← Back to Home

Addi Data Breach

Verified Breach
Mar 24, 2026 Breach Date
34,532,941 Accounts Affected
13 Data Types Exposed
May 18, 2026 Added to HIBP
About This Breach
In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.
Compromised Data Types
Age groups Credit scores Device information Email addresses Government issued IDs Income levels IP addresses Latitude and longitude pairs Names Phone numbers Physical addresses Purchases Socioeconomic levels
Check If You Were Affected

Were you part of the Addi breach?

Has your email been exposed in a breach?