u/MonopolyStickerHub

StickerHub security incident progress update: current findings and user guidance
▲ 10 r/StickerHub_App+1 crossposts

StickerHub security incident progress update: current findings and user guidance

>This update covers what information was involved, what was not exposed, and why the attacker’s “your data was sold” claim is not supported by our current findings.

Hi everyone. I’m the StickerHub team member who posted the AMA yesterday. This update is from our Security & Support Team.

We know the last 24 hours have been confusing, stressful, and honestly pretty chaotic. We also know our earlier understanding changed as the investigation developed, so we want to keep this update as clear as possible.

Here is where things stand now.

1. What information was involved

Since our previous notice, we have continued reviewing the externally published files, affected systems, and questions raised by the community.

At this time, we have not identified any additional categories of affected information.

The information reviewed remains limited to:

  • Email addresses and StickerHub usernames
  • Basic account metrics, such as account creation dates and transaction counts
  • Non-sensitive technical parameters, such as language settings, app version, and device identifiers

2. What was NOT involved

StickerHub does not receive or store users’ Google or Apple account passwords, payment card information, financial information, photos, or personal files stored on users’ devices.

Because StickerHub does not hold that data, it could not have been exposed through this incident.

Based on our current findings, users do not need to take additional action concerning their Google, Apple, Facebook, Monopoly GO accounts, or payment methods.

3. About the “your data was sold” notifications

StickerHub has not sold user data.

The messages saying “your data has been sold” were written and distributed by the attacker through unauthorized notifications. They were not written, approved, or sent by the StickerHub team.

The fact that some user information appeared on an unauthorized external website confirms an unauthorized disclosure. It does not support the claim that StickerHub sold user data.

4. Security and remediation progress

The unauthorized activity has been contained.

We have expanded our security response across the affected systems and data-access permissions, strengthened monitoring and audit controls, and have not identified any new unauthorized activity or additional data exposure.

5. What users should do now

Please stay cautious of emails, messages, or links impersonating StickerHub.

StickerHub will never ask users for passwords, verification codes, payment information, or Google/Apple login details.

For official information about this incident, please rely on the News section inside the StickerHub app.

Full official update: https://app.stickerhub.io/news/13

We will provide another update if a material development changes our current findings.

Since the weekend is coming up, replies here may be slower, but official updates will continue to be posted in StickerHub app News if anything materially changes.

Thank you to everyone who asked hard questions, corrected unclear wording, sent screenshots, or gave us a chance to explain. We know trust is not rebuilt by one post. We’ll keep working on it.

u/MonopolyStickerHub — 2 days ago
▲ 98 r/StickerHub_App+1 crossposts

I work on StickerHub marketing. Yes, we saw the “please stay” notifications. Today was a disaster. AMA.

Hi Reddit. I work on StickerHub’s marketing team.

I’m not a founder. I’m not legal. I’m not here to drop a polished corporate paragraph and disappear.

I’m going to be honest: I don’t really know what the perfect “brand response” is supposed to look like right now. We posted the official update. We replied to comments. We tried to explain the safety points as clearly as we could. And a lot of you still don’t trust us.

Honestly? I get it.

I came into work today in a good mood. I’m two years out of school. This is the first time I’ve ever been inside a situation like this. Then right after I got to the office, the team pulled everyone into an emergency meeting, and that was how I found out that while we were asleep, someone had abused access to our push notification system and sent a bunch of fake notifications to users.

Then I started seeing the screenshots: “your data has been sold,” “PLEASE STAY,” “DON’T GO,” “choose wisely,” “1,000 tickets.” And then Reddit turned the whole thing into an abusive-ex / parents-fighting / cursed-breakup-texts storyline.

At first I was panicking. Then I was trying to help get accurate information out. Then I was reading Reddit and hit the point where the whole thing was so absurd I didn’t know whether to laugh, cry, or crawl under my desk.

So I’m here as a real person on the team, because the polished statement clearly wasn’t enough for everyone.

Roast us if you want. I understand why. The screenshots are ridiculous. The situation is ridiculous. But I’ll still answer seriously, because people were scared and confused, and that part isn’t a meme.

Here’s what I can say clearly:

  • The strange push notifications were unauthorized.
  • They were sent after an unauthorized party abused access to StickerHub’s push notification system.
  • They were not written, approved, or intentionally sent by StickerHub.
  • The “your data was sold” claim was false.
  • Based on our investigation so far, we have found no evidence that user data was accessed, leaked, or sold.
  • We have found no evidence that bank cards, payment information, MoGo stickers, or MoGo accounts were accessed or affected.
  • The external website linked in the notifications was not official StickerHub. Please don’t enter anything there.
  • Receiving or tapping a push notification does not install malware.
  • The affected notification access has been secured.

If you deleted the app, I get it. If you don’t trust us right now, I get that too. If you’re only here because the screenshots are unhinged, honestly, I also get that.

Ask me anything. I’ll answer what I can. If I don’t know, I’ll say I don’t know. If something is still under investigation, I’ll say that too. I’m not here to pretend this was fine.

u/MonopolyStickerHub — 3 days ago
▲ 15 r/StickerHub_App+1 crossposts

StickerHub Security Update: Unauthorized Push Notifications and User Data Safety

Between 4:00 PM and 8:00 PM ET on July 22, 2026, some users received strange, alarming, and offensive push notifications appearing to come from StickerHub.

These messages were not written, approved, or sent by the StickerHub team. They were sent after an unauthorized party abused access to our notification-sending system.

Based on our investigation so far:

  • The incident was limited to the notification system.
  • StickerHub does not sell user data.
  • We found no evidence that our user database was accessed, leaked, or sold.
  • We found no evidence that accounts, bank cards, payment information, MoGo stickers, or MoGo accounts were accessed or affected.
  • Receiving or tapping a push notification does not install malware on your device.
  • The external website linked in the messages is not official StickerHub and contains false claims. Please do not enter any personal information there.

The affected notification access has been revoked and secured. Notifications already sent could not be recalled, which is why some users may still have seen them after the incident window.

If you entered a password or payment information on the external website, please change that password and contact your payment provider if needed.

We’re sorry for the fear and confusion this caused. We’ll continue monitoring and update users if anything changes.

Full update: https://stickerhub.io/security-update-unauthorized-notifications-july-2026

Thank you,
The StickerHub Team 💙

u/MonopolyStickerHub — 4 days ago