Data breach
Chumz
- Records
- 89,577
- Breach date
- 11 July 2026Estimated
- Added
- 11 July 2026
What was exposed
4 types of data
- Email addresses89,577
- Names14,952
- Phone numbers5,728
- Dates of birth4,382
About this breach
Chumz, a Nairobi-based savings and investment app operated by Moneto Ventures Limited, appears to have lost a database containing tens of thousands of user records to a public leak. The listing was added on July 11, 2026, with an estimated attack date of July 11, 2026, and contains 89,577 rows of personal data. No individual or group has been confirmed as the source of the intrusion. Separately, the leak-tracking service Dark Eye documented an advertised archive file named "chumz.io.rar" attributed to the actor known as Database World ROC, which it indexed on August 28, 2026.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses (89,577 records)
Names (14,952 records)
Phone numbers (5,728 records)
Dates of birth (4,382 records)
Not every individual is affected by every type of data listed here.
The presence of email addresses, phone numbers, and names is consistent with user account or customer data rather than financial account records, though the available indexed fields do not confirm what else may have been exposed.
What Are the Potential Risks for Affected Individuals?
Anyone whose contact details appear in this leak faces a heightened risk of targeted phishing. Because Chumz users link the app to mobile money accounts, scammers can use a person's name and phone number to craft convincing messages about savings balances, deposits, or account problems. Fake M-Pesa or bank alerts are a common tactic in Kenya, and a leaked phone number paired with a real name makes those messages harder to dismiss.
Email addresses can be used for credential phishing aimed at other accounts, especially where passwords are reused. Dates of birth and names support identity-related fraud, including attempts to answer security questions on other services. The overall risk depends on which data types applied to each individual record.
What Should You Do If You Were Affected?
Change your Chumz password and any other account where you used the same password.
Enable two-factor authentication where available, especially on your email and mobile money accounts.
Be skeptical of calls, texts, or emails referencing your savings, Chumz, or M-Pesa transactions. Verify directly with the company using official contact details from its website rather than any link or number in a message.
Watch for unusual activity in your mobile money and bank statements and report anything suspicious to your provider promptly.
If you receive a suspicious message claiming to come from Chumz, you can report it to the company at info@chumz.io.
