Toledo Zoo Data Breach Claim Alleges Theft of 1.9 Million Records

A threat actor is selling an alleged Toledo Zoo database containing 1.9 million records, with a reviewed sample containing membership and contact information.
Screenshot of an underground forum post offering an alleged Toledo Zoo database containing 1.9 million records, with the threat actor identity, sample link, contact details and exposed personal data redacted.
A cybercrime forum listing observed by BreachNews claims 1.9 million Toledo Zoo records were stolen through a third-party zero-day vulnerability.

A threat actor claims to have stolen approximately 1.9 million records from the Toledo Zoo & Aquarium after allegedly exploiting a zero-day vulnerability in an unnamed third-party system.

The alleged database was offered for sale on an underground cybercrime forum on Aug. 25 for $800. The seller claims the dataset contains personally identifiable information associated with zoo members and other individuals.

BreachNews reviewed a sample accompanying the claim containing 999 records. The sample includes fields for names, spouse information, street addresses, phone numbers, email addresses, membership information, county, children counts and other account-related information. BreachNews is not publishing any of the personal information contained in the sample.

Sample supports claimed data types

The forum post describes the material as a database obtained from the Toledo Zoo in August 2026 and claims approximately 1.9 million records were extracted.

The sample reviewed by BreachNews contains 38 database fields, including first, middle and last names, spouse details, addresses, phone numbers, email addresses, membership levels, membership start and end dates, membership status and county information.

Other fields include the number of children associated with a record and whether an individual is marked as deceased. Some rows in the sample contain populated personal information, while other fields are blank depending on the record.

The presence of data matching the seller’s description provides additional substance to the claim, but it does not independently establish that 1.9 million records were stolen or verify the attack method described by the threat actor.

Attacker claims third-party zero-day exploitation

The threat actor alleges the database was obtained by exploiting a zero-day vulnerability affecting a third-party system used by the zoo.

No software vendor, affected product or vulnerability identifier was provided, leaving the alleged initial access method unverified. It is also unclear whether the claimed vulnerability affected software hosted directly by the Toledo Zoo or an external service provider.

The seller is offering the purported database for $800 and claims the price is negotiable. BreachNews is withholding the actor’s identity, contact information and links used to distribute or sell the data.

Toledo Zoo has a large membership base

The Toledo Zoo & Aquarium is a nonprofit zoological organization in Toledo, Ohio. According to the zoo, it is home to more than 16,000 animals representing more than 680 species and has more than 78,000 active membership households.

That membership footprint makes the alleged exposure of membership-related information particularly significant. If the wider dataset contains the same categories visible in the sample, affected individuals could face phishing, impersonation and other social engineering risks because contact details can potentially be combined with household and membership information.

The sample reviewed by BreachNews did not establish that payment card numbers, passwords or Social Security numbers were included in the alleged dataset.

Claim remains unconfirmed

BreachNews has not independently verified the attacker’s claim that 1.9 million records were obtained, nor the allegation that a zero-day vulnerability was used to access the data.

The Toledo Zoo & Aquarium had not issued a public statement addressing the alleged breach at time of publication. Its public website remained operational when checked by BreachNews.

The existence of a sample containing data consistent with the seller’s description increases the credibility of the underlying data claim, but further confirmation would be required to establish the source, complete scope and circumstances of the alleged breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site