Egidio
Case file Β· August 23, 2026

iMapper.tech: 2,463 accounts claimed via a named CVE, unconfirmed

The hacker "0xSec" claims 2,463 accounts at iMapper.tech, a laser measurement tool for construction professionals, citing a specific CVE. Not confirmed by the company.

⚠️ Claimed, unconfirmed β€” a modest volume but a specific technical flaw. Unlike the large-scale claims documented elsewhere on this site, this one covers a limited volume (2,463 accounts) and cites a specific CVE reference, making it more technically checkable β€” without that confirming it.

The numbers

2,463
Rows from the user accounts table claimed by the hacker "0xSec."
Claim reported, not confirmed by iMapper.tech.
9
Data categories in the sample: identifiers, usernames, password hashes, emails, phone numbers, roles, Stripe identifiers, MFA settings, tax parameters.
Sample published by the hacker.
CVE-2026-72898
Vulnerability reference cited by the hacker β€” its validity is not independently verified.
Hacker's claim, unverified.
1
Database table claimed as accessed ("accounts") β€” the hacker mentions other potentially accessible tables, without detail.
Hacker's claim.

Timeline

CLAIMED
August 22, 2026
The hacker "0xSec" publishes a claim on a criminal forum concerning iMapper.tech, a connected 2D laser measurement solution for construction professionals: 2,463 rows from the user accounts table, citing reference CVE-2026-72898.
UNCONFIRMED
Since
The authenticity of the data, the real number of accounts affected, the content of the other tables mentioned, and the validity of the cited CVE itself remain to be confirmed. No public acknowledgment from iMapper.tech has been identified to date.

🎯Small volume, precise professional target

This case file illustrates a different profile from the large consumer breaches documented elsewhere: a niche B2B tool, a limited volume, but Stripe identifiers and password hashes potentially exposed. For the few thousand construction professionals using this tool, the individual risk isn't lower than a multi-million-row leak β€” it's just concentrated on a smaller audience.

What it changes for you

If you're a professional user of iMapper.tech, your email, password hash and Stripe identifiers could be in this claim β€” pending confirmation. As a precaution, change your password and check your associated Stripe account activity. See From Leak to Scam.

πŸ”’ A password hash isn't the plaintext password, but if it's weak or reused elsewhere, it can be cracked and tested against other services β€” change this password everywhere you reused it.

Frequently asked questions

Is the iMapper.tech leak confirmed?

No, it's a claim by the hacker "0xSec," citing a specific CVE, with no public confirmation from the company.

What is iMapper.tech?

A connected 2D laser measurement solution for construction professionals.

What data is claimed?

Identifiers, password hashes, emails, phone numbers, roles, Stripe identifiers and MFA settings for 2,463 accounts.

πŸ“Œ Last checked: August 23, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "iMapper.tech: 2,463 accounts claimed via a named CVE, unconfirmed," egidio.app/en/laboratoire/imapper-tech-cve-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.