Notion User Database Allegedly Offered on the Dark Web: 150 Million Records Claimed in Unverified Sale + Video

Listen to this Post

Featured ImageA Massive Database Claim Raises Fresh Questions About Notion Users

A disturbing database claim has surfaced on an underground forum, where a threat actor is allegedly advertising more than 150 million unique Notion user records for sale. If authentic, the dataset could represent one of the more significant collections of user information associated with a productivity and collaboration platform in recent years.

But there is an important distinction between a dark-web claim and a confirmed breach.

At the time of the report, there was no independent evidence proving that Notion itself had been compromised. The seller’s claims about the size, origin, freshness, and authenticity of the database remain unverified. The records could have come from an unrelated breach, multiple older datasets, credential-stuffing collections, scraping, third-party services, or some combination of previously exposed information.

That uncertainty is critical. A database appearing on a criminal marketplace does not automatically mean the company named in the listing was hacked.

Nevertheless, the alleged contents deserve attention.

What the Threat Actor Claims to Have

According to the underground listing, the database allegedly contains more than 150 million unique records connected to Notion users.

The advertised information reportedly includes email addresses, hashed passwords, registration dates, account activity information, signup and last-login IP addresses, locale information, time zones, countries, and workspace-related metadata.

The seller has also reportedly provided a sample that appears to demonstrate the structure of the alleged dataset.

If those samples accurately represent the full database, the information could provide attackers with considerably more intelligence than a simple list of email addresses.

Why 150 Million Records Would Be Significant

A dataset of 150 million unique records would be enormous.

Even if only a fraction of the records were current, the information could potentially be used for targeted phishing, identity correlation, credential attacks, social engineering, account discovery, and reconnaissance against organizations whose employees use collaborative productivity platforms.

The number itself, however, should not be treated as proof.

Threat actors frequently exaggerate database sizes to attract buyers, increase perceived value, or create urgency. A seller may also count duplicate records, historical entries, multiple records belonging to the same individual, or information aggregated from unrelated sources.

The phrase “150M+ unique records claimed” should therefore remain attached to the number until independent evidence establishes otherwise.

The Alleged Password Data Is the Most Concerning Element

The reported inclusion of hashed passwords is particularly important.

A hashed password is not normally equivalent to a plaintext password. Properly designed password-storage systems use cryptographic hashing and additional protections to make recovering the original password difficult.

However, not all password hashes are equally protected.

The security implications depend on the hashing algorithm, whether passwords were salted, the configuration used to generate the hashes, password strength, and whether attackers can obtain enough information to conduct offline cracking attempts.

Even strong password hashing does not make an exposed credential database irrelevant.

Users often reuse passwords across multiple services. An attacker who successfully recovers passwords from an old or poorly protected dataset could attempt those credentials against unrelated websites.

IP Addresses Turn a Database Into a Reconnaissance Tool

The alleged inclusion of signup and last-login IP addresses adds another layer of risk.

IP addresses can provide attackers with clues about geographic locations, networks, service providers, organizational infrastructure, and patterns of account activity.

An IP address alone does not necessarily identify a person or physical location precisely. But when combined with an email address, country, timezone, account history, and workspace metadata, it can become considerably more useful for profiling.

That combination is what makes large datasets dangerous.

Workspace Metadata Could Expose Organizational Relationships

Notion is widely used for documentation, project management, internal knowledge bases, planning, collaboration, and company workflows.

If the alleged workspace metadata is genuine, attackers could potentially gain clues about organizational structures and relationships.

A record might reveal that an account belongs to a particular domain, geographic region, or workspace environment. Even without access to private documents, such information could help an attacker identify likely employees, administrators, contractors, or business relationships.

This is why metadata should never automatically be dismissed as harmless.

The Difference Between a Notion Breach and a Database Containing Notion Users

One of the most important points in this case is provenance.

A database can contain information about Notion users without necessarily being stolen from Notion.

For example, the information could theoretically originate from another service where users registered with the same email address. It could also have been compiled from previous breaches, public information, data brokers, malware infections, credential dumps, third-party integrations, or historical exposures.

An attacker could then label the resulting collection as a “Notion database” because the records are associated with Notion accounts.

That would be fundamentally different from compromising

Dark-Web Sellers Have an Incentive to Overstate Their Claims

Criminal marketplaces operate on reputation, money, and perceived exclusivity.

