Last updated 1 month ago
In March 2026, Colombian fintech company Addi detected unauthorized activity on its platform, leading to a breach affecting over 34.5 million unique email addresses. The data originated from credit scoring requests, credit bureau records, customer identity records, and email validation logs. The exposure includes government-issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchase histories, and other credit-related data points.
The extortion group ShinyHunters claimed responsibility and published the stolen data. The initial access vector remains unconfirmed, but the attackers exfiltrated a large trove of personal and financial data. No specific CVEs or MITRE ATT&CK techniques were mentioned in the disclosure.
No further post-incident details such as regulatory actions, litigation, ransom payments, or containment milestones were provided in the article.
Unauthorized activity on platform, claimed by ShinyHunters extortion group
Addi's breach highlights the critical need for robust access controls and monitoring in fintech platforms handling sensitive credit data. The exfiltration of 34 million records, including government IDs and income levels, suggests inadequate segmentation and insufficient detection of unauthorized data access. Implementing strict least-privilege policies and real-time anomaly detection could have limited the scope and impact of this breach.
Sign in to join the discussion.
Company
Industry
Location
Discovered
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor