Simple.biz, a web development agency, allegedly experienced a data breach in April 2026. This incident reportedly led to the exposure of data and infrastructure access for more than 250 of its US business clients. Information from healthcare providers and e-commerce sites was reportedly affected, and this data is currently being advertised for sale on a cybercrime forum.
The compromised data reportedly includes personally identifiable information (PII) for 250 business owners, such as names, addresses, phone numbers, emails, and ages, along with family details. Other exposed data points include 6,700 phone numbers, 3,500 email addresses, 750 IP addresses, 200 server credentials (cPanel, AWS, DigitalOcean, WP Engine), and 50 source code repositories. More than 10,000 customer records from client e-commerce sites and patient records, including dates of birth and insurance details, were also reportedly exposed. The exact number of individuals affected, beyond the 250 business owners and the listed data points, has not been publicly confirmed.
Details surrounding this incident may emerge over time, and breach notification processes can be delayed.