7.5M Banking Customers Affected in Dave Security Breach7.5M Banking Customers Affected in Dave Security Breach
The financial services app confirms user data was compromised in a data breach at its former third-party provider, WayDev.
July 29, 2020
Financial services app Dave has confirmed a security incident after 7.5 million users' data was released on a hacker forum late last week. The company disclosed an incident on Saturday and said it was the result of a cyberattack against its former third-party service provider, WayDev.
Dave is a financial technology company that aims to help customers avoid overdraft fees with cash advances, as well as with automated budgeting, finding side jobs, and building better credit.
In a blog post, Dave says an attacker gained access to user data, including names, emails and physical addresses, birthdates, and phone numbers. The attacker was also able to access user passwords stored in hashed form using bcrypt. Bank account numbers, credit card numbers, financial transaction records, and unencrypted Social Security numbers were not affected.
There is no evidence the attacker took unauthorized actions with any of the accounts or that a Dave user has experienced financial loss following the incident.
When it learned of the breach, Dave says it initiated an ongoing investigation and coordinated with law enforcement, including the FBI. Its team secured its systems and is notifying customers. The company is also enforcing a mandatory reset of all customer passwords.
Register now for this year's fully virtual Black Hat USA, scheduled to take place August 1–6, and get more information about the event on the Black Hat website. Click for details on conference information and to register.
About the Author(s)
Tricks to Boost Your Threat Hunting GameNov 06, 2023
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
The Evolving Ransomware Threat: What Business Leaders Should Know About Data Leakage
2021 Gartner Market Guide for Managed Detection and Response Report
Managed Security and the 3rd Party Cyber Risk Opportunity Whitepaper