Data Breach Overview
A threat actor using the alias “passer” has claimed to be sharing a dataset containing more than one million records linked to users of Mexican credit and lending services.
According to the forum post, an initial batch of approximately 100,000 records was released, with additional data expected to follow. The post appears to have been published on August 23, 2026.
The exposed information allegedly includes extensive personal, identity, financial-profile, employment, and contact data belonging to loan applicants and users of multiple lending platforms.
Where Was the Data Found?
The dataset was advertised on DarkForums, where the poster shared a sample of the exposed records and provided access to the first batch.
The listed fields include:
- Unique applicant IDs
- Email addresses
- Phone and WhatsApp numbers
- Full legal names
- Gender, date of birth, and age
- CURP national identification numbers
- INE/IFE voter identification details
- Identification document issue and expiry information
- Full residential addresses
- Municipality, state, and postal codes
- Lending or BNPL platform names
- Declared salary information
- Education level
- Employment and housing information
- Pay frequency
- Registration timestamps
- References to identification-document files
The sample indicates that records may originate from multiple Mexican lending applications rather than a single company. Platforms visible in the sample include InputRapida, SieteRuedas, and ApoyoInmediato.
A Screenshot of the data can be found below:

Company Data Breach History
Because the dataset appears to aggregate information associated with several lending services, no single organization can currently be confirmed as the source of the alleged exposure.
A search for previous incidents involving the platforms visible in the sample did not identify credible public reports confirming earlier breaches or this newly advertised dataset.
Official information confirms that InputRapida is operated by Servicios de Inclusión INPUT S.A.P.I. de C.V. SOFORM ENR and processes personal and financial information as part of its lending services.
SieteRuedas identifies Ascoam SA de CV as its operator and states that its lending process may involve personal information, location data, identity documentation, and other information required for loan applications.
At this stage, there is no independent confirmation that either company suffered a direct system compromise. The origin and authenticity of the complete dataset remain unverified.
Impact and Risks
If the information is authentic, the combination of identity, contact, financial-profile, and address data creates significant risks for affected individuals.
Threat actors could potentially use the information for highly targeted phishing, impersonation, fraudulent loan applications, identity theft, social-engineering attacks, SIM-related fraud, or attempts to bypass identity-verification and account-recovery procedures.
CURP information, voter identification data, residential addresses, income details, and employment records are particularly sensitive because they can help criminals construct convincing identity profiles.
Recommendations for Users
Users who believe they may have used one of the affected lending platforms should:
- Change passwords associated with their lending and financial accounts
- Enable two-factor authentication wherever available
- Avoid reusing passwords across different services
- Monitor banking, credit, and lending accounts for suspicious activity
- Be cautious of unexpected calls, WhatsApp messages, emails, or loan offers requesting additional personal information
- Review credit activity for loans or accounts they do not recognize
- Contact the relevant financial institution immediately if unauthorized activity is detected
What is InsecureWeb?
InsecureWeb is a Dark Web monitoring service that keeps track of recent data breaches and tracks their impact by monitoring the darkest places of the internet.
Our commitment lies in providing top-notch cybersecurity services to our clients. Through continuous monitoring of the dark web and advanced threat detection methodologies, we strive to identify potential breaches promptly, enabling swift response and mitigation efforts. With our state-of-the-art tools and expertise, we prioritize the confidentiality, integrity, and availability of our clients’ data.
