Addi
CriticalConfirmedBanking and finance
In March 2026, Addi suffered a data breach. 35 million accounts were affected. The exposed data includes dates of birth, connection data, email addresses, identity documents, employment data, postal addresses, names, phone numbers and purchase histories.
- Disclosed on
- May 18, 2026
- Incident dated
- March 25, 2026
- Accounts affected
- 35M
- Sector
- Banking and finance
- Country
- International or undetermined
- Cause
- Undisclosed
Exposed data
- Date of birth
- Connection data (IP, logs)
- Email address
- Identity document
- Employment data
- Postal address
- Full name
- Phone number
- Order history
You are only affected if you had an account or an order with this organisation.
What you can do
- Expect phishing attempts quoting your name and this company. A message that knows your details is not legitimate for that reason.
- These documents enable identity theft, and cannot be reissued at will. Keep the notification letter: it proves where the leak came from if an account is opened in your name.
- You can ask the organisation exactly what was exposed about you (right of access), and complain to the DPA if no answer comes within a month.
Sources
Entry built from Have I Been Pwned’s structured data, with no model rewriting. Spotted an error, or have a correction? Write to us and the entry will be fixed. Contact