Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
The incident exposed marketing-contact records, most of which came from a Circle Media Labs database maintained after Aura’s acquisition of Circle. [1][2]
Documented data types include:
- Contact information — Email addresses and, in some cases, home addresses and phone numbers. [1][2][3]
- Customer service records — Customer service records listed for the HIBP incident corpus. [1][2][3]
- IP addresses — IP addresses in some leaked records. [1][2][3]
- Names — Names, which Aura said made up most records together with email addresses. [1][2][3]
A cited record reports 20,000 individuals (Upper-bound representation of Aura’s statement that fewer than 20,000 active Aura customers were affected; not an exact count). [1][2]
A cited record reports 903,080 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a customer total; as of 2026-03-18). [1][2][3]
A cited record reports 15,000 individuals (Upper-bound representation of Aura’s statement that fewer than 15,000 former Aura customers were affected; separate from active customers and not an exact count). [1][2]
A cited record reports 900,000 records (Aura’s approximate organization-reported record count; the vast majority were names and email addresses from an acquired company’s marketing tool; as of 2026-03-19). [1][2][3]
Aura said it was notifying impacted customers and would notify affected customers and partners as appropriate while its review continued. [1][2]
Timeline
Documented event
Incident date in the HIBP corpus; Aura’s public statements establish March timing and an approximately one-hour duration but do not publish this exact event date.
[3]Public disclosure
Date Aura’s later incident article says it announced the employee phishing incident.
[1]Public disclosure
Timestamp of Aura’s updated exposure statement.
[2]Public disclosure
Publication date of Aura’s detailed incident article.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Response
Aura said it immediately terminated the unauthorized access, activated its incident-response plan, engaged external cybersecurity and legal experts, and notified law enforcement. Aura said its identity-protection application and supporting databases were not accessed and no Social Security numbers, financial information, credit records, or passwords were compromised. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