A seller claiming to possess 150 million records has a strong incentive to make the dataset appear valuable.

That does not mean the claim is false. It means the claim should be treated as an allegation until evidence supports it.

The presence of a sample can increase credibility, but even samples require verification. Attackers can provide genuine-looking records copied from older incidents or publicly available sources.

The real question is not simply whether the sample contains real Notion users.

The real question is where the data came from, when it was obtained, how it was collected, and whether the seller actually possesses the larger dataset being advertised.

The

The underground account reportedly dates back to July 2023 and currently has VIP status, 41 posts, and a reputation score of 17.

Those details may provide some context about the seller’s history within the forum.

However, forum reputation is not the same thing as independent verification.

Criminal marketplaces can contain fraudulent sellers, compromised accounts, recycled datasets, misleading advertisements, and reputation manipulation. A long-lived account may make a claim more interesting to investigators, but it does not establish the authenticity of a database.

Why the Sample Matters

Samples are often the first technical clue investigators examine when evaluating underground database claims.

Researchers can compare sample records against known historical information, examine formatting patterns, identify timestamps, inspect field structures, search for duplicate entries, and determine whether supposedly private information was already available elsewhere.

A sample can also reveal whether the database appears to have been generated recently or assembled over a long period.

For example, a dataset containing accounts that were supposedly deleted years ago would raise very different questions from one containing recent account activity.

The Freshness Question Is Critical

A database may be genuine but still be old.

This distinction is frequently overlooked.

A threat actor could possess a legitimate collection containing millions of historical records and advertise it as a current database. If many users have changed passwords, abandoned accounts, changed email addresses, or moved organizations, the practical value of the dataset could be considerably lower than its headline size suggests.

Conversely, a large amount of recent activity data would make the situation considerably more serious.

Freshness therefore matters almost as much as authenticity.

What Organizations Should Watch For

Organizations using Notion should pay attention to unusual authentication activity, unexpected password-reset requests, suspicious login notifications, phishing messages, and unusual account behavior.

Security teams should also monitor for social-engineering attempts referencing legitimate company projects, internal terminology, workspace names, employee relationships, or other information that could plausibly have been derived from exposed metadata.

The most dangerous consequence may not be direct account takeover.

It may be increased credibility of future attacks.

Phishing Could Become More Convincing

Suppose an attacker knows an

That attacker can potentially construct a much more convincing phishing message than someone working with a generic email list.

A message could appear to come from an administrator, project manager, colleague, customer, or IT department.

This is why seemingly secondary metadata can become operationally valuable.

Credential Reuse Remains a Major Risk

If the alleged database contains password hashes and those hashes are eventually compromised, password reuse could become a significant concern.

Users should never reuse passwords between unrelated services.

Organizations should encourage unique credentials, strong authentication controls, phishing-resistant multi-factor authentication where possible, and centralized identity management.

Security teams should also monitor for leaked corporate credentials across relevant threat-intelligence sources.

Multi-Factor Authentication Changes the Equation

Multi-factor authentication can substantially reduce the value of stolen passwords.

An attacker may know a username and password but still face another authentication barrier.

However, MFA is not an absolute defense.

Attackers increasingly target authentication sessions, recovery processes, social-engineering workflows, and users themselves. Stronger authentication methods, especially phishing-resistant approaches, provide better protection than relying solely on passwords and basic one-time codes.

The Corporate Impact Could Extend Beyond Individual Accounts

If the alleged information is genuine and current, organizations could face risks beyond individual user accounts.

Employees often use collaboration platforms as gateways into business processes. Even if an attacker cannot directly access confidential workspaces, compromised accounts can potentially become stepping stones for social engineering or broader intrusion attempts.

An attacker might use one compromised identity to learn organizational terminology and identify additional targets.

This creates the possibility of a chain reaction.

Why

The distinction between “Notion users appear in a leaked dataset” and “Notion was breached” is not merely technical wording.

It is the difference between an evidence-based cybersecurity report and an unsupported attribution.

At this stage, the available claim establishes that an underground seller is allegedly offering a dataset associated with Notion users.

It does not establish how the data was obtained.

That question requires further investigation.

Potential Sources of the Alleged Dataset

There are several possible explanations for the appearance of such a database.

One possibility is a direct compromise of a company or service holding the information.

Another possibility is a breach at a third-party provider.

