Skip to content

Bebunk Database Allegedly Leaked, 12,324 Banking Customers With IBANs and KYC Records Exposed

Breach Report France flagFrance Fintech / Banking Free Download

Bebunk Database Allegedly Leaked, 12,324 Banking Customers With IBANs and KYC Records Exposed

A forum user posting as kitta has published what they describe as the database of Bebunk.com, a digital financial service offering current accounts and payment cards. The post claims 12,324 unique customers were exposed. The advertised field list is materially more sensitive than a typical consumer leak, combining identity and contact details with IBANs, account balances, withdrawal limits, KYC status, and authentication tokens. Records in the posted sample carry French IBANs, XPF currency values, and New Caledonia locality codes, alongside references to a third-party banking-as-a-service platform. The data is offered as a free download behind a reply-to-unlock gate. The claim is unverified.

Records12,324
PriceFree
CountryFrance flagFrance
Actorkitta

Post details

TargetBebunk.com
CountryFrance flagFrance / New Caledonia
SectorFintech / Digital banking
ListingFree — reply to unlock
Records12,324 unique customers
DataBanking identifiers, KYC, tokens
Observed
Actorkitta

!Allegedly included

  • Full names
  • Email addresses & logins
  • Phone numbers
  • IBANs
  • Account balances
  • Withdrawal limits
  • Fee & insufficient balances
  • KYC status & workflow
  • KYC tokens
  • PEP screening status
  • FATCA reporting status
  • Account & card status flags
  • Notification tokens
  • Platform user identifiers

Screenshots

Potential impact

Twelve thousand records is small by leak standards, but the per-record value here is unusually high. An IBAN paired with a verified full name, phone number, and current balance is close to an ideal input for SEPA direct debit fraud and for social engineering that opens by reciting a customer's own account details back to them. The KYC and compliance fields compound this: verification status, workflow state, PEP screening outcomes, and FATCA flags are regulatory data that customers never consented to see published, and PEP status in particular identifies individuals who may already be at elevated risk. The presence of notification, activation, and KYC tokens raises a separate question about whether any of those values remain valid, since tokens that have not been rotated since the extraction date could support account access rather than merely describing it. The apparent New Caledonian concentration narrows the exposure to a population of roughly a quarter of a million, meaning a meaningful share of the territory's users of this service may be affected. Signals in the sample also point to a third-party banking-as-a-service provider sitting behind the product, which leaves open where in that chain the data originated. The claim is unverified.

iStatus

Unverified

This is the second database posted by the same account today, following a listing against a US e-commerce platform earlier in the day. The account is recently registered with minimal posting history despite an elevated forum rank. Record timestamps in the sample run into 2026, which would place the extraction recently rather than in an aged dataset, though timestamps are trivially editable and prove nothing on their own. Neither the record count nor the field structure has been independently corroborated. The claim is unverified and Bebunk has not publicly addressed it. Customers of the service may wish to watch for unrecognised direct debits and treat unsolicited contact citing their account details with suspicion.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest