TheSqua.re Data Breach (2025): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
TheSqua.re data breach was disclosed on June 27, 2025, exposing email addresses, geographic locations, names, and phone numbers of approximately 107,000 individuals. Users are advised to check their accounts and consider protective steps such as monitoring for suspicious activity.
In June 2025, roughly 107,000 people who had used TheSqua.re to search for serviced apartments learned that their personal details may have been taken and shared online. For those individuals the practical stakes are immediate: contact information and location data that can be used for phishing, unwanted calls, or more targeted social engineering.
Public reporting indicates the material was posted to a popular hacking forum. TheSqua.re itself did not respond to repeated attempts to confirm or discuss the incident, leaving affected people to rely on independent verification rather than an official notice.
Inside the incident
According to the available record, the incident was reported on 27 June 2025. Approximately 107,000 unique customer email addresses were allegedly obtained from TheSqua.re. Alongside the emails, the material that appeared online also contained names, phone numbers and cities (geographic locations).
The data was subsequently posted to a popular hacking forum. Multiple subscribers to Have I Been Pwned who recognised their own details confirmed that the sample data matched records they held, supporting the claim that the set was authentic. TheSqua.re did not reply to repeated outreach seeking disclosure or comment. No further public detail has been released about the precise date of intrusion, the technical method used, or any internal investigation.
How a breach like this happens
Incidents that result in customer contact lists appearing on forums typically follow a small number of well-understood paths. An attacker may obtain credentials through phishing or credential-stuffing against an employee or partner account, then use that access to export customer records. Alternatively, a misconfigured database, an unpatched web application, or an exposed API endpoint can allow bulk extraction without any stolen password.
Once the data leaves the organisation it is often cleaned, deduplicated and offered for free or for sale on criminal forums. The presence of email addresses, names, phone numbers and cities makes the set useful for spam campaigns, SIM-swap attempts or spear-phishing that references a recent apartment booking. No specific threat group has been publicly attributed to this event, and the exact vector remains undisclosed.
TheSqua.re and its sector
TheSqua.re describes itself as a platform that helps people find serviced apartments—fully furnished, short- or medium-term rentals commonly used by business travellers, relocating employees and temporary residents. Companies in this sector routinely collect names, email addresses, telephone numbers and city or neighbourhood preferences so they can match customers with available properties and manage bookings.
Because the service sits between travellers and property operators, a single customer record can contain enough personal detail to identify an individual and their recent travel or relocation plans. A breach at such a platform therefore affects not only the company’s reputation but also the privacy of people who expected their contact and location information to remain limited to legitimate booking purposes.
What data was at risk
The public account of the incident names four categories of data: email addresses, geographic locations (cities), names and phone numbers. These were the fields that appeared in the material posted online and that Have I Been Pwned subscribers recognised as accurate.
Organisations that arrange serviced apartments typically also hold booking dates, payment references or corporate affiliation details, but no such additional fields have been confirmed as part of this release. The exact contents of the full dataset beyond the four named types remain unconfirmed.
The real-world impact
For the people whose records were exposed, the main risks are practical rather than abstract. Email addresses and phone numbers can be used to send convincing phishing messages that reference a recent apartment search or booking. Names combined with cities allow more personalised social-engineering attempts. In some cases the same data can support account-takeover efforts against other services that rely on email or SMS verification.
For TheSqua.re the consequences include loss of customer trust, potential regulatory scrutiny under data-protection rules, and the operational cost of any future remediation or notification programme. Because the company has not issued a public statement, affected individuals currently lack an official channel for confirmation or support.
Were you affected?
If you have ever created an account or submitted an enquiry on TheSqua.re, treat the possibility of exposure seriously. Practical first steps include:
- Changing any password that may have been reused on the platform and enabling multi-factor authentication wherever available.
- Watching for unexpected emails or phone calls that reference apartment bookings or personal details.
- Considering a temporary freeze or alert on financial accounts if you supplied payment information during a booking.
- Running a free exposure scan of your email address against known breach data to see whether your details have already appeared in public dumps.
Public detail remains limited; until TheSqua.re provides its own account, independent verification and ordinary digital hygiene remain the most reliable protections available to those who may be affected.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pass'Sport Data Breach (2025)APOIA.se Data Breach (2025)SoundCloud Data Breach (2025)Under Armour Data Breach (2025)Latest breaches
Read GalaxyWarden’s full analysis of the TheSqua.re Data Breach (2025) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.