A third possibility is credential-stealing malware that collected account information from infected devices.

The dataset could also represent an aggregation of multiple previous incidents.

Finally, it could be an exaggerated or fraudulent listing.

Without forensic evidence, all of these possibilities must remain open.

Data Aggregation Makes Attribution Harder

Modern cybercrime increasingly relies on aggregation.

Attackers do not always need to compromise a major company directly. They can collect information from thousands of smaller incidents and combine it into a single database.

An email address from one breach can be matched with a password hash from another. A phone number can be linked to a social profile. An IP address can be correlated with a historical login record.

Over time, separate fragments can become a surprisingly detailed profile.

This is one reason why old breaches can continue to create risk years after the original incident.

The 150 Million Figure Should Be Independently Tested

The headline number deserves skepticism until researchers can determine how the seller calculated it.

Investigators would ideally examine the

If a supposed 150-million-record dataset contains substantial duplication, the actual number of unique individuals could be much smaller.

Likewise, if many records are decades-old or unrelated to Notion, the advertised figure could be technically large but operationally misleading.

The Most Important Question Is Provenance

Provenance means understanding the history of the data.

Where did it originate?

When was it collected?

Which system originally stored it?

Was it obtained directly or indirectly?

Was it generated through automated collection?

Was it combined from previous breaches?

Has the information appeared elsewhere?

These questions matter more than the

A Breach Claim Should Never Be Confirmed Solely by a Dark-Web Advertisement

Threat intelligence is often built from incomplete information.

Analysts may discover a forum post before a company has even been notified. Researchers may find samples before they understand their origin. Companies may need time to investigate logs and determine whether their infrastructure was involved.

That is why responsible reporting uses language such as “allegedly,” “claimed,” “unverified,” and “potentially.”

Those terms are not weakness.

They are evidence discipline.

What Users Should Do Now

Users who rely on Notion or other cloud collaboration platforms should review account security without assuming that this particular claim has been confirmed.

Use a unique password.

Enable MFA where available.

Review active sessions and account activity.

Be suspicious of unexpected password-reset messages.

Avoid clicking authentication links delivered through unsolicited email or messaging platforms.

If a password has been reused elsewhere, change it on the other services as well.

What Security Teams Should Do

Security teams should monitor authentication logs for unusual locations, impossible-travel patterns, suspicious device changes, repeated failed authentication attempts, unexpected password resets, and unusual account recovery activity.

Organizations can also review whether employee credentials appear in known exposure datasets.

Where appropriate, identity providers should be configured to require stronger authentication for privileged users and high-risk sessions.

The objective should be to reduce the value of stolen credentials before attackers can use them.

Defensive Investigation Commands

For defenders investigating possible exposure, simple local searches can help identify suspicious authentication patterns without interacting with criminal infrastructure.

For example, security teams can search authentication logs for repeated failures:

grep -Ei "failed|failure|invalid|authentication" /var/log/auth.log

Administrators can also search for unexpected password-reset or account-recovery events within their identity platform’s legitimate audit tools.

For Windows environments, defenders can investigate relevant authentication events through Windows Event Viewer or PowerShell rather than relying on underground samples.

The important principle is to investigate your own telemetry and authorized security data, not attempt to access criminal marketplaces or unauthorized systems.

Deep Analysis: What the Alleged Database Could Mean
Command 1: Separate the Claim From the Evidence

The first analytical step is to separate what the seller says from what investigators can independently establish.

The claim is that more than 150 million Notion-related records exist.

The evidence presented publicly is an underground advertisement and an apparent sample.

Those are not equivalent.

Command 2: Establish Dataset Provenance

The next step is determining whether the records originated from Notion, another service, malware infections, previous breaches, public information, or data aggregation.

Provenance is the central unresolved issue.

Command 3: Test the

Investigators should examine timestamps and account activity indicators.

A dataset filled with current records would be considerably more concerning than one composed primarily of historical information.

Command 4: Measure Uniqueness

The advertised number should be tested against duplicates and repeated identities.

“150 million records” does not necessarily mean “150 million individual people.”

Command 5: Analyze Password Protection

If password hashes are genuinely included, analysts need to determine the hashing format and security properties.

The mere presence of hashes does not prove that passwords can be recovered.

Command 6: Analyze Metadata Exposure

IP addresses, timezones, countries, registration dates, and workspace information should be treated as intelligence assets.

Attackers can combine individually modest pieces of information to create highly useful profiles.

Command 7: Compare Against Historical Breaches

Researchers should determine whether the sample appears in previously documented incidents.

A match with an older breach would substantially change the interpretation of the listing.

Command 8: Examine Organizational Clustering

If many records belong to the same corporate domains, researchers can investigate whether those accounts share common infrastructure or historical exposure patterns.

Such clustering could help establish the

Command 9: Watch for Secondary Attacks

A major leak can generate follow-on campaigns.

Phishing, password spraying, impersonation, fake support messages, and account-recovery scams may appear even if the original database is only partially authentic.

Command 10: Avoid Premature Attribution

The final analytical command is restraint.

Until evidence establishes the source, the responsible conclusion remains that a threat actor claims to possess a large Notion-related database.

That is serious enough to monitor.

It is not enough to declare a confirmed Notion breach.

What Undercode Say:

The Claim Is Serious, But the Headline Must Remain Cautious

The alleged 150-million-record database is attention-grabbing, but the strongest part of the report is actually the uncertainty surrounding it.

Cybersecurity reporting becomes unreliable when an underground advertisement is immediately transformed into a confirmed breach.

The available information supports reporting the claim.

It does not yet support definitive attribution.

The

A huge database is not automatically catastrophic.

A smaller dataset containing fresh credentials for privileged corporate users could be more dangerous than hundreds of millions of outdated email addresses.

The practical risk depends on freshness, authenticity, sensitivity, and exploitability.

Hashed Passwords Raise the Stakes

If the password information is genuine, investigators should take the claim seriously.

But the security implications depend heavily on how those passwords were protected.

Strong, properly salted password hashes are fundamentally different from weak or improperly implemented hashes.

The report should therefore avoid implying that the alleged database automatically contains usable plaintext passwords.

Metadata Can Be More Dangerous Than It Looks

IP addresses and workspace information might appear secondary compared with passwords.

In targeted attacks, however, metadata can be extremely valuable.

It helps attackers understand who users are, where they operate, when they are active, and how they may relate to an organization.

That can make future social engineering considerably more believable.

The Dark Web Is a Marketplace of Both Data and Deception

Underground forums contain real stolen information.

They also contain scams, exaggerated claims, recycled databases, fake samples, and compromised accounts.

Researchers therefore need to treat every listing as an intelligence lead rather than an established fact.

The

VIP status and forum history may indicate that the account has been active.

They do not prove the database is legitimate.

Reputation can be manipulated, purchased, inherited through compromised accounts, or simply irrelevant to the authenticity of a specific listing.

A Sample Is Not the Whole Dataset

Even a genuine sample does not automatically validate the seller’s full claim.

The sample could be old.

It could come from another source.

It could represent only a tiny subset.

It could also have been selected specifically to make the listing appear convincing.

Independent correlation is therefore essential.

The Biggest Risk May Be Social Engineering

If exposed information includes email addresses, locations, timestamps, and workspace information, attackers may not need to crack passwords immediately.

They can use the information to build believable narratives.

A convincing phishing message can sometimes be more effective than a technically sophisticated attack.

Organizations Should Assume Metadata Has Value

Security teams should treat organizational metadata as sensitive intelligence.

Knowing which employees work in a particular timezone, which domains belong to an organization, or which accounts appear active can help attackers prioritize targets.

This is particularly relevant for administrators and employees with access to sensitive systems.

Credential Reuse Remains a Persistent Weakness

The alleged database also highlights an old cybersecurity problem: password reuse.

One exposed password can become a key to multiple services if the same credential has been reused elsewhere.

Unique passwords and strong authentication remain among the most effective defenses against this type of cascading risk.

MFA Can Reduce the Blast Radius

Even if credentials are exposed, MFA can prevent some forms of account takeover.

Organizations should increasingly prioritize phishing-resistant authentication for administrators, privileged accounts, and high-value business applications.

Security is strongest when stolen passwords alone are insufficient.

The 150 Million Figure Requires Verification

The number is extraordinary.

Extraordinary numbers require extraordinary verification.

Until independent researchers establish the record count, it should remain described as a claim.

This is particularly important because cybercriminal sellers sometimes use enormous numbers as a marketing mechanism.

Attribution Is the Missing Piece

The central unanswered question is where the alleged records originated.

