Data breach
yotepresto.com
- Records
- 1,437,622
- Breach date
- 22 June 2020Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses1,437,396
- IP addresses1,407,530
- Passwords10,045
About this breach
In mid 2020, the Mexican peer-to-peer lending platform yotepresto.com suffered a data breach that exposed records belonging to roughly 1.4 million users. The incident is estimated to have occurred on June 22, 2020, and the indexed dataset contains 1,437,622 rows. The company acknowledged unauthorized access to its systems at the time, while a breach broker later offered the user database for sale on hacker forums. The listing is tied to a single company rather than a compilation of multiple breaches.
Breach Timeline
June 21, 2020: YoTePresto's systems recorded unauthorized accesses that reached 1.4 million records containing email addresses and encrypted passwords, according to statements the company later gave to El Economista.
June 22, 2020: The company said it detected the breach early that morning and that its engineers fixed the flaw immediately, then notified users and the banking authority.
June 29, 2020: BleepingComputer reported that a data breach broker was selling a 1.4 million record Yotepresto database on hacker forums, with a claimed breach date of June 2020. Samples examined by the outlet looked legitimate, but the company had not confirmed the sale at the time.
August 10, 2020: El Economista published details of the incident and the company's response.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (present in 1,437,396 records), IP addresses (present in 1,407,530 records), and passwords (present in 10,045 records).
The company told El Economista that the exposed material consisted of email accounts and encrypted passwords, and that no names, addresses, phone numbers, or other personal documents were involved. Only a small portion of the indexed records includes a password entry, so the exposure of credentials varies from user to user.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
An exposed email address linked to a lending platform is useful to criminals even without a working password. Attackers can use it for phishing messages that impersonate YoTePresto or other financial services, attempting to trick recipients into revealing credentials or payment details.
Where password data is present, the risk is higher. If a user reused the same password on other websites, criminals can attempt credential stuffing, testing those credentials against email, banking, and shopping accounts. Because email addresses are often the recovery key for other services, their exposure also raises the risk of account takeover attempts. IP address data can help attackers link a person to a location or network, though on its own it is less directly exploitable.
What Is yotepresto.com Doing in Response?
The company told El Economista that it corrected the vulnerability immediately after detecting the breach and notified its users and the banking authority. It stated that no client suffered any financial impact because all transactions on the platform require two-factor authentication, and that no one gained access to customer accounts. YoTePresto also said it did not notify Mexico's data protection authority, the INAI, because it was not yet operating as a regulated financial technology company and because it judged that no personal data beyond email addresses and encrypted passwords was exposed.
What Should You Do If You Were Affected?
Change your YoTePresto password to a strong, unique one, if you have not already.
If you reused that password anywhere else, change it at those sites too.
Turn on two-factor authentication wherever it is offered, especially on your email account.
Be cautious with unexpected emails referencing loans, YoTePresto, or your account, and avoid clicking links in them. Go to the site directly instead.
Watch for unusual login alerts on accounts that share the exposed email address.
In the news
- BleepingComputer: Seller floods hacker forum with data stolen from 14 companiesbleepingcomputer.com (opens in a new tab)
- El Economista: YoTePresto expuso correos y contraseñas de todos sus 1.4 millones de clienteseleconomista.com.mx (opens in a new tab)
- Asociación Mexicana de Ciberseguridad: YoTePresto expone correos y contraseñas de sus usuariosameci.org (opens in a new tab)
