The Mykukun Breach Means Your USBANK Data Could Be for Sale
HEROIC analysts identified a large-scale database breach affecting Mykukun, a US-based firm that partners with major financial institutions including USBANK, SOFI, and NYK, on August 9, 2024. The breach exposed 2,702,972 records from the mykukun.com platform. The compromised data included email addresses, first names, last names, usernames, and phone numbers. The connection to USBANK customers makes this incident particularly consequential for financial account security.
Imagine receiving a call from someone who already knows your name, your email address, the phone number linked to your bank account, and the username you registered with a service your bank uses. That is exactly the position this breach puts affected USBANK customers in. A criminal armed with this data can impersonate bank representatives convincingly enough to bypass verbal security checks, intercept account recovery codes sent by SMS, or redirect a victim into fraudulent wire transfers. The sheer volume of 2.7 million records means this dataset has significant value on dark web markets, increasing the likelihood it reaches many different threat actors.
What Was Exposed
- Email addresses
- First names
- Last names
- Usernames
- Phone numbers
Why This Matters
When contact data from a financial services partner is exposed at this scale, it directly enables account takeover fraud, social engineering of bank support staff, and targeted phishing campaigns. Phone numbers tied to banking relationships are especially dangerous because they can be used to intercept SMS-based two-factor authentication codes. Criminals can also use the data to file fraudulent loan applications, open new lines of credit, or sell the verified contact profiles to other criminal groups specializing in financial fraud.
How a Database Breach Works
A database breach happens when an unauthorized party gains access to a company's backend database — often through SQL injection, stolen credentials, or misconfigured cloud storage. Once inside, an attacker can export millions of rows of structured user data in a single operation. The exported data is then packaged and sold or traded on dark web forums. Third-party vendors that process data on behalf of large financial institutions are a frequent target because they may have access to vast customer records while maintaining less rigorous security controls than the primary institution.
Check If You Are Affected
HEROIC's free scanner searches more than 400 billion exposed records, including the Mykukun breach. If you have a USBANK account or used Mykukun's services, enter your email at heroic.com to check your exposure right now.
Breach Breakdown
2,702,972 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds