In March 2023, Vultr, an "AI-first global cloud platform," disclosed a security incident that occurred at a third-party vendor, ActiveCampaign. This incident, which reportedly dates back to July 2022, led to the exposure of 188,000 unique email addresses. A smaller portion of these records also included names, IP addresses, and country of origin. Vultr stated that its own systems and additional customer data were not affected. There are also reports and mentions of Vultr in 2025 related to a cloud-init vulnerability (CVE-2023-1786) and an attacker using a Vultr IP in the Notepad++ incident. However, there is no confirmed Vultr data breach specifically in 2025.
Confirmed data types involved in the 2023 incident include email addresses, names, IP addresses, and geographic locations, affecting approximately 188,000 individuals. It remains unclear if any individuals were affected by the 2025 incidents involving the cloud-init vulnerability or the Notepad++ incident, as neither are confirmed company-wide breaches. There is no evidence of SSN, medical, or financial data exposure. The states affected remain unclear, and customer notifications related to the 2025 events have not been confirmed.
Details surrounding these incidents, especially regarding the unconfirmed 2025 events, may still emerge. Official notices may also be delayed.