---
title: "APOIA.se user-registration data incident"
description: "Evidence-backed account of APOIA.se user-registration data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/apoia-se-user-registration-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/apoia-se-user-registration-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/apoia-se-user-registration-data-incident-2025/stix.json"
---

# APOIA.se user-registration data incident

APOIA.se told affected users that a point vulnerability permitted access to a database limited to registration data. APOIA.se confirmed exposure of names, emails, and internal identifiers; HIBP separately characterized a broader incident corpus that also listed physical addresses.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Platform, registration database, and internal identifiers
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[APOIA.se](https://apoia.se/) told affected users that a point vulnerability permitted access to a database limited to registration data. [2](#source-2)

## Impact

APOIA.se confirmed exposure of names, emails, and internal identifiers; HIBP separately characterized a broader incident corpus that also listed physical addresses. [1](#source-1) [2](#source-2)

Documented data types include:

- Names — Full names identified in APOIA.se's customer email and names listed for the HIBP corpus. [1](#source-1) [2](#source-2)
- Usernames and account identifiers — Internal APOIA.se identifiers that the company said do not reveal supported campaigns, interests, or preferences without access to protected internal systems. [1](#source-1) [2](#source-2)
- Contact information — Email addresses identified in APOIA.se's customer email; HIBP also lists email and physical addresses for its corpus. [1](#source-1) [2](#source-2)

A cited record reports 450,764 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a company-confirmed number of affected users or people; as of 2026-02-16). [1](#source-1) [2](#source-2)

APOIA.se said passwords remained encrypted and inaccessible and were not exposed. [2](#source-2)

APOIA.se said payment information, including card numbers and security codes, was not exposed. [2](#source-2)

## Timeline

### December 16, 2025 — Documented event

HIBP BreachDate and date associated with third-party exposure alerts. Canaltech reported that the relationship between the December forum data and APOIA.se's confirmed vulnerability had not been established. [1](#source-1) [2](#source-2)

### January 6, 2026 — Discovery

Date APOIA.se said it confirmed the flaw. [2](#source-2)

### January 10, 2026 — Public disclosure

Date Canaltech reviewed APOIA.se's email to affected users. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

A point vulnerability in APOIA.se's system allowed access to a database limited to registration data. [2](#source-2)

APOIA.se said its security teams corrected the vulnerability before the situation was confirmed, preventing further access. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

APOIA.se said it contained the vulnerability, reinforced security controls, and contacted the competent authorities. APOIA.se emailed affected users about the vulnerability, exposed registration fields, non-exposed sensitive information, remediation, and authority notification. APOIA.se said the list of projects a user supported was not accessed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/apoia-se-user-registration-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### APOIA.se breach record

advisory · Have I Been Pwned · Feb 16, 2026

<https://haveibeenpwned.com/api/v3/breach/APOIAse>

<a id="source-2"></a>

### APOIA.se confirma vazamento de dados de usuários; veja como se proteger

news · Canaltech · Jan 10, 2026

<https://canaltech.com.br/seguranca/apoiase-confirma-vazamento-de-dados-de-usuarios-veja-como-se-proteger/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   APOIA.se registration-data exposure: 450,764 record
2. **Affected Organization · 100% confidence · current**  
   December 2025 APOIA.se registration-data incident: APOIA.se
3. **Disclosed At · 100% confidence · current**  
   January 2026 APOIA.se customer notification: 2026-01-10
4. **Resulted In · 100% confidence · current**  
   December 2025 APOIA.se registration-data incident: APOIA.se said it contained the vulnerability, reinforced security controls, and contacted the competent authorities.
5. **Discovered At · 100% confidence · current**  
   December 2025 APOIA.se registration-data incident: 2026-01-06
6. **Resulted In · 80% confidence · current**  
   December 2025 APOIA.se registration-data incident: APOIA.se registration-data exposure
7. **Resulted In · 100% confidence · current**  
   December 2025 APOIA.se registration-data incident: A point vulnerability in APOIA.se's system allowed access to a database limited to registration data.
8. **Resulted In · 100% confidence · current**  
   December 2025 APOIA.se registration-data incident: APOIA.se said its security teams corrected the vulnerability before the situation was confirmed, preventing further access.
9. **Occurred At · 80% confidence · current**  
   December 2025 APOIA.se registration-data incident: 2025-12-16
10. **Resulted In · 100% confidence · current**  
   APOIA.se registration-data exposure: APOIA.se said passwords remained encrypted and inaccessible and were not exposed.
11. **Exposed Data Category · 100% confidence · current**  
   APOIA.se registration-data exposure: Names
12. **Resulted In · 100% confidence · current**  
   January 2026 APOIA.se customer notification: APOIA.se emailed affected users about the vulnerability, exposed registration fields, non-exposed sensitive information, remediation, and authority notification.
13. **Resulted In · 100% confidence · current**  
   APOIA.se registration-data exposure: APOIA.se said the list of projects a user supported was not accessed.
14. **Exposed Data Category · 100% confidence · current**  
   APOIA.se registration-data exposure: Usernames and account identifiers
15. **Exposed Data Category · 90% confidence · current**  
   APOIA.se registration-data exposure: Contact information
16. **Resulted In · 100% confidence · current**  
   APOIA.se registration-data exposure: APOIA.se said payment information, including card numbers and security codes, was not exposed.

</details>
