malconguerra2 calls for an attack on Cashea
On February 21, 2026, the actor malconguerra2 claimed on DarkForums to have published 46.5 GB of confidential Cashea data, including 79,006,942 transaction records, store records, and data from partner merchants. Cashea officially confirmed a data exfiltration involving users and merchant partners from the Merchant Web environment, which occurred between January 30 and February 21, 2026, attributed to the use of valid credentials from a partner merchant’s employee account that had been compromised outside the platform, as well as insufficient controls on APIs. The company stated that the information involved consists of operational and transactional data, such as names, ID numbers, phone numbers, orders, and merchant information; it also indicated that it did not identify any compromise of user passwords, internal administrative credentials, cloud infrastructure, private keys, system secrets, or financial payment processing components. The DarkForums.ru link added on July 4, 2026, corresponds to a repost or update of the same dataset from February, not a separate incident.
Overview
Missing evidence
Impact details
Cashea officially confirmed the leak of Merchant Web’s operational and transactional data affecting users and business partners. It has not confirmed the figure cited by the attacker—46.5 GB and 79,006,942 records— and has stated that user passwords, infrastructure credentials, confidential data, cloud infrastructure, financial systems, and payment processing components have not been compromised.
Classification & severity
- Category
- Information content security
- Subtype
- Leak of confidential information
- Confidence
- High
Severity assessment
High- Functional impact
- None
- Information impact
- Sensitive personal data
- Affected scope
- National
- Critical service
- None
- Public confidence
- Moderate
- Recoverability
- Regular
Cashea officially confirmed the data breach and explained the chain of failures in credential and API controls, while limiting the confirmed scope and denying that payments, passwords, secrets, infrastructure, the cloud, or the financial system had been compromised.
Timeline
Cashea reported in its technical report that between December 25 and 31, 2025, there was a silent reconnaissance phase targeting Merchant Web.
According to the official technical report, the anomalous activity began with a compromised account at a partner merchant, and the active exfiltration phase began on Merchant Web.
Cashea recorded an external post reporting the data breach on February 21, 2026, at 4:50 p.m. Venezuela time.
malconguerra2 posted the full dump (~46.5 GB; 79,006,942 transaction records claimed) on DarkForums.
Cashea activated containment, identified and deactivated the compromised account, and began response measures on February 21, 2026.
Cashea publicly confirmed the data breach and stated that user and partner passwords and access credentials were not compromised.
Cashea announced the start of an independent forensic investigation with Mandiant and the filing of a complaint with the CICPC.
Monitoring entry attributed to dev0x7C00 regarding a repost by Cashea (+600GB/79M), pending direct access to a public source; it is being treated as an unconfirmed report rather than a separate incident.
malconguerra2 posted a RE-POST UPDATE of the Cashea dataset on DarkForums.ru dated February 21, 2026, with the same claimed size of 46.5 GB and 79,006,942 transaction records.