If they came directly from Notion, the implications would be severe.

If they came from a third-party service, the incident would need to be attributed elsewhere.

If they were assembled from historical breaches, the situation would represent aggregation rather than a new Notion intrusion.

If the claim is fraudulent, the headline number may mean very little.

Timing Will Reveal More

The next several days and weeks could be important.

Independent researchers may analyze the sample.

Organizations may begin identifying suspicious activity.

Security researchers may correlate the records with previous incidents.

Notion or relevant security teams may also have an opportunity to investigate whether their infrastructure was involved.

More evidence should gradually narrow the possibilities.

The Most Responsible Position Is Unverified

For now, the correct description is straightforward:

A threat actor allegedly claims to be selling a database containing more than 150 million Notion-related user records.

That is a significant threat-intelligence lead.

It is not yet a confirmed Notion breach.

What This Means for the Wider Security Industry

The episode demonstrates how modern data exposure increasingly works.

Attackers do not necessarily need a single spectacular intrusion.

They can accumulate fragments from different sources until those fragments become a valuable intelligence package.

This makes old breaches, credential leaks, malware infections, and exposed databases part of the same long-term ecosystem.

The Real Lesson Is Bigger Than Notion

Whether this particular database proves authentic or not, the underlying lesson remains important.

Personal information has a long shelf life.

An email address may remain useful for years.

A historical IP address can still provide context.

An old password can become dangerous when reused.

A workspace identifier can reveal organizational relationships.

Attackers benefit from combining these pieces.

Security Teams Should Prepare for the Possibility, Not Panic

Organizations should not treat an unverified forum advertisement as proof of compromise.

But they also should not ignore it.

The appropriate response is measured investigation: review logs, enforce strong authentication, monitor for suspicious activity, evaluate credential exposure, and remain alert for targeted phishing.

That approach protects users without turning an allegation into an unsupported conclusion.

❌ No Confirmed Evidence of a Notion Breach

The available report does not establish that

❌ The 150 Million Record Count Is Not Independently Confirmed

The figure should be described as claimed, not established. Database size claims on criminal forums can include duplicates, historical records, aggregated information, or exaggerated numbers.

✅ The Listing Itself Is Reported as an Underground Threat Claim

The core fact that a threat actor is allegedly advertising a large Notion-related dataset is distinct from the question of whether the data originated from Notion. Those two claims should not be conflated.

Prediction

(+1) Independent Investigation Will Determine More About the Dataset

As researchers analyze samples and compare them against known breach collections, the provenance of the alleged records is likely to become clearer.

(+1) Organizations Will Increase Monitoring for Credential Abuse

Even without confirmation of a Notion breach, companies using collaboration platforms are likely to pay greater attention to authentication anomalies, password reuse, phishing, and suspicious account-recovery attempts.

(+1) Strong Authentication Will Become Even More Important

The incident reinforces the value of MFA and phishing-resistant authentication. If credentials appear in future datasets, organizations with stronger identity controls should be better positioned to limit account takeover.

(-1) The Dataset Could Turn Out to Be Misrepresented

There remains a realistic possibility that the advertised database is significantly smaller, older, aggregated from multiple sources, or unrelated to a direct Notion compromise.

(-1) A Genuine Dataset Could Still Be Misleadingly Attributed

Even if the sample proves authentic, that would not automatically prove that Notion was the source. Investigators will still need to establish the chain of custody and original collection point.

Final Assessment

A Major Claim, But Not Yet a Confirmed Breach

The alleged sale of more than 150 million Notion-related records is significant enough to warrant attention from security researchers, organizations, and users.

But the most important word in the story remains “allegedly.”

There is currently a substantial difference between a threat actor claiming to possess a massive database and investigators proving that the database is genuine, current, unique, and sourced from Notion.

Evidence Must Come Before Attribution

If the database proves authentic and contains current email addresses, password hashes, IP addresses, account activity information, and workspace metadata, the potential impact could be considerable.

If it instead turns out to be an aggregation of historical breaches or unrelated datasets, the story would have a very different meaning.

For now, the safest and most accurate conclusion is that a dark-web seller is claiming to possess a massive Notion-related user database, while the database’s authenticity, provenance, freshness, and reported 150-million-record size remain independently unverified.

That distinction is not a footnote.

It is the central fact of the story.

▶️ Related Video (76% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube