On March 24, 2026, Whitepages detected an unusual spike in login attempts on its site. The company’s investigation determined this was a credential stuffing attack, a type of hacking or system intrusion in which someone uses usernames and passwords already stolen from other, unrelated websites to try logging into accounts elsewhere. Whitepages says it was not the source of the stolen credentials, but if you reused a password from another site on your Whitepages account, that account may have been accessed during the attack.
The notice is directed at Whitepages account holders whose credentials matched those attempted during the March 24, 2026 incident. Whitepages has not said how many people were affected in total, and states it has found no evidence so far that any accessed information has been used for fraud or identity theft.
What information was exposed?
- Full name
- Email address
- Lookup and order history on Whitepages
- Partial payment card information (last 4 digits and card type only — the company says full card numbers are never accessible via account login)
Whitepages has not announced any free credit monitoring or identity protection service in connection with this incident. Its main recommendation is that affected users reset their account password promptly.
What should you do now?
- Reset your Whitepages password right away, and choose a strong, unique password you don’t use anywhere else.
- If you used the same password on other websites, change those passwords too, since attackers who obtained your Whitepages credentials may try them elsewhere.
- Turn on multi-factor authentication for any account that offers it, including email and financial accounts.
- Watch your payment card statements for unfamiliar charges, since partial card details were viewable through affected accounts.
- Be cautious of emails or messages referencing your Whitepages account, lookups, or order history, since scammers sometimes use exposed details to make phishing attempts look legitimate.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially if you tend to reuse passwords across sites.
- Use a password manager to generate and store unique passwords for each of your accounts going forward.
If you have questions, Whitepages can be reached at [email protected].