Skip to content

Addi

Disclosed May 18, 20264 months ago34,532,941 accountsUnverified

In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeco

What is known

People affected34,532,941 (accounts in the leaked data, per Have I Been Pwned)
DisclosedMay 18, 2026
HappenedMar 25, 2026
AttackExtortion
Data exposedEmails, Government IDs, Financial, IP addresses, Names, Phone numbers, Addresses
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Addihaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataMay 1834,532,941
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Addi

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.