AvaTrade
We noticed a significant influx of user data originating from the financial services sector appearing on a well-known cybercrime forum. Specifically, the data dump attributed to AvaTrade, an online financial services platform, was posted on August 16, 2024. What struck us immediately was the relatively high volume of records and the inclusion of personally identifiable information (PII) that could be leveraged for sophisticated phishing or social engineering attacks against their user base. The nature of the data suggests a potential compromise of a customer database, a critical asset for any financial institution.
The breach, discovered on August 16, 2024, involved a database compromise at AvaTrade, impacting approximately 313,000 records in total. Of these, 109,954 unique email addresses were exposed, alongside associated first names, last names, and phone numbers. While physical addresses were also mentioned in the initial reports, the primary focus of the leak appears to be contact and identification details. The threat theme here is clearly credential harvesting and identity theft, with the exposed data providing a rich foundation for targeted attacks. The source structure points to a direct database exfiltration, rather than a web application vulnerability, suggesting a potential internal or infrastructure-level compromise.
This incident has garnered some attention within cybersecurity circles, though widespread public news coverage is still developing. Open-source intelligence (OSINT) indicates that the data was posted on a prominent cybercrime forum, a common tactic for threat actors to monetize stolen information or to signal their capabilities. While no specific research papers or technical analyses have been published yet directly on the AvaTrade breach, the methodology of database compromise and subsequent data dumping is a well-documented threat vector in financial sector attacks. The implications for AvaTrade's customers are significant, potentially leading to an increase in targeted phishing campaigns and account takeover attempts.
Breach Breakdown
109,954 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds