PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

The Cash App Breach Involved an Inside Actor

By Tom Nawrocki
August 9, 2024
in Analysts Coverage, Data Breach, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Quantum Isn’t Armageddon; But Your Horse Has Already Left the Barn

Quantum Isn’t Armageddon; But Your Horse Has Already Left the Barn

The recent Cash App class-action lawsuit settlement may seem like an opportunity for users of the payment service, with headlines suggesting that anyone who used Cash App between 2018 and now could be eligible for up to $2,500. However, these claims are somewhat exaggerated. A more pressing concern is understanding how the breaches that led to the suit occurred—and whether similar incidents could happen again.

The lawsuit claims that Cash App and its parent company Block Inc. were negligent in 2022 when an employee accessed account data without authorization, followed by another breach in 2023. 

Block has agreed to a $15 million settlement. But merely having used the app is not enough to receive a share of the settlement. User must provide “third-party documentation showing a “data security incident, unauthorized account event, or deficiency in error resolution” with a Cash App account. That said, providing documented proof of these actions will be tough for many users, especially two or three years after the fact.

These are not the only user issues that Cash App has dealt with. According to a 2022 study from the Bank Policy Institute, six times as many disputed transactions were made using Cash App as with Zelle, underscoring growing concerns about transaction processes.

An Insider with Access

The initial breach was caused by an insider. An employee at Cash App Investing accessed and downloaded consumers’ personal identifiable information. The suit claims that Block and Cash App Investing didn’t implement sufficient controls to prevent unauthorized access and misuse of Cash App and Cash App Investing accounts after the breach was discovered. This failure led to customer complaints about unauthorized or fraudulent transactions.

That led to a second data breach in 2023, where Cash App identified further unauthorized access to customer accounts. It alerted customers that “an unauthorized user logged into your Cash App account using a phone number that was linked to your account and had been recycled by your carrier.”

The fact that the first breach was caused by an insider made it even harder to correct, according to Jennifer Pitt, Senior Analyst of Fraud and Security at Javelin Strategy & Research. Pitt’s new report, Password Fatigue: A Case for Multilayered Passwordless Authentication, examines the challenges organizations face when insiders commit data breaches, whether purposefully or unwittingly. A Stanford study cited in the research found that half of all surveyed employees made an error at work that could lead to security concerns.

“Data breaches that involve inside actors often take longer to detect, causing more damage and financial loss, because the employee already has authorized access to the company network,” Pitt said. “With the rise of social engineering and shockingly realistic generative AI-based phishing attacks, employees are more easily being coaxed into providing user credentials and other sensitive information.”

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: BlockCash AppData BreachLawsuitPayment AppsZelle

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    banking

    Inside Banking’s $10 Billion Inflection Point

    May 14, 2026
    fraud disputes

    The Hidden Cost of Fraud Disputes Is Hitting Banks Hard

    May 13, 2026
    crypto payments

    Crypto Payments Are Ready for the Mainstream

    May 12, 2026
    payments, payment operations

    Staying Afloat as Payment Operations Rapidly Evolve

    May 11, 2026
    first-party fraud

    Inside the Growth of First-Party Fraud

    May 8, 2026
    fraud passkey, passkeys

    The Passkey You Can’t Steal: Why Hardware Beats Software for High-Stakes Authentication 

    May 7, 2026
    automotive collections

    Reducing Friction in Automotive Collections

    May 6, 2026
    payment cards as customer experience

    From Hygiene Factor to Hero Product: Why the Card Deserves a Second Look

    May 5, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result