Utah Parent Center Logo Brining Hope, Opening Doors, Elevating Inclusion
HEROIC Mega Menu
Breach Intelligence Report 21 Feb 2024

Money Bookers Hack: 3.6 Million User Records Leaked

HEROIC
HEROIC Threat Intelligence Team
Email Address Ip Phone Number First Name Last Birthday
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 3,667,762
Source Type Database
Origin Darkweb
Password Type No Passwords

HEROIC's DarkHive intelligence system discovered the Money Bookers data breach, exposing 3,667,762 records. The breach occured in January 2009 when this e-wallet and payment platform, now known as Skrill, had its database compromised. The breach leaked email addresses, IP addresses, phone numbers, first names, last names, and birthdates, and went undetected for over six years until October 2015.


Why This Is Dangerous

Financial platform breaches that expose personal identity data create layered risks that go far beyond the original platform. With email addresses, phone numbers, full names, and birthdates all exposed together, attackers can build comprehensive identity profiles for each of the 3.6 million affected users. These profiles enable SIM swapping attacks using the victim's phone number, social engineering of financial institutions using thier personal details, and highly targeted phishing emails that reference the victim's real name and birthday. Since Money Bookers processed financial transactions, many affected users also have payment account histories that attackers can reference when impersonating them.


What Was Exposed

  • Email Address
  • IP Address
  • Phone Number
  • First Name
  • Last Name
  • Birthday

Why This Matters

A breach of nearly 3.7 million financial service users is among the most consequential types of data exposures. The combination of birthdates, full names, and phone numbers gives attackers the three key data points most commonly required to verify identity with banks, mobile carriers, and government agencies. SIM swapping attacks enabled by phone number data can bypass SMS-based two-factor authentication on banking and cryptocurrency accounts. Identity theft using full name and birthdate combinations allows criminals to open fraudulent credit accounts, file false tax returns, and impersonate victims in government systems. The six-year detection gap meant this data circulated freely for years before users were even aware of thier exposure.


How Database Breaches Work

Financial platform database breaches occur when attackers gain unauthorized access to production databases through SQL injection, insider threats, or exploitation of unpatched application vulnerabilities. Payment and e-wallet services store rich user profile data because identity verification is required for financial compliance purposes. Once attackers export this data, it becomes a permanent fixture in the dark web ecosystem, being sold and resold across criminal markets for years. The six-year gap between the Money Bookers breach in 2009 and its discovery in 2015 is a stark illustration of how inadequate breach detection capabilities were at the time, allowing attackers to exploit the data for years without affected users taking protective action.


Check If You Are Affected

HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like Money Bookers. Visit heroic.com to scan your email address and find out if your information was exposed. If you had a Money Bookers or Skrill account before 2015, your name, email, phone number, and birthdate may be circulating in criminal databases. Consider placing a fraud alert with credit bureaus and contact your mobile carrier about additional account security measures to protect against SIM swapping attacks.

Breach Breakdown

Domain N/A
Leaked Data Email Address, IP Address, Phone Number, First Name, Last Name, Birthday
Password Types No Passwords
Date Leaked 21 Feb 2024
Check in 5 seconds

3,667,762 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,777 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $26.5M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance