Mobexly, a U.S.-based mobile app development and no-code platform provider, suffered a data breach that was detected in early 2026. A hacker claimed responsibility on February 14, 2026, offering 24 GB of stolen data for sale. The incident involved unauthorized access to Mobexly's servers, likely through exploited vulnerabilities in their cloud infrastructure. Mobexly posted an official breach notification statement on its security page on March 10, 2026, and began notifying affected individuals on March 15, 2026.
Approximately 1.2 million individuals were impacted. The exposed data includes names, email addresses, phone numbers, physical addresses, usernames, hashed passwords, API keys, project files, and app source code. Mobexly stated that there is no evidence of SSN, medical, or financial data exposure. The states primarily affected include California, Texas, Florida, New York, and Illinois, with a broader nationwide U.S. impact.
Details about data breaches can emerge over time, and notifications may be delayed. Mobexly has offered 24 months of credit monitoring to affected users.