Data breach
Adelante Soluciones Financieras (Addi.com)
- Records
- 67,979,172
- Breach date
- 5 May 2026Estimated
- Added
- 8 May 2026
What was exposed
5 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses67,979,172
- Phone numbers20,921,365
- Names8,608,185
- Dates of birth203
- Government IDs1
- IP addressesReported, not counted
- Home addressesReported, not counted
- Purchase historyReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Addi, the Colombian fintech platform operated by Adelante Soluciones Financieras, appears in a large data breach that our investigation team has indexed at roughly 68 million records. The incident traces back to March 2026, when the company reportedly identified unauthorized activity on its platform. In May 2026, the ShinyHunters extortion group listed the company on its leak site, claiming it had exfiltrated more than 518 GB of compressed data containing personal, financial, and credit-related records. Independent reporting and breach-tracking services have since confirmed that a large dataset tied to Addi has circulated, though the full picture of what was taken remains under review.
Breach Timeline
March 25, 2026: Mozilla Monitor records this as the date the Addi breach occurred, after the company reportedly identified unauthorized activity on its platform that month.
May 5, 2026: ShinyHunters listed Adelante Soluciones Financieras (Addi.com) on its leak site, claiming a 518 GB-plus dataset with more than 16 million unique person records, according to Ransomware.live.
May 6, 2026: BreachNews reported that the group claimed the release followed a failed extortion negotiation, and that the company had not yet issued a public statement.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (67,979,172 records), phone numbers (20,921,365), names (8,608,185), and dates of birth (203). The count of government ID numbers could not be determined from the indexed data.
Independent breach trackers list additional fields. XposedOrNot, which indexes more than 25.9 million unique email addresses from this incident, reports government-issued IDs, IP addresses, physical addresses, and purchase records. Mozilla Monitor's entry adds credit scores, income levels, socioeconomic levels, and latitude-longitude pairs.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of government ID numbers, financial details, and purchase records is what makes this breach serious. Unlike a password, a national ID number such as the Colombian cédula cannot simply be changed, so it can be reused by criminals for years in identity fraud, loan applications, and account takeovers. Email addresses and phone numbers in the same dataset give scammers the raw material for targeted phishing messages that appear credible because they reference real purchases or financial details. People whose data appears in the leak should also watch for attempts to open credit accounts in their name, particularly if credit bureau records were included in the published material, as the attackers claimed.
What Is Adelante Soluciones Financieras (Addi.com) Doing in Response?
According to XposedOrNot, Addi identified unauthorized activity on its platform in March 2026. Public details about the company's own response, including whether it notified customers directly or filed reports with Colombian regulators, were limited in the sources we reviewed as of September 25, 2026. We will update this article if the company publishes a formal notice.
What Should You Do If You Were Affected?
If you used Addi or applied for financing through the platform, take these steps:
Change your Addi password and any other account where you reused it, and turn on two-factor authentication wherever it is offered.
Watch your bank and card statements for charges you do not recognize, and review your credit reports for accounts you did not open.
Be cautious with emails, texts, or calls referencing your finances or purchases. Scammers often use breach data to sound legitimate. Do not share ID numbers or codes with unsolicited contacts.
Consider placing a fraud alert or credit freeze with credit bureaus operating in Colombia, such as TransUnion or Experian, especially since the attackers claimed the stolen material included credit bureau records.
Report suspected identity fraud to local authorities and to the financial institutions involved.
In the news
- Ransomware.live listing for Adelante Soluciones Financieras (Addi.com)ransomware.live (opens in a new tab)
- BreachNews: ShinyHunters claims 16M record breach of Addibreachnews.com (opens in a new tab)
- XposedOrNot: Addi data breachxon-web-test.xposedornot.com (opens in a new tab)
- Mozilla Monitor: Addi breach detailsmonitor.mozilla.org (opens in a new tab)
