roughly 900,000 records after a vishing call compromised an employee account. About 20,000 current and 15,000 former customers were affected, alongside inherited Circle Media Labs marketing contacts. Names, addresses, phones, emails and IP addresses leaked — no Social Security numbers or passwords. Here are the six steps to take now.
What Happened
Aura is a Burlington, Massachusetts consumer digital safety company selling identity theft protection and credit monitoring. In March 2026 it disclosed that an unauthorized third party had accessed an employee account through a targeted voice phishing (vishing) attack and pulled roughly 900,000 records from a marketing database. ShinyHunters — the crew behind the Salesloft Drift wave that hit TransUnion in 2025 — claimed responsibility.
The breached database traces back to Circle Media Labs, parent of the parental-control device Circle, which Aura acquired in 2021 — legacy sales and marketing systems, not the core identity protection product. Who was in it: roughly 20,000 current Aura customers, about 15,000 former customers, and a much larger pool of inherited Circle marketing contacts.
The Irony Isn't Lost on Anyone
Aura sells identity theft protection and got compromised by a phone call. The incident is a case study in why marketing data should be walled off from customer security systems, and why databases inherited through acquisitions are a favourite target for social-engineering crews like ShinyHunters.
What Data Was Stolen
Based on Aura's disclosure and subsequent reporting, the exposed fields include:
- Full name
- Home address
- Telephone number
- Email address
- IP address
- Customer service comments and notes
- Additional marketing-database fields (varies by record)
Aura has stated the following were not exposed:
- Social Security numbers
- Account passwords
- Financial account information
- Credit reports or credit-monitoring data
Those fields alone will not open a credit line, but they are more than enough for targeted phishing, robocalls, SIM-swap attempts and harassment. The customer-service notes are the unusual part, since free-text support comments sometimes contain details customers volunteered. ShinyHunters merges every breach into one searchable identity graph, so your Aura record will be cross-referenced against older exposures.
Who Is Affected
You are likely in the affected group if any of these are true:
- You were an active Aura customer whose marketing profile was migrated from Circle systems
- You ever signed up for Circle (the parental control device or app), before or after the 2021 acquisition
- You entered your email into a Circle or Aura marketing form, quiz or promotional page
- You cancelled an Aura subscription at any point — roughly 15,000 former customers were in the dataset
- You received a notification letter from Aura in March or April 2026
- Your email address appears on haveibeenpwned.com tagged with the Aura breach
Step 1: Confirm Your Exposure
Go to haveibeenpwned.com and enter every email address you have ever used. If the Aura breach appears, your record is confirmed exposed. Screenshot the result — useful evidence if downstream fraud shows up later.
Free PrivacyOn Scan
Have I Been Pwned tells you that you leaked. A free PrivacyOn scan tells you what an attacker can do with it — which data broker sites currently publish the same name and address combination that leaked from Aura. Those broker listings are exactly what turns a leaked email into a complete identity profile.
Step 2: Watch for Aura-Specific Phishing and Vishing
The attack that caused this breach was a vishing call. That same playbook now points at you, and the attackers have your customer-service history to sound convincing with.
Red Flags to Watch For
Legitimate Aura communications will never ask you to confirm a password, read a verification code aloud, or move money. Hang up on any inbound call claiming to be Aura's fraud team, breach-response team or refund department. Call back using the number in your account dashboard — never the number that called you, and never a number read out during the call.
Step 3: Rotate the Password You Used on Aura or Circle
Aura says passwords were not exposed, but rotating one now tied to a leaked email costs nothing. If you reused it anywhere else, change it there too — credential stuffing against a fresh breach list is automated and cheap. Use a password manager going forward.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Enable Multi-Factor Authentication Everywhere
Turn on MFA — app-based (Authy, Google Authenticator) or a hardware security key — on your email, banking and the Aura account itself. Avoid SMS-based MFA where you have a choice: SIM-swap attacks become trivial once your phone number is on a breach list, and yours now is.
Step 5: Freeze Your Credit at All Five Bureaus
The Aura breach did not expose SSNs, but your leaked email and phone will be combined with data from other 2026 breaches to assemble a fraud-ready profile. A credit freeze is free, reversible, and blocks new accounts being opened in your name.
- Equifax: equifax.com/personal/credit-report-services
- Experian: experian.com/freeze
- TransUnion: transunion.com/credit-freeze
Then freeze the two lesser-known bureaus criminals routinely exploit because most people forget them: Innovis (innovis.com) and NCTUE (nctue.com).
Step 6: Remove Your Data From People-Search Sites
The breach handed attackers your name, address, phone number and email. What makes those dangerous is what they connect to next — the address history on Spokeo, the relatives on BeenVerified, the neighbours on Whitepages. Removing those listings is the one step that shrinks your exposure rather than just monitoring it.
PrivacyOn continuously removes your information from 100+ data broker sites, monitors the dark web for your exposed details, and covers up to 5 family members on one plan from $8.33/month. It also carries no inherited marketing databases from past acquisitions — which is precisely the surface that failed at Aura.
Should You Cancel Aura?
An honest read: the breach hit a legacy marketing system, not the core product, and Aura's disclosure timeline was reasonable. If the bundle still fits your needs, staying is defensible. If your priority is dedicated data broker removal — and you would rather not pay a vendor that was itself just breached — alternatives like PrivacyOn are the cleaner swap.
Frequently Asked Questions
How do I know if I was affected by the Aura data breach?
Check every email address you own on haveibeenpwned.com — the Aura dataset is indexed there. Aura also mailed written notifications in March and April 2026. If you were a Circle Media Labs customer before or after the 2021 acquisition, or cancelled an Aura subscription at any point, assume you may be affected even before a letter arrives: roughly 15,000 former customers were in the dataset.
Were passwords or Social Security numbers stolen in the Aura breach?
No. Aura confirmed that Social Security numbers, account passwords and financial account information were not exposed. The breached data was limited to marketing-database fields — name, address, phone, email, IP address and customer-service notes. Rotating any password you used on Aura or Circle is still a sensible precaution, since the email tied to it is now public.
How many people were affected by the Aura breach?
Roughly 900,000 records in total. Of those, about 20,000 were current Aura customers and around 15,000 were former customers; the remainder were marketing contacts inherited from Circle Media Labs, many of whom never had an Aura account at all. That is why people who have never heard of Aura are finding themselves in the dataset.
Is there a better alternative to Aura after this breach?
Yes — for data broker removal and privacy monitoring, PrivacyOn is the strongest swap. It removes you from 100+ broker sites, includes dark web monitoring, and covers up to 5 family members from $8.33/month, which undercuts Aura's individual pricing. It also holds no legacy marketing databases from prior acquisitions — the exact surface that was breached at Aura. Run a free scan before you decide.
Can I sue Aura over the breach?
Consumer protection law firms opened class action investigations shortly after the March 2026 disclosure. Whether a class is certified and whether it produces a settlement takes months to years. Watch your notification letter for opt-in details, and contact a consumer protection attorney if you have direct evidence of downstream fraud.
How did ShinyHunters get into Aura?
Through a targeted voice phishing (vishing) call against an Aura employee, tricking them into handing over credentials or approving a malicious authentication prompt. It is the same social-engineering pattern behind the 2025 Snowflake and Salesloft Drift waves: phone the help desk, impersonate a real employee, reset MFA. It works even against well-hardened infrastructure, which is why no vendor can promise you it will not happen to them.
Protect Yourself Long-Term With PrivacyOn
The Aura breach is a reminder that any company holding your data — including one that sells identity protection — can be compromised. The durable defense is layered: unique passwords, hardware-key MFA, a permanent freeze at all five bureaus, and continuous removal of your data from the broker sites that turn a leaked email into a full identity profile. PrivacyOn handles that last layer — 100+ sites, 24/7 dark web monitoring, up to 5 family members from $8.33/month. Start with a free scan — no credit card required.