APOIA.se user-registration data incident

APOIA.se told affected users that a point vulnerability permitted access to a database limited to registration data. APOIA.se confirmed exposure of names, emails, and internal identifiers; HIBP separately characterized a broader incident corpus that also listed physical addresses.

Last modified

Summary

  • Environment: Platform, registration database, and internal identifiers
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

APOIA.se told affected users that a point vulnerability permitted access to a database limited to registration data. [2]

Impact

APOIA.se confirmed exposure of names, emails, and internal identifiers; HIBP separately characterized a broader incident corpus that also listed physical addresses. [1][2]

Documented data types include:

  • Names — Full names identified in APOIA.se’s customer email and names listed for the HIBP corpus. [1][2]
  • Usernames and account identifiers — Internal APOIA.se identifiers that the company said do not reveal supported campaigns, interests, or preferences without access to protected internal systems. [1][2]
  • Contact information — Email addresses identified in APOIA.se’s customer email; HIBP also lists email and physical addresses for its corpus. [1][2]

A cited record reports 450,764 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a company-confirmed number of affected users or people; as of 2026-02-16). [1][2]

APOIA.se said passwords remained encrypted and inaccessible and were not exposed. [2]

APOIA.se said payment information, including card numbers and security codes, was not exposed. [2]

Timeline

  1. Documented event

    HIBP BreachDate and date associated with third-party exposure alerts. Canaltech reported that the relationship between the December forum data and APOIA.se’s confirmed vulnerability had not been established.

    [1][2]
  2. Discovery

    Date APOIA.se said it confirmed the flaw.

    [2]
  3. Public disclosure

    Date Canaltech reviewed APOIA.se’s email to affected users.

    [2]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

A point vulnerability in APOIA.se’s system allowed access to a database limited to registration data. [2]

APOIA.se said its security teams corrected the vulnerability before the situation was confirmed, preventing further access. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

APOIA.se said it contained the vulnerability, reinforced security controls, and contacted the competent authorities. APOIA.se emailed affected users about the vulnerability, exposed registration fields, non-exposed sensitive information, remediation, and authority notification. APOIA.se said the list of projects a user supported was not accessed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]