Summary
- Environment: Platform and information
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Addi warned that personal information may have been compromised; HIBP separately characterized a verified incident corpus and its data classes. [2]
Documented data types include:
- Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [1]
- IP addresses — IP addresses listed for the HIBP incident corpus. [1]
- Purchase history — Purchases listed for the HIBP incident corpus. [1]
- Government-issued identifiers — Government-issued IDs listed for the HIBP incident corpus; the canonical record does not infer a specific document type. [1]
- Demographic information — Age groups listed for the HIBP incident corpus. [1]
- Names — Names listed for the HIBP incident corpus. [1]
- Credit and income information — Credit scores, income levels, and socioeconomic levels listed for the HIBP incident corpus. [1]
- Device information — Device information listed for the HIBP incident corpus. [1]
- Precise geolocation data — Latitude and longitude pairs listed for the HIBP incident corpus. [1]
A cited record reports 34,532,941 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a confirmed number of affected Addi customers or people; as of 2026-05-18). [2]
Addi shared the information as a precaution and advised customers to distrust unexpected requests for personal data, passwords, or verification codes and to use official reporting channels. [2]
Timeline
Discovery
Organization-reported detection date relayed in Addi’s customer communication.
[2]Public disclosure
Date El Colombiano published its review of Addi’s customer communication; the communication’s exact send time was not established.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Unauthorized access to part of the information on Addi’s platform. [2]
Addi said passwords, accounts, and access information were not compromised. [2]
Addi warned that some users’ personal information may have been compromised during the incident. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Addi said its application and platform were fully operational and users could continue purchasing and paying. Addi said its technical team and security specialists contained and corrected the situation, strengthened security, and maintained active monitoring. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
