Aura Statement on Exposure of Limited Customer Information
Aura is aware of an incident where one of our employees was the victim of a targeted phone phishing attack. We identified that an unauthorized third-party gained access to that employee’s account for approximately one hour. Upon discovery, Aura immediately terminated access to the account and activated its incident response plan, engaged external cybersecurity and legal experts, and notified law enforcement.
At this time, we can confirm that the unauthorized party was able to access approximately 900,000 records, the vast majority of which consist of names and email addresses from a marketing tool used by a company Aura acquired in 2021.
We believe the contact information (name, email, home address, phone number) for less than 20,000 active Aura customers and less than 15,000 former Aura customers was accessed. No Social Security numbers, passwords, or financial information were compromised.
Aura’s systems have been purpose-built to limit the potential exposure of customer information in the event of a breach, including organizational, technical, and physical safeguards that worked as designed in this incident. All sensitive customer personal information (Social Security numbers, financial transactions, credit files, payment details, credentials) is encrypted and access is highly restricted.
We are in the process of notifying impacted customers as appropriate. While we do not expect that these customers’ risk is significantly elevated, we will be providing support to those impacted.
While we make every effort to ensure that our customers have peace of mind about their safety, we recognize that in this case we did not live up to that standard. We are committed to earning our customers’ continued trust.