EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/cash-app-breach-2021
170/430

File EL-0261HighResolvedData Breach / Insider Threat

Cash App Block Insider Data Breach

Also filed as Block Inc. Insider Data Leak · Former Employee Data Theft

This incident involved the unauthorized exfiltration of sensitive user data from Cash App, a financial technology platform owned by Block Inc. The breach was attributed to a former employee who misused internal access credentials. The leaked data included personal identifying information (PII) and financial records belonging to millions of users.

  • #cash-app
  • #block-inc
  • #insider-threat
  • #pii-leak
  • #data-breach
  • #credential-theft
Notoriety6/10
Event
10 Dec 2021
Disclosed
10 Dec 2021
Target
Cash App / Block Inc.
Actor
Former Cash App Employee
Scale
8.2M people
Status
Resolved

01Summary

The breach occurred when a former employee of Cash App accessed and downloaded a massive dataset containing user information. The data leak was reported to affect approximately 8.2 million individuals. The compromised information included names, email addresses, phone numbers, and potentially financial transaction details. The incident highlighted significant internal security vulnerabilities related to offboarding procedures and access control management within the FinTech sector. Block Inc. subsequently initiated internal reviews and enhanced its data governance protocols to mitigate future risks.

02Background

Cash App is a widely used peer-to-peer payment service, making its user data highly valuable to malicious actors. The incident occurred during a period of rapid growth and increased scrutiny on FinTech security practices following several high-profile industry breaches. The vulnerability exploited was related to the retention of excessive access privileges by departing staff.

03Key revelations

  1. 01The breach confirmed the existence of a large, centralized database of user PII and financial data.
  2. 02The incident exposed critical weaknesses in corporate offboarding and access revocation policies.
  3. 03The scale of the leak demonstrated the high value of FinTech user data on the black market.

04Technical analysis

The attack vector was internal, utilizing legitimate, but unauthorized, access credentials belonging to a former employee. The method involved bulk data extraction (exfiltration) of records from internal databases. The data was likely compiled from multiple sources, including user account databases and transaction logs, indicating a high level of internal system knowledge was required.

Attack vector
Internal Access / Misuse of Credentials
Attack method
Data Exfiltration
Initial access
Former Employee Credentials
Lateral movement
Internal Network Access
Exfiltration
Bulk Data Download
Malware type
Stealer / Exfiltration

Vulnerabilities exploited

  • Insufficient Offboarding Security

MITRE ATT&CK techniques

  • T1022
  • T1560

05Threat actor

This was not a group operation but an individual act of corporate espionage or malice. The perpetrator leveraged authorized access, making the attack highly targeted and difficult to trace without internal logs.

Aliases

  • Insider Threat

MITRE groups

  • T1136.001
  • T1022

Attribution sources

  • Media Reports
  • Company Statements

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Email Addresses
  • Phone Numbers
  • Financial Records
  • User Credentials

Notable documents

  • User Database Dump

08Financial damage

Damage estimate is speculative, related to regulatory fines and reputational harm.

09Timeline

  1. 2021-12-10Breach discovered and publicly disclosed.

10Reaction and fallout

Public reaction

The public reaction was characterized by immediate concern regarding the security of personal financial data. Media coverage focused heavily on the need for stronger regulatory oversight of FinTech companies handling sensitive PII.

Political impact

The incident increased political pressure on financial technology companies to adopt stricter, auditable security standards. It fueled discussions about the necessity of federal data protection legislation tailored for the digital economy.

11Legal

While specific criminal charges against the former employee were not widely publicized, the incident prompted internal legal reviews and potential civil litigation regarding data misuse.

Civil lawsuits

  • Class Action Lawsuits (Potential)

12Aftermath

Policy changes

  • Enhanced Employee Offboarding Protocols
  • Mandatory Least Privilege Access Review

Regulatory changes

  • Increased Scrutiny under CCPA/GDPR for FinTechs

Security improvements

  • Zero Trust Architecture Implementation
  • Immediate Revocation of All Former Employee Access

13Significance and legacy

Significance

This breach is significant because it represents a textbook example of an insider threat exploiting systemic weaknesses in corporate access management. It set a precedent for the heightened scrutiny of employee offboarding procedures across the entire FinTech industry, moving security focus from external perimeter defense to internal process control.

Legacy

The incident contributed to the industry-wide shift toward 'Zero Trust' security models, emphasizing continuous verification of every user and device, regardless of their physical location or previous employment status. It also increased the legal and financial risk associated with poor data governance.

14Disclosure and media

Authentication
Internal Source Confirmation

Media partners

  • TechCrunch
  • Bloomberg

15Field notes

  1. 01The breach was primarily focused on non-financial PII, which often makes the data more valuable for identity theft and account takeover attempts.
  2. 02The incident underscored the difficulty of securing data access when employees transition out of the company's ecosystem.

16Resolution

Block Inc. issued public statements detailing the scope of the breach and confirming that the compromised data was contained to non-financial PII, though the risk remained high.

17Sources

Official documents

  • Internal Security Audit Reports (Confidential)

References

  1. [1]TechCrunch Reporting
  2. [2]Block Inc. Press Releases
Fact sheetEL-0261

Dates

Event
10 Dec 2021
Started
10 Dec 2021
Discovered
10 Dec 2021
Disclosed
10 Dec 2021
Ongoing
No

Target

Organisation
Block Inc.
Type
Technology Company
Sector
Financial Technology (FinTech)
Country
United States

Actor

Name
Former Cash App Employee
Type
Corporate Insider
Affiliation
Cash App / Block Inc.
Motivation
Financial gain or malicious intent (unspecified)
Attribution
High
Arrested
No
Convicted
No

Data

People
8,200,000
Records
8,200,000
Volume
Unknown (Millions of records)
Sensitivity
Confidential
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.