Data breach
DreamUp
- Records
- 1,652,692
- Breach date
- 1 March 2026Estimated
- Added
- 12 March 2026
What was exposed
4 types of data
- Email addresses1,652,692
- Street addresses224,191
- Phone numbers212,904
- Names7,551
About this breach
DreamUp, a U.S.-based space education company headquartered in Washington, D.C., has been linked to a data breach affecting more than 1.6 million records. The dataset tied to the incident contains roughly 1.65 million email addresses, alongside smaller amounts of personal contact information. The team estimates the attack occurred on or around March 1, 2026.
Coverage of the incident remains sparse. No formal notice from the company has been located, and no major news organization has published detailed reporting on the breach.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
DreamUp is a space education organization that provides programs for students and educators, including opportunities to send experiments to the International Space Station and other space platforms. According to Breachsense, the breach involving dreamup.org was discovered on March 5, 2026, and the listing attributes the incident to the Lapsus$ extortion group. The investigation team has not independently confirmed a claim of responsibility, and the breach remains unclaimed in its own records. No ransom amount or proof of system intrusion has been publicly verified.
What Information Was Compromised?
Our analysis found the following data types in this breach: approximately 1,652,692 email addresses, 212,904 phone numbers, 224,191 street addresses, and 7,551 names.
Not every individual is affected by every type of data listed here.
The volume of email addresses relative to names suggests the exposed material consists largely of contact and account records rather than detailed identity documents. The investigation team did not report finding Social Security numbers, payment card data, or medical information in the dataset. It is possible that some records include other fields not reflected in the indexed categories, but nothing of that kind has been verified.
What Are the Potential Risks for Affected Individuals?
Because the dataset is dominated by email addresses, phone numbers, and street addresses, the most immediate risk is targeted phishing. Attackers who know a person's email address, phone number, and physical address can craft messages that appear legitimate, such as fake shipping notices, account alerts, or messages referencing space education programs the recipient may have signed up for.
Phone numbers in the dataset could also be used for smishing, which is phishing carried out over text messages, or for unwanted robocalls and spam. Street addresses and names, where present, raise the risk of physical mail scams and impersonation attempts.
The relative absence of financial or government identity data lowers the likelihood of direct identity theft or payment card fraud stemming from this incident alone. However, email addresses can be cross-referenced with passwords exposed in unrelated breaches, so anyone who reused the same password across multiple sites should treat those accounts as at risk.
What Should You Do If You Were Affected?
If you had an account with DreamUp or interacted with its programs, change that password first, and change it anywhere else you reused it. Use unique passwords for each account.
Enable two-factor authentication on your email account and any other account that supports it.
Be cautious with unexpected emails, texts, or calls that reference DreamUp, student programs, or shipping, especially if the sender appears to know your address. Do not click links or open attachments from unverified sources.
Watch your financial accounts and credit reports for activity you do not recognize. In the United States, you can request free credit reports from the three major bureaus and place a fraud alert or security freeze at no cost.
Report phishing attempts to your email provider and, in the United States, to the Federal Trade Commission.
