ADDA Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
ADDA has disclosed a data breach affecting 1.8 million individuals, exposing names, email addresses, phone numbers, and passwords. If you have an account with the organisation, review your recent activity and change your password immediately.
Data breaches involving community and housing platforms continue to surface regularly in 2025, reflecting the broader pressure on services that store personal details for large numbers of residents. These incidents often involve credential material and contact data that can be reused across other accounts, making them relevant beyond the original service.
In March 2025, data allegedly taken from ADDA, a housing societies service, was posted to a public hacking forum. The material reportedly covered more than 1.8 million unique email addresses together with names, phone numbers and MD5 password hashes. The episode matters because the volume and the types of records create practical risks for the people whose information appeared.
Inside the incident
Public reporting dated 24 March 2025 states that data allegedly breached from the ADDA housing societies service was posted to a public hacking forum. The posted set contained over 1.8 million unique email addresses along with names, phone numbers and MD5 password hashes. No further confirmed detail has been released about the precise date of the intrusion, the technical method used, or any internal discovery timeline. The scale is given as 1.8 million people affected. Attribution to any specific threat group is absent from the available record; the material is described only as having been posted to a public forum.
How a breach like this happens
Incidents of this type commonly begin with an initial foothold obtained through stolen credentials, unpatched software, or misconfigured cloud storage. Once inside, an attacker may extract databases that hold user profiles and authentication material. Password fields stored as MD5 hashes are frequently included because many older systems still rely on that algorithm. The extracted files are then packaged and offered or simply dumped on public forums, where they can be downloaded by anyone. The sequence is typical of opportunistic data theft rather than a highly targeted campaign; no specific actor is named in connection with this event, and the method remains undisclosed.
ADDA and its sector
ADDA operates as a housing-societies service, providing digital tools for apartment complexes, resident associations and community management. Organisations in this sector routinely maintain directories of residents, committee members and service contacts so that notices, payments and access controls can be handled online. Because the platforms sit between property managers and large numbers of households, they accumulate contact details and login credentials at scale. A breach affecting such a service is consequential precisely because the same individuals often reuse email addresses and passwords for banking, government portals and other everyday accounts; exposure therefore extends beyond the housing platform itself.
The information in question
The facts name the exposed data types as email addresses, names, passwords and phone numbers. The reported summary further specifies that the passwords appeared as MD5 hashes and that the set contained over 1.8 million unique email addresses. No additional categories such as financial account numbers, government identifiers or physical addresses are listed in the available record. Exact contents beyond the named fields remain unconfirmed; organisations of this kind typically hold resident contact lists and authentication data, yet only the items explicitly reported can be treated as fact for this incident.
What's at stake
For affected individuals the immediate risks are credential stuffing and targeted phishing. Email addresses paired with MD5 password hashes allow attackers to attempt the same login combinations on other services; phone numbers and names improve the credibility of social-engineering messages. Even if the hashes are later cracked only partially, the contact data alone can be used for spam or fraud campaigns. For the organisation the stakes include loss of resident trust, potential regulatory scrutiny over data-protection practices, and the operational cost of notifying users and resetting credentials. No dollar figure or formal regulatory action is stated in the public facts.
If your data was in this breach
If you used ADDA or believe your details may have been included, take the following practical steps:
- Change any password that was ever used with the service, and do so on every other account where the same password was reused.
- Enable multi-factor authentication wherever it is offered, especially on email and financial accounts.
- Treat unsolicited calls or messages that reference your housing society or personal details with caution; verify through official channels.
- Monitor account statements and credit activity for unexpected activity in the coming months.
- Run a free exposure scan of your email address to check whether the address has already appeared in known breach data sets.
These measures reduce the most common follow-on risks without requiring specialised tools. Public detail on the incident remains limited to the points already stated; further confirmation would need to come from official notices issued by ADDA itself.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
WhiteDate Data Breach (2025)Raaga Data Breach (2025)Dragonica Lunaris Data Breach (2025)Operation Endgame 3.0 Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the ADDA Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.