Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownReported

Identity protection firm Aura breached in vishing attack; ~900,000 records taken

Aura · Technology · United States · March 2026

People or records affected
900,000
900K as reported

What happened

Aura, a Burlington, Massachusetts identity protection company, was breached in March 2026 when a vishing attack compromised an employee account for roughly an hour before the access was removed. Approximately 900,000 records were taken from a marketing database acquired through Circle Media Labs, containing names, home addresses, telephone numbers and email addresses. The breach drew attention because many affected individuals were customers who had bought protection against exactly this kind of threat.

How the deception worked

The attackers targeted a single employee account with a voice phishing call, the same pattern the group used against Okta and Microsoft Entra single sign-on accounts throughout early 2026: pose as internal IT, offer help with an authentication task, and capture credentials and a one-time code through a lookalike login page. The compromised account was live for only about an hour, but that was long enough to export a marketing database wholesale. The stolen combination of name, address, phone and email is itself high-quality raw material for follow-on phishing and vishing.

AI involvement · Unknown

No confirmation that synthetic voice was used on the call that compromised the employee account.

The control that would have caught it· our reading, not a claim from the sources

Short-lived access still enables bulk export; rate-limiting and alerting on large database exports would have caught the theft inside the one-hour window.

Sources (1)

  1. Aura data breach
    Wikipedia·en.wikipedia.orgOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.