Cybba Inc. $52,400 fine: was your data leaked? What California found
If you have an account with Cybba Inc., here’s what is being claimed, and what it would mean for you.
California fined data broker Cybba Inc. $52,400 for missing a 2025 registration deadline, not for a hack. The August 2026 order does not report stolen records or a number of people affected. The company must now stay on the state’s public registry and honor official deletion requests.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On August 13, 2026, the California Privacy Protection Agency announced a $52,400 fine against Cybba Inc., a Boston company that sells personal information for advertising. The agency’s board adopted the order on August 10, 2026. Cybba agreed to the facts and the terms.
Cybba failed to register with California’s Data Broker Registry by the January 31, 2025 deadline. After regulators contacted the company, it registered late. The agency did not allege a hack, a leak, or any unauthorized access, and it did not name a number of affected people. This case is about a missed registration, not stolen files.
The $52,400 is not the part that affects you
Most coverage leads with the fine and the missed deadline. That framing makes this sound like a late fee for paperwork.
California built the Data Broker Registry so you can see which companies sell information about people they do not have as customers — and so you can tell those companies to delete it. A broker that never registers is not on that list. You cannot opt out of a company you cannot find, and the state’s shared deletion system cannot reach them either.
Cybba’s business is selling personal information to help run targeted ads, including campaigns on Facebook, Instagram, LinkedIn, and YouTube. The agency says that information includes location data, internet activity, identifiers, commercial data, and inferences about people. None of that was reported stolen. Selling it is the product. The enforcement action puts Cybba on the public registry, onto the state’s deletion system going forward, and under a duty to publish how it handles California privacy requests.
If you came here because a headline made you think your records were dumped online, that is not what the official order describes. The quieter fact is the one that actually involves you: a company that may already have been selling data about Californians was, for a time, missing from the list built so you could stop it.
What to actually expect
- You should not expect a breach notice about stolen Cybba files. The agency did not describe a security incident or exposed records.
- If you live in California, Cybba may already have handled information about you as part of its ordinary work. The agency said the company meets the legal line of collecting or selling personal information of 100,000 or more consumers or households a year, without a direct relationship with those people.
- From here, Cybba must process California deletion requests through the state’s official deletion system in any year it operates as a data broker, and it must post the required yearly counts of requests received, granted, and denied.
- Follow-up articles you see are almost certainly the same August 2026 order being repeated. They are not a sign that a new leak has appeared.
What you can and cannot fix
What cannot be undone is any personal information Cybba already collected and sold. A fine does not pull that data back from advertisers or partners who already received it. There is no recall for a sale that already happened, and nobody has published a list of whose information was involved.
- If you are a California resident, use the state’s Data Broker Registry and its official deletion system. That is the tool this case is about, and Cybba is now required to honor requests that come through it.
- You can also send the company a deletion request under California law and read the request numbers it must now publish in its privacy policy. Those numbers will not tell you whether you specifically were included, but they show whether the company is actually responding.
- Cutting back what people-search sites publish about you still helps. Data brokers and those public listings feed each other. A thin commercial record becomes much easier to attach to a real person once it is joined to relatives, phone numbers, past addresses, and employers. Unlike a sale that already closed, many of those public listings can be removed or suppressed.
- Do not take a “clear” result from a dark-web or people-search scan as proof you were not in Cybba’s files. Those checks almost never see a data broker’s internal records, and this case never released a victim list.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
LocateSmarter data broker fine: did they sell your Social Security number?
California ordered Iowa data broker LocateSmarter LLC to pay $116,490 after it sold personal informa…
Verifications.io — 763 Million Email Records Left on an Open Database (2019)
An email-validation firm most people had never heard of left 763 million records in a MongoDB instan…
Exactis — 340 Million Records of Profiling Data Nobody Consented To (2018)
A marketing data broker left an ElasticSearch node exposed with no firewall. It held about 340 milli…