[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2uyhd1klgconx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488251cf","finsure","Finsure Data Breach","finsure.com.au","2024-10-15T00:00:00.000Z","2024-11-19T04:25:18.000Z","2026-07-18T23:50:37.834Z","Third party breach","",[],296124,"known",null,"unknown","High",[22,23,24,25],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>Finsure is an Australia-based mortgage broking group. In October 2024, approximately 300 thousand unique email addresses appeared with name, phone, and physical address in the marketing data obtained through the real estate marketing platform called ActivePipe.\u003C\u002Fp>\u003Cp>It has been stated that this incident did not directly affect Finsure systems and did not disclose passwords or financial data. Nevertheless, in the context of mortgages and real estate, combined with addresses and phone numbers, it provides valuable context for targeted fraud messages.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data categories tracked in the Finsure record should be considered as email addresses, full name information, phone numbers, and physical addresses. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Full name information makes fake support, fake donation, fake delivery, or customer service messages more convincing. Phone numbers allow personalized fraud scenarios to be set up via SMS, calls, and messaging applications. Physical addresses can be used in delivery, donation, official correspondence, or local service-themed social engineering messages.\u003C\u002Fp>\u003Cp>Messages about mortgage, broker, and real estate are associated with high-value financial decisions. A combination of name, address, phone, and email can make fake credit offer, refinancing, document update, or consulting messages more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is related to the domain finsure.com.au and a third-party marketing data incident in October 2024. The scope is limited to email addresses, full names, phone numbers, and physical addresses. Passwords, credit application details, bank data, or payment cards are not verified for this record.\u003C\u002Fp>\u003Cp>Fields not present in this record should not be described as if they were leaked. Full payment card, bank information, official ID, private message, health data, student file, password, or financial data should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Individuals who have communicated with Finsure customers or the broker network, users open to mortgage or real estate offers, and individuals whose address and phone information are included in marketing systems are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, share their phone and address information on many platforms, or clearly use their real identity on community\u002Fevent accounts are at higher risk. The privacy impact in records with political, student, or official identity context can be heavier than in normal commercial records.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should verify documents, credit, payment, refinancing, or advisory messages received on behalf of Finsure or a broker through the official channel. Additional verification should be carried out for requests asking for financial documents, bank information, or identification information.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Records that do not contain passwords but include contact, donation, address, event, or student data should be monitored for unexpected calls, offers, support, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Marketing lists in the context of mortgage and finance should be regularly monitored. Users should use separate email and strong authentication for financial transactions, and share documents only through trusted portals.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is found in Finsure's linked marketing data. This result does not mean that financial data has been leaked; however, it indicates a risk of mortgage-themed phishing.\u003C\u002Fp>","Finsure Data Breach (296.1 Thousand Reported Records)","Finsure Data Breach. 296.1 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffinsure_com_au.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Finsure","Mortgage Broking \u002F Financial Services","Australia"]