[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f10kywmqfcisft":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488253bd","TheSqua.re","TheSqua.re Data Breach","thesquare","thesqua.re","2025-06-27T00:00:00.000Z","2025-08-27T03:59:00.000Z","2026-07-18T23:59:30.329Z","Verified breach record","https:\u002F\u002Finsecureweb.com\u002F100540-rows-exposed-in-thesqua-re-data-breach\u002F",[15,17],"https:\u002F\u002Fwww.thesqua.re\u002F",107041,"known",null,"unknown","High",[24,25,26,27],"Email addresses","Geographic locations","Names","Phone numbers","\u003Cp>TheSqua.re data breach is an incident dated June 2025 that affected the contact information of customers seeking serviced apartments and corporate accommodation services. Since the brand is a platform offering both short- and long-term accommodation options, the exposed fields should be considered not only as general contact information but also in the context of travel and accommodation. The verified scope is based on 107,041 unique email addresses. The breached data included email addresses, names, phone numbers, and city or geographical location fields. There is no reliable evidence that passwords, payment cards, passports, official ID numbers, or reservation contents were within the verified scope.\u003C\u002Fp>\n\u003Cp>The significance of this event from the user's perspective is that the communication information matches the accommodation interest. An attacker can combine email, name, phone, and city information to create convincing messages themed around accommodation offers, reservation updates, payment reminders, loyalty point notifications, or customer support. The entire dataset may not carry the same level of detail for every user; some accounts contain only basic contact fields, while others, including phone and city information, allow for stronger targeting. Therefore, the risk should be considered in the context of targeted fraud, unwanted calls, fake support messages, and matching with other datasets, rather than simply a password-stealing scenario.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types are email addresses, names, phone numbers, and geographic location or city fields. An email address can be a key indicator to find out whether the user has opened accounts on other services with the same address. When the name field is added, an attacker can personalize the message; when a phone number is added, SMS, calls, and fake customer representative scenarios become more convincing. City or location information can be associated with the user's travel preferences, possibility of moving, interest in business trips, or search for accommodation in a specific area. This combination, although not as directly evident as a password leak alone, holds significant value in terms of social engineering.\u003C\u002Fp>\n\u003Cp>Since the password and payment information have not been verified, users should not mistakenly interpret the incident as a financial card leak. The severity of the risk comes from the currency and contextual nature of contact information. In the hospitality sector, name, phone, and city information can be used in fake messages themed around cancellation, deposit, early check-in, invoice, corporate stay, or special offers. For people seeking corporate accommodation, a business email, even if not combined with the company name, can give the impression of a corporate connection. Therefore, affected users should consider messages that appear to be related to accommodation or travel but contain unexpected links as suspicious.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The confirmed breach date is tracked as June 27, 2025, and the record was added to extensive breach indexes on August 27, 2025. The total impact is at the level of 107,041 unique email accounts. Reliable breach records indicate that the data is associated with TheSqua.re customers and includes fields for name, phone, and email along with city information. More limited security reports show that the incident became visible through forum sharing, and in some counts, the number of rows and the number of unique individuals were reported differently. Therefore, the number of unique emails should be used as the main metric, and the number of rows should not be confused with the number of users.\u003C\u002Fp>\n\u003Cp>Areas excluded from the scope are at least as important as the scope itself. There is no verified leak evidence for passwords, payment cards, bank accounts, passports, official IDs, and full reservation content. Additionally, data from other platforms in the same industry as TheSqua.re should not be combined with this incident. The breach is classified as a data incident related to serviced apartment search and customer communication processes. The fields shown to the user should be limited to verifiable data types; additional fields mentioned in forum claims but with weak independent verification should not be expanded in the public scope.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Individual users looking for accommodation through TheSqua.re, people planning to move, employees researching long-term out-of-town stays, and individuals with corporate travel plans are the main risk groups. Users who leave a request with a work email can be targeted with fake corporate accommodation offers or invoice-themed messages. Users who share their personal phone numbers become more vulnerable to call and SMS fraud. In accounts with city information, the attacker can tailor the message according to a specific region or travel need; this creates a more convincing social engineering risk rather than simple spam.\u003C\u002Fp>\n\u003Cp>Old requests can also pose a risk. Even if a user searched for short-term accommodation years ago and did not use the service, their email and phone information may still be valid. The impact is particularly broader if the same email address is used for work, travel, shopping, and financial accounts. Information becomes more sensitive for individuals searching for reservations for family members, requesting accommodation on behalf of a company, or looking for temporary accommodation in different countries. Such a user may have difficulty distinguishing fake messages from legitimate messages from travel companies in the future.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>A user who sees they have been affected should first check their session, contact, and notification preferences on their TheSqua.re account. Multi-factor authentication should be enabled on critical accounts that use the same email address, with priority given to email accounts, password managers, financial accounts, and travel platforms. Even though a password leak was not confirmed in this incident, if the same password has been used in many places for a long time, it would be appropriate to change it. Accommodation offers, payment reminders, reservation changes, or links themed around customer service should not be opened directly; the user should access the service by manually entering the address in their browser.\u003C\u002Fp>\n\u003Cp>Affected users should not share payment, identity, card, or account recovery information during unexpected calls. The authenticity of the caller should only be verified through an independent channel. It should be remembered that messages mentioning city information may appear more convincing; for example, an email referring to a city where the user previously searched for accommodation should not automatically be considered trustworthy. Corporate users can ensure caution against fake accommodation and invoice messages by informing their company's travel or human resources teams.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, using a separate email address or an alias for travel and accommodation accounts reduces data accumulation. The phone number should only be shared in mandatory fields, and unnecessary profile fields should be cleared, if possible, after the reservation is completed. Users should regularly review old accommodation, event, and offer accounts; they should either delete personal information from accounts that are no longer used or close the account. This way, the amount of data that could be exposed in a similar event in the future will be lower.\u003C\u002Fp>\n\u003Cp>Separate mailing groups, supplier verification steps, and invoice approval controls should be used for travel and accommodation procurement processes on the corporate side. Employees' use of the company email for individual accommodation searches can be restricted. In security trainings, fake accommodation messages containing real city and phone information should be used as sample scenarios. Individual users should also maintain the habit of using a password manager, strong multi-factor authentication, and regular leak checks. This approach cannot completely reverse a single data incident; however, it significantly reduces the likelihood of subsequent misuse.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The user whose result appears on TheSqua.re should consider this incident as an identity and communication data leak. The first step is to secure the email account, and then review travel, accommodation, finance, and shopping accounts used with the same email. If the phone number and city information are also affected, more caution should be taken against SMS, calls, and location-specific offer messages. If the user has a real accommodation request or past reservation inquiry, it should be considered that this context could be used in fake messages.\u003C\u002Fp>\n\u003Cp>A match on the results screen does not necessarily mean that the user's password or payment card has been definitively leaked. Verified fields are limited to email, name, phone, and location level. Nevertheless, this data set may be sufficient for targeted fraud. Before deleting suspicious messages, users can forward the subject, sender, and link details to the security team or the relevant service provider. Notifications should be kept on for critical accounts, session histories should be reviewed from time to time, and unexpected payment requests related to the hospitality sector should not be accepted without independent verification.\u003C\u002Fp>","","TheSqua.re Data Breach (107 Thousand Reported Records)","TheSqua.re Data Breach. 107 Thousand reported records were reported. Reported data: Email addresses, Geographic locations, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fthesqua_re.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Serviced apartments and hospitality","United Kingdom"]