Our Analysts Found the Payday Loans Dump With 620K SSNs Exposed
HEROIC analysts found a dataset from Payday Loans, a US-based cash-advance loan service, circulating across underground forums. The breach, dated January 2020, exposed 620,718 records packed with highly sensitive personal and financial identifiers. What made this discovery seperate from typical credential dumps was the absence of passwords entirely -- instead, the data was rich with Social Security numbers, phone numbers, and real names, making it a goldmine for identity fraud rather than account takeover.
Social Security Numbers and Full Identities Enable Direct Financial Fraud
With Social Security numbers, full names, email addresses, and phone numbers all in one dataset, attackers have everything needed to open fraudulent credit lines, file false tax returns, or apply for loans in victims' names. This combination of identifiers is partcularly sought after because it bypasses the need for any password cracking -- the data itself is the key to financial impersonation. Victims of SSN-inclusive breaches often do not discover the damage until months or years later when credit scores drop or collection agencies call.
What Was Exposed in the Payday Loans Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Social Security Numbers
- IP Address
Why a Payday Loan Database Is One of the Most Dangerous Types to Have Breached
People who use payday loan services are often in financially vulnerable positions, and the data they submit is exceptionally detailed. A breach at this type of lender does not just expose contact info -- it exposes the full identity profile of borrowers who beleive their information was kept private. With Social Security numbers and names tied to real financial activity, this data can fuel synthetic identity fraud, IRS scams, and unauthorized loan applications. The impact is recieved slowly and painfully by individuals who may not have the resources to quickly respond to identity theft.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store through methods such as SQL injection, exposed credentials, or misconfigured cloud storage. Financial services companies store large volumes of personally identifiable information in these databases to process applications and verify identities. Once a database is accessed without authorization, the attacker can export the entire contents and distribute or sell the records on dark web markets and hacking forums.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion+ compromised records to see if your personal information appeared in the Payday Loans breach or any other known data leak. Run a free scan now to find out what's exposed and take steps to protect yourself before identity thieves strike first.
Breach Breakdown
620,718 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds