Data breach
Dave
- Records
- 119,138
- Breach date
- 23 June 2020Estimated
- Added
- 24 March 2025
What was exposed
3 types of data · 5 more reported
- Names96,514
- Email addresses75,647
- Home addresses43,755
- PasswordsReported, not counted
- Social security numbersReported, not counted
- Phone numbersReported, not counted
- Dates of birthReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Dave, the personal finance and mobile banking app, suffered a data breach in mid 2020 in which customer records were stolen and later leaked on a hacking forum. According to Dave's own breach notice, an unauthorized party accessed company data between June 23 and July 1, 2020 after a security failure at Waydev, a former third-party analytics provider. The incident was first reported publicly by ZDNet in late July 2020, and researchers later attributed the leak to the actor known as ShinyHunters. Our investigation team's index for this listing contains 119,138 records, including 75,647 email addresses, 96,514 names, and 43,755 home addresses. No actor has claimed this listing on our site.
June 23, 2020: Per Dave's breach notification, the unauthorized party began accessing customer data through a compromise at former service provider Waydev.
July 1, 2020: Dave became aware of the incident, secured its systems, and began an investigation with cybersecurity firm CrowdStrike and law enforcement including the FBI.
July 2, 2020: Waydev warned that its service may have been breached after unauthorized use of a GitHub OAuth token; the security firm Cyble also notified Dave about the circulating data.
July 24, 2020: ShinyHunters released the Dave database for free on a hacking forum after an earlier auction attempt, according to Cyble and SecurityAffairs.
July 25, 2020: Dave publicly disclosed the breach and began a mandatory reset of all customer passwords.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, names, and home addresses.
Dave's official notice to customers listed additional fields, including phone numbers, dates of birth, gender, profile images, hashed passwords, encrypted Social Security numbers, and application preferences such as notification settings.
Not every individual is affected by every type of data listed here.
The notice stated that bank account numbers, credit card numbers, and records of financial transactions were not affected. Social Security numbers were encrypted with AES-256, and passwords were stored hashed with bcrypt. Dave also confirmed, however, that at least some of the stolen hashed passwords were likely cracked into plain text.
What Are the Potential Risks for Affected Individuals?
Exposed names, emails, addresses, and phone numbers are useful for phishing, since criminals can tailor messages using real personal details. Cracked passwords are a more direct threat: anyone who reused the same password on other sites faces a risk of account takeovers through credential stuffing. Stolen dates of birth and addresses can also support identity fraud attempts. Dave's notice said it had no evidence of fraudulent account activity or financial loss, but that does not eliminate the longer-term risk once data circulates on criminal forums.
What Is Dave Doing in Response?
Dave publicly disclosed the breach on July 25, 2020, retained CrowdStrike, and notified the FBI. The company forced a reset of all customer login credentials, added technical security measures, and stopped working with the provider whose breach enabled the attack. Its notice directed customers to support@dave.com and 1-888-865-8193 with questions.
What Should You Do If You Were Affected?
Change your Dave password if you have not already, and make it unique.
Change passwords on any other account where you reused the same credentials.
Watch for phishing emails or texts that reference Dave, your finances, or your personal details, and avoid clicking links in unexpected messages.
Review your bank and credit card statements for unfamiliar activity.
Consider a free credit report from annualcreditreport.com and, if you see signs of identity theft, a fraud alert or security freeze with the major credit bureaus.
In the news
- Dave notice of data breach (California Attorney General archive)oag.ca.gov (opens in a new tab)
- Banking Dive, July 28, 2020bankingdive.com (opens in a new tab)
- SecurityAffairs, records for 7.5 million Dave users leaked onlinesecurityaffairs.com (opens in a new tab)
- BankInfoSecurity, anatomy of a breachbankinfosecurity.com (opens in a new tab)
