Skip to content

B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted

Breach Report United States flagUnited States Fintech / Neobank Point-Gated Download

B9 Neobank Data Allegedly Scraped, 36,000 Records With Partial SSNs and Dates of Birth Posted

A forum user posting as riche has published what they describe as a database from Bnine.com, the platform operated by B9, a US neobank offering checking accounts, debit cards, and early direct deposit. The poster states the dataset holds roughly 36,000 users and describes it as scraped rather than dumped, noting that collection excluded accounts requiring selfie verification and that the remainder could not be reached under current limitations. The advertised sample carries full names, dates of birth, partial SSN values, home addresses, phone numbers, and email addresses alongside account status, KYC state, and cash advance limits. The claim is unverified.

Records~36,000
MethodClaimed scraping
CountryUnited States flagUnited States
Actorriche

Post details

TargetBnine.com / B9
CountryUnited States flagUnited States
SectorFintech / Digital banking
ListingDownload + mirror, points to unlock
Records~36,000 obtained
DataIdentity, KYC, advance limits
Observed
Actorriche

!Allegedly included

  • Full names
  • Dates of birth
  • Partial SSN values
  • Home addresses & unit numbers
  • Phone numbers
  • Email addresses
  • Account status & closure state
  • Blocking reasons
  • KYC verification status
  • Cash advance limits
  • Premium tier limits
  • Payroll & ACH transfer fields

Screenshot

Potential impact

The field combination here is the concern rather than the volume. Full name, date of birth, home address, and a partial SSN is close to the standard input set for US identity verification, and the same four values are what a fraudster needs to open credit in someone else's name or to pass knowledge-based authentication with a bank or carrier. Unlike a password, none of these can be rotated. The financial context sharpens it further: records carry account status, KYC verification state, and cash advance limits, which identify not merely who someone banks with but how much credit they can draw and whether their account is already blocked or closing. That is precise targeting material for advance-fee and account-recovery scams aimed at people who may already be under financial pressure. The claimed collection method is worth attention in its own right. If 36,000 records were assembled by scraping rather than by extracting a database, that would point to an enumerable interface returning full customer records, which is a condition that persists until it is fixed and would leave the remainder of the user base reachable by the same route. The poster's reference to a much larger total user base describes the platform's estimated size, not what was obtained. The claim is unverified.

iStatus

Unverified

The post offers a download and mirror behind a forum points paywall and includes a record sample. The poster describes the dataset as partial and explicitly attributes the shortfall to scraping limits and verification requirements rather than to a database compromise, a distinction that materially changes what would have gone wrong and has not been corroborated either way. The account has a moderate posting history on the forum. Neither the record count nor the collection method has been independently verified. The claim is unverified and B9 has not publicly addressed it. Customers may wish to consider a credit freeze and to treat unsolicited contact referencing their account status or advance limit as suspect.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest