Summary
- Environment: Platform, registration database, and internal identifiers
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
APOIA.se confirmed exposure of names, emails, and internal identifiers; HIBP separately characterized a broader incident corpus that also listed physical addresses. [1][2]
Documented data types include:
- Names — Full names identified in APOIA.se’s customer email and names listed for the HIBP corpus. [1][2]
- Usernames and account identifiers — Internal APOIA.se identifiers that the company said do not reveal supported campaigns, interests, or preferences without access to protected internal systems. [1][2]
- Contact information — Email addresses identified in APOIA.se’s customer email; HIBP also lists email and physical addresses for its corpus. [1][2]
A cited record reports 450,764 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a company-confirmed number of affected users or people; as of 2026-02-16). [1][2]
APOIA.se said passwords remained encrypted and inaccessible and were not exposed. [2]
APOIA.se said payment information, including card numbers and security codes, was not exposed. [2]
Timeline
Threat Group & Attack Vector
A point vulnerability in APOIA.se’s system allowed access to a database limited to registration data. [2]
APOIA.se said its security teams corrected the vulnerability before the situation was confirmed, preventing further access. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
APOIA.se said it contained the vulnerability, reinforced security controls, and contacted the competent authorities. APOIA.se emailed affected users about the vulnerability, exposed registration fields, non-exposed sensitive information, remediation, and authority notification. APOIA.se said the list of projects a user supported was not accessed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
