Back to news
Cybersecurity Alert
August 5, 2026 by EmailMeNow IT Consulting

Was ZenBusiness Breached? ShinyHunters Dump Hits HIBP at 5.1M; W.D. Tex Class Actions

ShinyHunters released ZenBusiness CRM data after a March 2026 extortion claim. HIBP lists 5,118,184 accounts. W.D. Tex In Re 1:26-cv-00812. Audit: zenbusiness.com 66% (ideal 100%).

Source: Have I Been Pwned · CourtListener

NewsData BreachShinyHuntersTexasClass ActionMFACybersecurity
ZenBusiness ShinyHunters data dump and Texas federal class actions

Yes — ZenBusiness customer and CRM data was publicly released after a March 2026 extortion campaign by ShinyHunters. Have I Been Pwned indexes 5,118,184 affected accounts (breach date March 27, 2026; added May 2, 2026), primarily email addresses, names, and phone numbers from multi-terabyte dumps the group claimed came from Snowflake / Mixpanel / Salesforce-class platforms.

Consumer class actions are consolidated in the U.S. District Court for the Western District of Texas as IN RE: ZENBUSINESS DATA BREACH LITIGATION (1:26-cv-00812, filed April 1, 2026).

We scanned zenbusiness.com for email/domain posture relevant to LLC-formation phishing and notice spoofing.

ZenBusiness ShinyHunters data dump and Texas federal class actions

What Happened

FieldDetail
EntityZenBusiness, Inc. (zenbusiness.com) — Austin-area business formation / compliance SaaS
Threat actorShinyHunters (extortion → public dump)
HIBP accounts5,118,184 (verified)
Data types (HIBP)Email, name, phone (file-dependent)
Federal litigationIn Re ZenBusiness 1:26-cv-00812 (W.D. Tex, filed Apr 1, 2026)

Member filings include Price (1:26-cv-00817), Michail, and Camacho.

Why it matters for Texas founders

Leaked formation / CRM contacts fuel fake “file your annual report,” EIN, and registered-agent phishing. Treat unexpected ZenBusiness-branded mail as hostile until verified in-product.

Independent Cybersecurity Audit

EmailMeNow audit of zenbusiness.com on August 5, 2026. 100% is the ideal.

DomainOverallIdentityTransportWebsiteRisk
zenbusiness.com66%50%15%84%Above Average

zenbusiness.com audit scoreboard with Transport at 15%

Key findings: 66% overall still far below 100%; 15% transport (no effective MTA-STS enforce) leaves spoofed formation notices easy to deliver; identity at 50% needs DMARC hardening.

Audit link: zenbusiness.com

MFA: YubiKey & Google Authenticator

SurfaceYubiKey / FIDOOpen TOTPGrade
ZenBusiness loginNot documentedYes (authenticator app; MFA reset docs)Pass

Takeaway: Documented authenticator-app MFA is a Pass for open TOTP; public docs do not advertise YubiKey / FIDO (not Strong). Prefer hardware keys on email and banking while formation phishing spikes.

Website stack · blacklist · lookalikes

CheckResult (Aug 5, 2026)
Website-techWordPress (version hidden); Let’s Encrypt TLS
BlacklistClear on checked mail/domain lists (public DoH)
Cybersquat43 to review; BEC staging: zenbusiness.tech (NS + MX)

ZenBusiness lookalike domains beside spoofed LLC formation phishing

Prefer in-app notice channels — see Cybersquat Domain Monitoring.

Priority Actions

If you use ZenBusiness: Check HIBP for your emails; lock domain registrar / transfer PIN; ignore unexpected “annual report / EIN update” links.

For SaaS formation platforms: Enforce DMARC + MTA-STS toward 100%; publish FIDO options; monitor BEC-staging lookalikes.


Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting.


Sources: HIBP — ZenBusiness · CourtListener — In Re ZenBusiness 1:26-cv-00812 · EmailMeNow audit — zenbusiness.com