FairMoney Database Leak Claim Allegedly Exposes 335,000 User Accounts

A threat actor claims to have leaked approximately 335,505 FairMoney accounts containing contact, banking, device and transaction-related information.
Cybercrime forum post claiming a FairMoney.io breach involving approximately 335,505 user accounts, with more than 330,000 phone numbers and 143,000 email addresses allegedly exposed.
A threat actor claims to have leaked a FairMoney database containing approximately 335,505 user accounts, including phone numbers, email addresses, banking-related fields and transaction data.

A threat actor claims to have breached FairMoney and released a database containing approximately 335,505 user accounts, including more than 330,000 phone numbers and 143,000 email addresses.

The alleged dataset was published for free on September 10, 2026. The threat actor claims the original source contained approximately 7 million users, but says the released archive was filtered to accounts containing phone numbers or email addresses.

The same threat actor previously claimed responsibility for a B-Stock database leak reported by BreachNews, in which approximately 42,000 user accounts were allegedly exposed.

Financial and transaction data appears in sample

The FairMoney archive is described as a 242 MB JSON Lines dataset compressed into a roughly 37 MB download. The actor claims the data was obtained on the morning of September 10 and says no ransom demand was made before publication.

According to the field structure disclosed alongside the leak, the dataset allegedly contains a mixture of identity, contact, banking, device and transaction information. BreachNews is not reproducing the individual records or personal information included in the sample.

  • Names and customer names
  • Phone numbers and email addresses
  • Gender and geographic information
  • Customer and internal user identifiers
  • Bank names and account classifications
  • Device identifiers
  • Agent and recruiter information
  • Transaction references and amounts
  • Transaction status and payment information

The sample provided with the claim appears to contain transaction-related records, including amounts, transaction references, bank names, transaction modes and status information. It also contains fields associated with FairMoney agents and aggregators.

The actor did not claim that passwords, payment card numbers, PINs or Bank Verification Numbers were included in the released dataset.

FairMoney operates a CBN-licensed digital bank

FairMoney provides digital banking, personal loans, savings and other financial services in Nigeria. The company’s website identifies FairMoney Microfinance Bank Limited as a microfinance bank licensed by the Central Bank of Nigeria.

FairMoney also operates business banking services covering accounts, loans, savings and point-of-sale services. Its published merchant terms describe electronic payment services involving transfers, bill payments, cash deposits and withdrawals.

The financial context makes the alleged exposure potentially more significant than a conventional account database. Phone numbers, email addresses and transaction-related information could provide useful context for targeted phishing, impersonation or other social engineering attempts against customers if the dataset proves authentic.

Actor claims original dataset contained 7 million users

The approximately 335,505 accounts being distributed should not be confused with the actor’s much larger claim regarding the source database. The threat actor alleges having access to records associated with approximately 7 million users before creating a smaller dataset focused primarily on records containing contact information.

BreachNews has not independently verified the claimed 7 million-user figure or established how the data was allegedly obtained. The actor’s previous B-Stock claim also involved publication of a downloadable database rather than an extortion demand, although that does not independently establish the authenticity of the FairMoney material.

FairMoney had not issued any public statement addressing the alleged breach at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site