Black Friday Sale! 50% Off All Access

An Ex-Employee Is Behind the Cash App Breach Impacting Over 8 Million Users. Here's Everything We Know So Far. According to the company's SEC filing, the former employee downloaded reports containing U.S. customer data on December 10.

By Amanda Breen Edited by Jessica Thomas

Block Inc. confirmed Monday that a security breach initiated by a former employee several months ago has potentially impacted 8.2 million users of Cash App, the mobile-payment service that facilitates the transfer of funds, and, more recently, the purchase of stocks and Bitcoin. According to the company's SEC filing, the ex-employee downloaded reports containing U.S. customer data on December 10.

The filing also reveals that only customers who used the app's stock-related features were affected by the breach. The reports in question included customers' full names and brokerage account numbers, and in some cases, also included brokerage portfolio value, brokerage portfolio holdings and/or stock trading activity. They didn't include usernames or passwords, Social Security numbers, dates of birth, payment-card information, addresses, bank-account information or any other personally identifiable information.

Related: The How-To: Protect Your Business From a Data Breach

At one point, the ex-employee "had regular access to these reports as part of their past job responsibilities," the filing states, but their employment had already come to an end when the download occurred. Block declined to answer TechCrunch's questions as to why a former employee was still able to access the reports, and for what length of time they continued to have access following their employment's end.

"At Cash App we value customer trust and are committed to the security of customers' information," Cash App spokesperson Danika Owsley told TechCrunch in a statement. "Upon discovery, we took steps to remediate this issue and launched an investigation with the help of a leading forensics firm. We know how these reports were accessed, and we have notified law enforcement. In addition, we continue to review and strengthen administrative and technical safeguards to protect information."

Block's investigation of the incident is ongoing.

Related: 8 Ways a Data Breach Could Take Out Your Company Tomorrow

Block, formerly known as Square, is also behind numerous other enterprises, including music-streaming service Tidal and Bitcoin company Spiral.

Block, Inc. was down more than 7% as of 10:12 a.m. ET.

Amanda Breen

Entrepreneur Staff

Senior Features Writer

Amanda Breen is a senior features writer at Entrepreneur.com. She is a graduate of Barnard College and received an MFA in writing at Columbia University, where she was a news fellow for the School of the Arts.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Living

These Are the 'Wealthiest and Safest' Places to Retire in the U.S. None of Them Are in Florida — and 2 States Swept the List.

More than 338,000 U.S. residents retired to a new home in 2023 — a 44% increase year over year.

Business News

These Are the Highest Paying Jobs Available Without a College Degree, According to a New Report

The median salaries for these positions go up to $102,420 per year.

Starting a Business

He Started a Business That Surpassed $100 Million in Under 3 Years: 'Consistent Revenue Right Out of the Gate'

Ryan Close, founder and CEO of Bartesian, had run a few small businesses on the side — but none of them excited him as much as the idea for a home cocktail machine.

Starting a Business

This Sommelier's 'Laughable' Idea Is Disrupting the $385 Billion Wine Industry

Kristin Olszewski, founder of Nomadica, is bringing premium wine to aluminum cans, and major retailers are taking note.

Business News

Is Reddit Down Again? Tens of Thousands of Users Are Reporting Issues With the Platform.

A Reddit outage has been occurring off-and-on for two days.

Business News

DOGE Leaders Elon Musk and Vivek Ramaswamy Say Mandating In-Person Work Would Make 'a Wave' of Federal Employees Quit

The two published an op-ed outlining their goals for their new department, including workforce reductions.