Addi unauthorized-access data incident

Addi told customers that it detected unauthorized access to part of the information on its platform on March 25, 2026. Addi warned that personal information may have been compromised; HIBP separately characterized a verified incident corpus and its data classes.

Last modified

Summary

  • Environment: Platform and information
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Addi told customers that it detected unauthorized access to part of the information on its platform on March 25, 2026. [2]

Impact

Addi warned that personal information may have been compromised; HIBP separately characterized a verified incident corpus and its data classes. [2]

Documented data types include:

  • Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [1]
  • IP addresses — IP addresses listed for the HIBP incident corpus. [1]
  • Purchase history — Purchases listed for the HIBP incident corpus. [1]
  • Government-issued identifiers — Government-issued IDs listed for the HIBP incident corpus; the canonical record does not infer a specific document type. [1]
  • Demographic information — Age groups listed for the HIBP incident corpus. [1]
  • Names — Names listed for the HIBP incident corpus. [1]
  • Credit and income information — Credit scores, income levels, and socioeconomic levels listed for the HIBP incident corpus. [1]
  • Device information — Device information listed for the HIBP incident corpus. [1]
  • Precise geolocation data — Latitude and longitude pairs listed for the HIBP incident corpus. [1]

A cited record reports 34,532,941 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a confirmed number of affected Addi customers or people; as of 2026-05-18). [2]

Addi shared the information as a precaution and advised customers to distrust unexpected requests for personal data, passwords, or verification codes and to use official reporting channels. [2]

Timeline

  1. Discovery

    Organization-reported detection date relayed in Addi’s customer communication.

    [2]
  2. Documented event

    Date Addi said it identified unauthorized access; also the HIBP BreachDate.

    [1][2]
  3. Public disclosure

    Date El Colombiano published its review of Addi’s customer communication; the communication’s exact send time was not established.

    [2]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Unauthorized access to part of the information on Addi’s platform. [2]

Addi said passwords, accounts, and access information were not compromised. [2]

Addi warned that some users’ personal information may have been compromised during the incident. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Addi said its application and platform were fully operational and users could continue purchasing and paying. Addi said its technical team and security specialists contained and corrected the situation, strengthened security, and maintained active monitoring. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]