Skip to content

Belgian Consumer Database Allegedly Exposed, 148,251 Citizens With Bank Account Numbers and Birth Dates

Breach Report Belgium flagBelgium Data Broker / Marketing Free Download

Belgian Consumer Database Allegedly Exposed, 148,251 Citizens With Bank Account Numbers and Birth Dates

An actor posting as exfilar claims to have found an unsecured marketing database holding 148,251 Belgian consumer records, described as left accessible with no authentication and no encryption. The 81MB export is said to contain 40,455 bank account numbers, 52,688 email addresses, 43,234 phone numbers, and full names, postal addresses, genders, dates of birth, and subscription details, covering every province in Belgium. The operator is not identified: the actor describes it only as a data broker or loyalty programme aggregator and states the host is unknown, meaning affected citizens have no named party to approach. The claim is unverified.

Citizens148,251
Bank accounts40,455
OperatorUnidentified
Actorexfilar

Post details

TargetUnidentified data broker
CountryBelgium flagBelgium
SectorMarketing / Data aggregation
ListingFree, reply to unlock
Records148,251 across 5 files
CauseClaimed open server
Observed
Actorexfilar

!Allegedly included

  • IBAN bank account numbers
  • BIC bank codes
  • Legacy account numbers
  • Full names and titles
  • Dates of birth
  • Gender
  • Street and house numbers
  • Apartment or box numbers
  • Postal codes and cities
  • Primary phone numbers
  • Secondary phone numbers
  • Email addresses
  • Subscription types
  • Order identifiers

Screenshots

Potential impact

An IBAN paired with a verified name, home address, and date of birth is the strongest combination in this dataset. It supports direct debit fraud, and it makes a caller reciting a person's own account details and birth date extremely difficult to doubt. Because the records also carry subscription type and order identifiers, a fraudulent message can reference a service the recipient actually holds. The exposure is aggravated by the operator being unknown: nobody can be notified, no controller can be held to account, and affected citizens cannot check whether they are included. Under GDPR this would be a reportable breach, but only once a controller is identified.

iStatus

Unverified

The actor publishes record samples but names no company and states the host is unknown, so the claim cannot be checked against any operator and the origin of the aggregation is unestablished. Dark Web Informer is not reproducing the sample records, which contain living individuals' bank details. The post credits a scanning tool the actor is separately selling for $50,000, and advertises paid penetration testing. This is the seventh listing from this actor in eight days. The claim is unverified.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest