On July 19, 2025, Whitepages detected a credential stuffing attack where stolen credentials from other sites were used to access user accounts. Affected data included names, email addresses, lookup history, and partial payment card information (last 4 digits). Whitepages disabled affected accounts, required password resets, and enhanced threat detection. No evidence of fraud or identity theft was found.