Yes — ZenBusiness customer and CRM data was publicly released after a March 2026 extortion campaign by ShinyHunters. Have I Been Pwned indexes 5,118,184 affected accounts (breach date March 27, 2026; added May 2, 2026), primarily email addresses, names, and phone numbers from multi-terabyte dumps the group claimed came from Snowflake / Mixpanel / Salesforce-class platforms.
Consumer class actions are consolidated in the U.S. District Court for the Western District of Texas as IN RE: ZENBUSINESS DATA BREACH LITIGATION (1:26-cv-00812, filed April 1, 2026).
We scanned zenbusiness.com for email/domain posture relevant to LLC-formation phishing and notice spoofing.

What Happened
| Field | Detail |
|---|---|
| Entity | ZenBusiness, Inc. (zenbusiness.com) — Austin-area business formation / compliance SaaS |
| Threat actor | ShinyHunters (extortion → public dump) |
| HIBP accounts | 5,118,184 (verified) |
| Data types (HIBP) | Email, name, phone (file-dependent) |
| Federal litigation | In Re ZenBusiness 1:26-cv-00812 (W.D. Tex, filed Apr 1, 2026) |
Member filings include Price (1:26-cv-00817), Michail, and Camacho.
Why it matters for Texas founders
Leaked formation / CRM contacts fuel fake “file your annual report,” EIN, and registered-agent phishing. Treat unexpected ZenBusiness-branded mail as hostile until verified in-product.
Independent Cybersecurity Audit
EmailMeNow audit of zenbusiness.com on August 5, 2026. 100% is the ideal.
| Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|
| zenbusiness.com | 66% | 50% | 15% | 84% | Above Average |

Key findings: 66% overall still far below 100%; 15% transport (no effective MTA-STS enforce) leaves spoofed formation notices easy to deliver; identity at 50% needs DMARC hardening.
Audit link: zenbusiness.com
MFA: YubiKey & Google Authenticator
| Surface | YubiKey / FIDO | Open TOTP | Grade |
|---|---|---|---|
| ZenBusiness login | Not documented | Yes (authenticator app; MFA reset docs) | Pass |
Takeaway: Documented authenticator-app MFA is a Pass for open TOTP; public docs do not advertise YubiKey / FIDO (not Strong). Prefer hardware keys on email and banking while formation phishing spikes.
Website stack · blacklist · lookalikes
| Check | Result (Aug 5, 2026) |
|---|---|
| Website-tech | WordPress (version hidden); Let’s Encrypt TLS |
| Blacklist | Clear on checked mail/domain lists (public DoH) |
| Cybersquat | 43 to review; BEC staging: zenbusiness.tech (NS + MX) |

Prefer in-app notice channels — see Cybersquat Domain Monitoring.
Priority Actions
If you use ZenBusiness: Check HIBP for your emails; lock domain registrar / transfer PIN; ignore unexpected “annual report / EIN update” links.
For SaaS formation platforms: Enforce DMARC + MTA-STS toward 100%; publish FIDO options; monitor BEC-staging lookalikes.
Related Trackers
- Sysco ShinyHunters claim + lawsuits
- Marquis Software ransomware litigation
- Texas breach-litigation defendants scoreboard
- Have I Been Pwned 2026
- Texas OAG YTD dashboard
- All state AG trackers
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting.
Sources: HIBP — ZenBusiness · CourtListener — In Re ZenBusiness 1:26-cv-00812 · EmailMeNow audit — zenbusiness.com