An Australian fintech platform's database was reported as insecure in 2025, and
youX believed it had been fixed. According to the attacker who later claims to have
exploited it, the exposure continued for roughly ten more months β
affecting an estimated 444,000 borrowers.
β οΈ Read this before anything else. The
underlying vulnerability β a misconfigured, publicly reachable database β is corroborated
independently. The exact scale (444,000 borrowers, the full list of stolen data types) and
the 10-month exposure window come primarily from the attacker group's own claims and
security-researcher writeups, not a youX public disclosure with matching figures.
The numbers, and their real status
~10 months
Time the database allegedly remained exposed after a researcher
first flagged it, per the attacker's account.
Security researcher disclosure reports, 2026.
444,000
Borrowers affected, per breach analysis and reporting on the
incident.
Multiple security outlets, 2026.
~800
Broker organisations whose data was also exposed through the same
platform.
Breach analysis, 2026.
8,075
Password hashes claimed stolen β reportedly using MD5, a weak,
crackable algorithm. Not independently re-verified by Egidio.
Attacker's own technical claims, 2026.
Timeline
REPORTED
Around March 2025
A security researcher reportedly identifies and discloses an
insecure, publicly reachable MongoDB Atlas database belonging to youX. youX indicates
the issue has been remediated.
CLAIMED
February 2026
The group FulcrumSec claims to have exfiltrated roughly 300GB
from 22 production databases, following a breakdown in ransom negotiations. Claimed
contents: loan applications, driver's licence numbers, residential addresses,
financial records, and password hashes for broker employees.
2026
The breach becomes public through security-research writeups and
trade press, corroborating the existence of the exposed database and the general
shape of the incident, though not every figure claimed by the attacker.
πThe part that matters most: this was flagged in advance
Most breaches documented on this site involve a company being caught off guard. This
one is different: if the reporting is accurate, the vulnerability was identified and
reported before the exploitation, remediation was believed complete, and
the exposure allegedly continued anyway for months. That gap β between "we fixed it" and
"it was still open" β is the part worth remembering, more than the exact borrower
count.
What was allegedly stolen
Government identification numbers, driver's licence numbers, residential addresses,
and detailed financial records β income, debts, loan applications. This is data that
supports identity theft and fraudulent credit applications, not just a
convincing phone call.
π If you've held a loan or finance application through a broker
in Australia in recent years, the useful precaution goes beyond call screening: watch for
unexpected credit enquiries in your name. For the call-and-message side of what typically
follows a financial data breach, see
From Leak to Scam and
how Medusa links channels together.
Frequently asked questions
Is the youX breach confirmed?
The underlying database misconfiguration is corroborated by multiple sources. The
exact 10-month exposure window and full extraction figures come from the attacker's
account and have not been independently confirmed in full.
What made this breach preventable?
A researcher reportedly flagged the exposed database to youX in March 2025. youX said
it was fixed. The attacker claims it remained accessible for roughly 10 more
months.
What should affected youX borrowers do?
The stolen data includes government IDs and financial records β enough for identity
theft. Watch for unexpected credit applications and consider a credit report
check.
π Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "youX: a flagged database, left open for 10 months," egidio.app/en/laboratoire/youx-australia-fintech-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.