[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1dquilnzmc5h1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"68e3266eda11adda4882517a","dave","Dave Data Breach","dave.com","2020-06-28T00:00:00.000Z","2020-07-27T02:38:41.000Z","2026-07-09T20:40:58.580Z","2026-07-18T23:49:15.798Z","Third party breach","https:\u002F\u002Fwww.bankingdive.com\u002Fnews\u002Fdave-security-breach\u002F582426\u002F",[15,17,18,19,20],"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002F7-5m-banking-customers-affected-in-dave-security-breach","https:\u002F\u002Fwww.securityweek.com\u002Fdigital-banking-service-dave-says-data-stolen-third-party-breach\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fdave-2020","https:\u002F\u002Fsiliconangle.com\u002F2020\u002F07\u002F27\u002F7-5m-customer-records-stolen-dave-found-dark-web\u002F",2964182,"known",null,"unknown","Critical",[27,28,29,30,31,32,33],"Dates of birth","Email addresses","Names","Passwords","Phone numbers","Physical addresses","Social security numbers","\u003Cp>The Dave data breach is related to the unauthorized acquisition of user data from Dave, a United States-based digital banking and cash advance app, during the period of June 2020. The incident is associated with a security breach that occurred through Dave’s former third-party service provider. The verified scope is 2,964,182 unique email addresses; the raw data related to the incident was reported to be approximately 7.5 million rows. The number of rows does not correspond to individual persons; there may be multiple rows or different record fragments belonging to the same user. The records include date of birth, email addresses, names, bcrypt-protected password hashes, phone numbers, physical addresses, and an encrypted Social Security number field.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data listed in Dave’s record are high-risk due to the context of the financial application. Name, email address, phone number, and physical address together indicate the user's identity and direct reachability. Date of birth can be used for account recovery or customer support verification in some services. The social security number field is specified as encrypted; this does not mean that a readable number has leaked, but the mere presence of the field in the record increases the sensitivity of the incident. The password field should also be considered as a bcrypt hash value, not as plaintext.\u003C\u002Fp>\n\u003Cp>Although Bcrypt is a strong password storage method, the risk of a password does not completely disappear. Weak or previously used passwords may be more vulnerable. If a user has repeated the same password on email, financial, shopping, social media, or work accounts, attackers may try the cracked or guessed password on different platforms. A physical address and phone number can make social engineering attempts, such as fake calls from financial representatives, account verification messages, cash advance notifications, credit offers, or identity verification pretenses, more convincing.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number 2,964,182 shown in this record represents the scope of verified unique email addresses. The raw data associated with the incident has been reported as approximately 7.5 million rows; however, these rows do not equate to the number of unique users. This distinction is important both to avoid unnecessary panic for users and to accurately reflect the actual scope of the breach. The incident date is recorded as June 2020, and the subsequent appearance of the data on different forums or data indexes does not change the actual period of the breach. The record is dedicated to Dave's user data and should not be confused with the other customers of the third-party provider.\u003C\u002Fp>\n\u003Cp>Care should also be taken at the boundary of the data field. In this record, birth dates, email addresses, names, bcrypt password hashes, phone numbers, physical addresses, and the encrypted social security number field have been verified. The encrypted field does not mean that the number can be read in plain text. Similarly, the fact that the incident is related to a financial application does not mean that transaction movements or direct account access information are contained in this record. The correct message to the user is that personal identity and contact fields carry high risk, password reuse should be checked, and caution should be exercised against finance-themed fraud attempts.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for people who have used the Dave app and have used the same email or password on other financial or personal accounts. Finance app users can be targeted with scenarios such as fake account verification, payment issues, cash advance updates, credit score, identity checks, or customer support calls. An attacker knowing the person's name, phone number, address, and date of birth makes these contacts more convincing. Therefore, users should be suspicious not only of incoming emails but also of phone calls and text messages.\u003C\u002Fp>\n\u003Cp>The risk may be broader for individuals who have opened a Dave account with a corporate email address. The exposure of an employee's data in a personal finance application does not mean that the organization's systems have been compromised; however, if the same password is used for work accounts or if an attacker targets the corporate address for a message, there could be a risk for the organization. In cases such as a shared address, shared phone, or family account, the risk may also affect other people. Physical address information can also be used in fraud attempts carried out through fake mail, fake deliveries, or pretexts for identity verification.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step for users matching the Dave record is to change the password used on the Dave account and all accounts where the same or similar password is used. Email accounts, financial applications, banking services, payment platforms, shopping sites, and social media accounts should be checked first. New passwords should be unique and strong, generated with a password manager if possible. Multi-factor authentication should be enabled on important accounts, unknown sessions should be closed, and recovery options should be updated.\u003C\u002Fp>\n\u003Cp>The second step is to take precautions against finance-themed social engineering attempts. The user should not share a verification code, password, account access, or additional personal information even if the caller or message sender claims to be Dave, a financial institution, a support team, or an authentication unit. If account status needs to be checked, a known app or official login channel should be used. In the email account, forwarding rules, recovery addresses, and recent login activity should be checked. If there is suspicion of a fraudulent financial transaction or identity use, direct contact should be made with the relevant service providers.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Dave incident shows that personal data stored in financial applications is not limited to password security alone. Users should use unique passwords and multi-factor protection on all accounts used for finance, email, and authentication processes. It should not be forgotten that phone numbers and physical addresses can be used in fraud scenarios. Credit and identity monitoring habits can be useful in terms of unexpected account openings, fake applications, or suspicious financial notifications. If old financial application accounts are not being used, they should be closed or data retention settings should be reviewed.\u003C\u002Fp>\n\u003Cp>The lesson to be learned for financial technology companies is that third-party service provider risk can directly translate into customer security. It should be clearly limited which customer areas suppliers used for analytics, development, or support purposes can access. Passwords should be stored using strong methods, sensitive identity fields should be kept encrypted, unnecessary data sharing should be minimized, and third-party access should be regularly audited. After a breach, it should be clearly explained to the user which areas were affected and which areas were explicitly not affected.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the verification result on this page matches the Dave record, the user should consider the result sensitive. First, password repeats should be cleared, and then additional verification should be enabled on email and financial accounts. The user should be cautious of unexpected links, verification code requests, account lock messages, and identity update forms coming on behalf of Dave or any other financial service. Since physical address and phone information are also considered within the risk scope, not only email but also call and message channels should be monitored.\u003C\u002Fp>\n\u003Cp>Although the Dave breach is dated, personal identity and communication data retain their value for a long time. Bcrypt password hashes do not directly mean readable passwords; however, the risk persists with weak or reused passwords. The encrypted social security number field also does not directly mean an open number, but it makes the record sensitive. The user should treat this record as a concrete warning to update password patterns, protect financial accounts, monitor signs of identity misuse, and apply stricter verification in unexpected finance-related contacts.\u003C\u002Fp>","","Dave Data Breach (3 Million Reported Records)","Dave Data Breach. 3 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fdave_com.webp",false,{"name":41,"sector":42,"country":43,"website":9,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":23},"Dave","Digital banking and cash advance app","United States"]