B9 : 36 000 profils bancaires annoncés piratés
A French news outlet, ZATAZ, reports that approximately 36,000 bank profiles, including sensitive financial and personal data like Social Security numbers, have been leaked. The data originates from Bnine.com, a platform used by the US neobank B9. The report highlights a risk associated with fully digital banks relying on automated data collection through scraping, which can expose vulnerabilities. The leaked data is not simply a database extraction but a result of automated data collection from accessible interfaces, potentially enabling targeted fraud and phishing attacks. The report emphasizes that while the data is substantial, there’s no confirmation of a breach by B9 or the authenticity of the 36,000 profiles.
A French news outlet, ZATAZ, has reported that approximately 36,000 bank profiles, including sensitive financial and personal data like Social Security numbers, have been leaked. The data originates from Bnine.com, a platform used by the US neobank B9. The report highlights a risk associated with fully digital banks relying on automated data collection through scraping, which can expose vulnerabilities.
According to ZATAZ, the leaked data includes names, addresses, dates of birth, apartment numbers, phone numbers, email addresses, account statuses, KYC verification details, account closure reasons, and cash advance limits. Fragments of US Social Security numbers (SSN) are also present. The data is not simply a database extraction; it’s the result of automated data collection from accessible interfaces, potentially enabling targeted fraud and phishing attacks.
ZATAZ notes that fully digital banks, like B9, operate differently than traditional banks, relying on a network of interfaces – client portals, mobile apps, partner integrations – each of which can become a point of data exposure. The report emphasizes that a significant portion of the data is not a single database but a collection of profiles, making it a valuable asset for attackers.
ZATAZ states that fully digital banks, like B9, operate differently than traditional banks, relying on a network of interfaces – client portals, mobile apps, partner integrations – each of which can become a point of data exposure. The report emphasizes that a significant portion of the data is not a single database but a collection of profiles, making it a valuable asset for attackers.
ZATAZ indicates that the data is particularly useful for crafting convincing phishing attacks. Individuals already facing banking restrictions are more likely to respond to messages appearing to come from the bank’s customer service, as the attacker has a precise understanding of the account’s status. The combination of data – including account status, potential closures, and SSN fragments – significantly increases the credibility of a pretext, such as a request for account regularization or a recovery process.
Crucially, the report stresses that there’s currently no evidence confirming a breach by B9, whether an interface was systematically enumerated, or whether the 36,000 profiles are authentic. However, the method of automated data collection – scraping – is strongly suspected and warrants careful consideration. The data’s longevity is also a concern, as information like passwords and SSN fragments remain linked to individuals for extended periods.
