---
title: "Aura phone-phishing data incident"
description: "Evidence-backed account of Aura phone-phishing data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/aura-phone-phishing-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/aura-phone-phishing-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/aura-phone-phishing-data-incident-2026/stix.json"
---

# Aura phone-phishing data incident

A targeted phone-phishing attack enabled unauthorized access to an Aura employee corporate account for approximately one hour. The incident exposed marketing-contact records, most of which came from a Circle Media Labs database maintained after Aura's acquisition of Circle.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A targeted phone-phishing attack enabled unauthorized access to an [Aura](https://www.aura.com/) employee corporate account for approximately one hour. [1](#source-1) [2](#source-2)

## Impact

The incident exposed marketing-contact records, most of which came from a Circle Media Labs database maintained after Aura's acquisition of Circle. [1](#source-1) [2](#source-2)

Documented data types include:

- Contact information — Email addresses and, in some cases, home addresses and phone numbers. [1](#source-1) [2](#source-2) [3](#source-3)
- Customer service records — Customer service records listed for the HIBP incident corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- IP addresses — IP addresses in some leaked records. [1](#source-1) [2](#source-2) [3](#source-3)
- Names — Names, which Aura said made up most records together with email addresses. [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 20,000 individuals (Upper-bound representation of Aura's statement that fewer than 20,000 active Aura customers were affected; not an exact count). [1](#source-1) [2](#source-2)

A cited record reports 903,080 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a customer total; as of 2026-03-18). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 15,000 individuals (Upper-bound representation of Aura's statement that fewer than 15,000 former Aura customers were affected; separate from active customers and not an exact count). [1](#source-1) [2](#source-2)

A cited record reports 900,000 records (Aura's approximate organization-reported record count; the vast majority were names and email addresses from an acquired company's marketing tool; as of 2026-03-19). [1](#source-1) [2](#source-2) [3](#source-3)

Aura said it was notifying impacted customers and would notify affected customers and partners as appropriate while its review continued. [1](#source-1) [2](#source-2)

## Timeline

### March 6, 2026 — Documented event

Incident date in the HIBP corpus; Aura's public statements establish March timing and an approximately one-hour duration but do not publish this exact event date. [3](#source-3)

### March 17, 2026 — Public disclosure

Date Aura's later incident article says it announced the employee phishing incident. [1](#source-1)

### March 19, 2026 — Public disclosure

Timestamp of Aura's updated exposure statement. [2](#source-2)

### March 26, 2026 — Public disclosure

Publication date of Aura's detailed incident article. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Aura said a single employee was targeted in a phone-phishing attack and an unauthorized party accessed the employee's corporate account for approximately one hour before Aura removed access. [1](#source-1) [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [2](#source-2)

## Response

Aura said it immediately terminated the unauthorized access, activated its incident-response plan, engaged external cybersecurity and legal experts, and notified law enforcement. Aura said its identity-protection application and supporting databases were not accessed and no Social Security numbers, financial information, credit records, or passwords were compromised. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/aura-phone-phishing-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Aura Security Incident: What Happened & How We're Responding

official · Aura · Mar 26, 2026

<https://www.aura.com/learn/march-2026-security-incident-update>

<a id="source-2"></a>

### Aura Statement on Exposure of Limited Customer Information

official · Aura · Mar 19, 2026

<https://www.aura.com/press/release/statement-on-exposure-of-customer-information>

<a id="source-3"></a>

### Aura breach record

advisory · Have I Been Pwned · Mar 18, 2026

<https://haveibeenpwned.com/api/v3/breach/Aura>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Used Attack Technique · 95% confidence · current**  
   March 2026 Aura phone-phishing incident: https://attack.mitre.org/techniques/T1566/004/
2. **Affected Individual Count · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: 20,000 individual
3. **Affected Organization · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: Circle Media Labs, Inc.
4. **Disclosed At · 100% confidence · current**  
   Aura March 2026 incident disclosures and notifications: 2026-03-19T10:00:00-04:00
5. **Resulted In · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura said it immediately terminated the unauthorized access, activated its incident-response plan, engaged external cybersecurity and legal experts, and notified law enforcement.
6. **Resulted In · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura said its identity-protection application and supporting databases were not accessed and no Social Security numbers, financial information, credit records, or passwords were compromised.
7. **Affected Organization · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura
8. **Occurred At · 90% confidence · current**  
   March 2026 Aura phone-phishing incident: 2026-03-06
9. **Exposed Data Category · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: Contact information
10. **Exposed Record Count · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: 903,080 record
11. **Disclosed At · 100% confidence · current**  
   Aura March 2026 incident disclosures and notifications: 2026-03-17
12. **Affected Individual Count · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: 15,000 individual
13. **Resulted In · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura said a single employee was targeted in a phone-phishing attack and an unauthorized party accessed the employee's corporate account for approximately one hour before Aura removed access.
14. **Resulted In · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura March 2026 incident disclosures and notifications
15. **Exposed Record Count · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: 900,000 record
16. **Resulted In · 100% confidence · current**  
   Aura March 2026 incident disclosures and notifications: Aura said it was notifying impacted customers and would notify affected customers and partners as appropriate while its review continued.
17. **Exposed Data Category · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: Customer service records
18. **Subsidiary Of · 100% confidence · current**  
   Circle Media Labs, Inc.: Aura
19. **Exposed Data Category · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: IP addresses
20. **Resulted In · 100% confidence · current**  
   March 2026 Aura phone-phishing incident: Aura and Circle marketing-contact data exposure
21. **Exposed Data Category · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: Names
22. **Affected Organization · 100% confidence · current**  
   Aura and Circle marketing-contact data exposure: Aura
23. **Disclosed At · 100% confidence · current**  
   Aura March 2026 incident disclosures and notifications: 2026-03-26

</details>
