
StickerHub security incident progress update: current findings and user guidance
>This update covers what information was involved, what was not exposed, and why the attacker’s “your data was sold” claim is not supported by our current findings.
Hi everyone. I’m the StickerHub team member who posted the AMA yesterday. This update is from our Security & Support Team.
We know the last 24 hours have been confusing, stressful, and honestly pretty chaotic. We also know our earlier understanding changed as the investigation developed, so we want to keep this update as clear as possible.
Here is where things stand now.
1. What information was involved
Since our previous notice, we have continued reviewing the externally published files, affected systems, and questions raised by the community.
At this time, we have not identified any additional categories of affected information.
The information reviewed remains limited to:
- Email addresses and StickerHub usernames
- Basic account metrics, such as account creation dates and transaction counts
- Non-sensitive technical parameters, such as language settings, app version, and device identifiers
2. What was NOT involved
StickerHub does not receive or store users’ Google or Apple account passwords, payment card information, financial information, photos, or personal files stored on users’ devices.
Because StickerHub does not hold that data, it could not have been exposed through this incident.
Based on our current findings, users do not need to take additional action concerning their Google, Apple, Facebook, Monopoly GO accounts, or payment methods.
3. About the “your data was sold” notifications
StickerHub has not sold user data.
The messages saying “your data has been sold” were written and distributed by the attacker through unauthorized notifications. They were not written, approved, or sent by the StickerHub team.
The fact that some user information appeared on an unauthorized external website confirms an unauthorized disclosure. It does not support the claim that StickerHub sold user data.
4. Security and remediation progress
The unauthorized activity has been contained.
We have expanded our security response across the affected systems and data-access permissions, strengthened monitoring and audit controls, and have not identified any new unauthorized activity or additional data exposure.
5. What users should do now
Please stay cautious of emails, messages, or links impersonating StickerHub.
StickerHub will never ask users for passwords, verification codes, payment information, or Google/Apple login details.
For official information about this incident, please rely on the News section inside the StickerHub app.
Full official update: https://app.stickerhub.io/news/13
We will provide another update if a material development changes our current findings.
Since the weekend is coming up, replies here may be slower, but official updates will continue to be posted in StickerHub app News if anything materially changes.
Thank you to everyone who asked hard questions, corrected unclear wording, sent screenshots, or gave us a chance to explain. We know trust is not rebuilt by one post. We’ll keep working on it.