---
title: "Addi unauthorized-access data incident"
description: "Evidence-backed account of Addi unauthorized-access data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/addi-unauthorized-access-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/addi-unauthorized-access-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/addi-unauthorized-access-data-incident-2026/stix.json"
---

# Addi unauthorized-access data incident

Addi told customers that it detected unauthorized access to part of the information on its platform on March 25, 2026. Addi warned that personal information may have been compromised; HIBP separately characterized a verified incident corpus and its data classes.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Platform and information
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Addi](https://addi.com/) told customers that it detected unauthorized access to part of the information on its platform on March 25, 2026. [2](#source-2)

## Impact

Addi warned that personal information may have been compromised; HIBP separately characterized a verified incident corpus and its data classes. [2](#source-2)

Documented data types include:

- Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [1](#source-1)
- IP addresses — IP addresses listed for the HIBP incident corpus. [1](#source-1)
- Purchase history — Purchases listed for the HIBP incident corpus. [1](#source-1)
- Government-issued identifiers — Government-issued IDs listed for the HIBP incident corpus; the canonical record does not infer a specific document type. [1](#source-1)
- Demographic information — Age groups listed for the HIBP incident corpus. [1](#source-1)
- Names — Names listed for the HIBP incident corpus. [1](#source-1)
- Credit and income information — Credit scores, income levels, and socioeconomic levels listed for the HIBP incident corpus. [1](#source-1)
- Device information — Device information listed for the HIBP incident corpus. [1](#source-1)
- Precise geolocation data — Latitude and longitude pairs listed for the HIBP incident corpus. [1](#source-1)

A cited record reports 34,532,941 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a confirmed number of affected Addi customers or people; as of 2026-05-18). [2](#source-2)

Addi shared the information as a precaution and advised customers to distrust unexpected requests for personal data, passwords, or verification codes and to use official reporting channels. [2](#source-2)

## Timeline

### March 25, 2026 — Discovery

Organization-reported detection date relayed in Addi's customer communication. [2](#source-2)

### March 25, 2026 — Documented event

Date Addi said it identified unauthorized access; also the HIBP BreachDate. [1](#source-1) [2](#source-2)

### April 1, 2026 — Public disclosure

Date El Colombiano published its review of Addi's customer communication; the communication's exact send time was not established. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Unauthorized access to part of the information on Addi's platform. [2](#source-2)

Addi said passwords, accounts, and access information were not compromised. [2](#source-2)

Addi warned that some users' personal information may have been compromised during the incident. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Addi said its application and platform were fully operational and users could continue purchasing and paying. Addi said its technical team and security specialists contained and corrected the situation, strengthened security, and maintained active monitoring. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/addi-unauthorized-access-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Addi breach record

advisory · Have I Been Pwned · May 18, 2026

<https://haveibeenpwned.com/api/v3/breach/ADDI>

<a id="source-2"></a>

### Pilas: Addi también advierte sobre posible filtración de datos de sus usuarios tras ciberataque

news · El Colombiano · Apr 1, 2026

<https://www.elcolombiano.com/negocios/addi-ciberataque-hackeo-datos-filtracion-datos-usuarios-BB35164432>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Contact information
2. **Resulted In · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: Addi said its application and platform were fully operational and users could continue purchasing and paying.
3. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: IP addresses
4. **Exposed Record Count · 100% confidence · current**  
   Addi personal-information exposure: 34,532,941 record
5. **Resulted In · 90% confidence · current**  
   March 2026 Addi unauthorized-access incident: Addi personal-information exposure
6. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Purchase history
7. **Disclosed At · 90% confidence · current**  
   April 2026 Addi customer communication: 2026-04-01
8. **Discovered At · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: 2026-03-25
9. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Government-issued identifiers
10. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Demographic information
11. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Names
12. **Resulted In · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: Unauthorized access to part of the information on Addi's platform.
13. **Resulted In · 100% confidence · current**  
   April 2026 Addi customer communication: Addi shared the information as a precaution and advised customers to distrust unexpected requests for personal data, passwords, or verification codes and to use official reporting channels.
14. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Credit and income information
15. **Resulted In · 100% confidence · current**  
   Addi personal-information exposure: Addi said passwords, accounts, and access information were not compromised.
16. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Device information
17. **Resulted In · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: Addi said its technical team and security specialists contained and corrected the situation, strengthened security, and maintained active monitoring.
18. **Resulted In · 100% confidence · current**  
   Addi personal-information exposure: Addi warned that some users' personal information may have been compromised during the incident.
19. **Occurred At · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: 2026-03-25
20. **Exposed Data Category · 90% confidence · current**  
   Addi personal-information exposure: Precise geolocation data
21. **Affected Organization · 100% confidence · current**  
   March 2026 Addi unauthorized-access incident: Addi

</details>
