On March 24, 2026, Whitepages detected a credential stuffing attack where attackers used stolen credentials from other sites to access user accounts. Affected data included names, email addresses, lookup history, and partial payment card information (last 4 digits). Whitepages disabled affected accounts, required password resets, and enhanced threat detection. No evidence of fraud or identity theft was found.