A threat actor has allegedly published data stolen from Bridge Storage, claiming to have exploited weaknesses in the company’s Django API to extract customer, billing, payment, and operational records from the U.S.-based self-storage and creative workspace rental provider.
The listing, published June 25, 2026, claims the breach resulted in 21 JSON datasets spanning customer accounts, invoices, contracts, payments, facility access information, and other internal business records. According to the threat actor, the data was obtained after initial access to the company’s administrative interface and subsequent exploitation of API endpoints that allegedly lacked sufficient authentication and rate limiting. The claims have not been independently verified by BreachNews.
Threat actor describes alleged API exploitation
According to the listing, the attacker first obtained access to Bridge Storage’s administrative panel before identifying what was described as a vulnerability in the company’s Django API implementation. The threat actor claims certain API endpoints could be queried without authentication or effective rate limiting, allowing large amounts of information to be extracted from the backend.
The actor further alleges that files within an access directory contain physical access permissions and customer access grants associated with tenant storage units, potentially exposing information related to facility entry.
No technical evidence has been published that independently verifies the alleged attack path or the claimed API vulnerabilities.
Alleged leak spans multiple business systems
The published archive allegedly contains 21 JSON files covering multiple areas of Bridge Storage’s operations, including customer management, billing, payments, contracts, reservations, insurance, scheduling, and facility administration.
- Customers: 5,284 records
- Invoices: 50,646 records
- Invoice line items: 159,481 records
- Payment history: 36,735 records
- Customer notes: 10,802 records
- Contracts: 599 records
- Units: 774 records
- Rental applications: 92 records
- Access control, scheduling, insurance, reservation, and lien-related data
The scope of the alleged dataset suggests attackers claim to have accessed both customer information and internal operational records rather than a single database export.
Customer records reportedly include sensitive personal information
According to the threat actor, the customer dataset contains names, company names, email addresses, phone numbers, mailing addresses, emergency contacts, alternate contacts, employer information, driver’s license details, customer vetting information, intended storage uses, Stripe customer identifiers, autopay settings, payment method metadata, internal notes, account approval information, and account creation timestamps.
The listing also references gate access codes, security questions, customer types, credit balances, and additional administrative fields used to manage tenant accounts.
BreachNews is not reproducing sample records or sensitive information published by the threat actor.
Possible Bridge AI relationship remains unverified
The threat actor speculated that Bridge Storage may be associated with Bridge AI after observing administrative email addresses using the @bridge.ai domain within the platform. BreachNews could not independently verify any relationship between Bridge Storage and Bridge AI.
Sample records published alongside the listing contain account creation and update timestamps from February 2026, suggesting at least some of the allegedly compromised information is relatively recent. The sample also includes placeholder email addresses using the reserved example.invalid domain, a format commonly used by applications when customer email addresses are unavailable. While these details may indicate the sample originated from a live application, they do not independently verify the authenticity or scope of the alleged breach.
No public statement issued
Bridge Storage had not issued any public statement regarding the alleged breach at the time of publication.
BreachNews will update this article if the company confirms an incident or releases additional information.












