A threat actor claims to have stolen approximately 1.9 million records from the Toledo Zoo & Aquarium after allegedly exploiting a zero-day vulnerability in an unnamed third-party system.
The alleged database was offered for sale on an underground cybercrime forum on Aug. 25 for $800. The seller claims the dataset contains personally identifiable information associated with zoo members and other individuals.
BreachNews reviewed a sample accompanying the claim containing 999 records. The sample includes fields for names, spouse information, street addresses, phone numbers, email addresses, membership information, county, children counts and other account-related information. BreachNews is not publishing any of the personal information contained in the sample.
Sample supports claimed data types
The forum post describes the material as a database obtained from the Toledo Zoo in August 2026 and claims approximately 1.9 million records were extracted.
The sample reviewed by BreachNews contains 38 database fields, including first, middle and last names, spouse details, addresses, phone numbers, email addresses, membership levels, membership start and end dates, membership status and county information.
Other fields include the number of children associated with a record and whether an individual is marked as deceased. Some rows in the sample contain populated personal information, while other fields are blank depending on the record.
The presence of data matching the seller’s description provides additional substance to the claim, but it does not independently establish that 1.9 million records were stolen or verify the attack method described by the threat actor.
Attacker claims third-party zero-day exploitation
The threat actor alleges the database was obtained by exploiting a zero-day vulnerability affecting a third-party system used by the zoo.
No software vendor, affected product or vulnerability identifier was provided, leaving the alleged initial access method unverified. It is also unclear whether the claimed vulnerability affected software hosted directly by the Toledo Zoo or an external service provider.
The seller is offering the purported database for $800 and claims the price is negotiable. BreachNews is withholding the actor’s identity, contact information and links used to distribute or sell the data.
Toledo Zoo has a large membership base
The Toledo Zoo & Aquarium is a nonprofit zoological organization in Toledo, Ohio. According to the zoo, it is home to more than 16,000 animals representing more than 680 species and has more than 78,000 active membership households.
That membership footprint makes the alleged exposure of membership-related information particularly significant. If the wider dataset contains the same categories visible in the sample, affected individuals could face phishing, impersonation and other social engineering risks because contact details can potentially be combined with household and membership information.
The sample reviewed by BreachNews did not establish that payment card numbers, passwords or Social Security numbers were included in the alleged dataset.
Claim remains unconfirmed
BreachNews has not independently verified the attacker’s claim that 1.9 million records were obtained, nor the allegation that a zero-day vulnerability was used to access the data.
The Toledo Zoo & Aquarium had not issued a public statement addressing the alleged breach at time of publication. Its public website remained operational when checked by BreachNews.
The existence of a sample containing data consistent with the seller’s description increases the credibility of the underlying data claim, but further confirmation would be required to establish the source, complete scope and circumstances of the alleged breach.











