Data breach
PayUp
- Records
- 289,031
- Breach date
- 19 August 2026Estimated
- Added
- 10 September 2026
What was exposed
6 types of data · 1 more reported
- Names289,031
- Email addresses278,356
- Phone numbers256,765
- Licence plates59,618
- Street addresses10,339
- Dates of birth4,810
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The ransomware group Direwolf listed PayUp, a Texas-based fintech platform, on its leak site on August 19, 2026, claiming to have stolen customer data from the company. The dataset tied to this incident contains roughly 289,031 rows of personal information, including names, email addresses, phone numbers, home addresses, vehicle license plates, and dates of birth. PayUp has not publicly confirmed the claim. GalaxyWarden and recentbreaches.com both reported that the company had not verified the group's assertions when they reviewed the listing.
Per BreachSense, PayUp is a fintech company based in Texas that specializes in automated vendor payments and early invoice factoring for property management companies.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 19, 2026: The Direwolf group listed PayUp on its leak site, claiming to have stolen internal and customer data. Ransomware.live recorded the listing as discovered at 00:54 UTC that day, with an estimated attack date of August 19.
August 20, 2026: BreachSense logged the incident as discovered and began tracking credential exposure associated with the payup.com domain.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (289,031 records), email addresses (278,356), phone numbers (256,765), vehicle license plates (59,618), street addresses (10,339), and birthdays (4,810).
Separately, GalaxyWarden reported that the Direwolf listing itself claims the stolen files include customer records with at least one password field. The group has not published the full dataset, and the storage scheme for that password field has not been disclosed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the dataset includes names, emails, and phone numbers for most records, the most immediate risk is targeted phishing. Attackers who hold real names and contact details can craft convincing messages that appear to come from PayUp, a bank, or a vendor, and use them to trick recipients into handing over logins or payment details.
The combination of street addresses and license plates, even in smaller volumes, adds risk of more personalized scams or harassment, since those details are hard for victims to change.
If the group's claim about a password field is accurate, any affected account could be at risk of takeover, and reused passwords could expose other services. Because PayUp handles payments and invoice factoring, attackers with account access could potentially view or alter payment-related information. No financial account numbers or government identifiers appear in the indexed data, which limits the risk of new account fraud, but the exposure of a birthday for roughly 4,800 individuals adds a piece that scammers often use to sound legitimate.
What Should You Do If You Were Affected?
If you have a PayUp account, change your password now. Use a unique, randomly generated password that you have not used anywhere else, and turn on two-factor authentication if the service offers it.
If you reused that password on other accounts, change those too. Start with your email, banking, and any service tied to money.
Expect phishing. If a message references PayUp, an invoice, or a payment, do not click links in it. Go to the company's website directly by typing the address yourself. Be skeptical of calls or texts that already know your name, phone number, or vehicle details.
Check your financial statements for charges you do not recognize, and consider a credit freeze or fraud alert through the major credit bureaus if you want to reduce the chance of someone opening accounts in your name. The birthday exposure, though limited to a small share of records, makes that step reasonable for cautious readers.
In the news
- Ransomware.live victim listing for PayUpransomware.live (opens in a new tab)
- GalaxyWarden: PayUp Listed by Direwolf Ransomware Groupgalaxywarden.com (opens in a new tab)
- BreachSense: PayUp Data Breach in 2026breachsense.com (opens in a new tab)
- RecentBreach: PayUp Ransomware Claim (2026)recentbreaches.com (opens in a new tab)
