Cashea suffers data breach after security incident

Foto del autor

By Berto R

  • External reports mention up to 46.5 GB of leaked data.

  • The data would include transactions and records linked to allied businesses.

The Venezuelan platform Cashea detected and publicly confirmed a data leak on February 21, 2026. External cybersecurity monitoring sources indicate a possible leak of user transactions with businesses associated with the company’s credit system.

According to the statement released by the company, the incident was detected and attended to by its technical and security teams. Cashea assured that there was no breach of user accounts or passwords.

Besidesstated that the application remains operational and that protocols were activated to reinforce security after the event. The company promised to continue informing its users of any news regarding the incident.

Official statement from Cashea in response to the leak. White background, black letters. Company logo.
Official statement from Cashea in response to the leak. Source: X

In parallel, reports circulating on social networks claim that an identified actor had published a database of approximately 46.5 GBcomposed of more than 79 million records linked to transactional activity within the Cashea ecosystem.

Publication by @VECERTRadar that exposes the alleged amount of data that was leaked. Publication by @VECERTRadar that exposes the alleged amount of data that was leaked.
Publication by @VECERTRadar that exposes the alleged amount of data that was leaked. Source: X

In incidents of this type, potentially compromised data They usually include basic personal information (name, email, ID number), transaction histories, internal user identifiers, addresses associated with billing or shipping and technical metadata linked to activity within the system.

In some cases, when it comes to e-commerce or digital credit platforms, records related to affiliated businesses, transaction amounts, purchase dates, and financing statuses may also be exposed. However, these categories respond only to patterns observed in similar incidents and not to facts confirmed by official sources. To date, the company has not publicly confirmed the scope or specific content from the leaked database.

The leak of this data has important implications for Cashea users, including if your email or password does not give hackers access to your user accounts. From the incident onwards, such users could experience phishing attacks.

These attacks are intended to trick users into providing, without their consent, confidential data (passwords, cards) or the installation of malware on their computers. The way used to execute these attacks is usually the impersonation of legitimate entities (such as Cashea technical support) via email, SMS or calls.

It is worth noting that Cashea is one of the most used digital commerce and credit platforms in Venezuela, with transactions equivalent to 3.5% of the Venezuelan GDP, as reported by NoticiasVE.

Deja un comentario