Skip to main content

NubankSensitive debt-collection data of 30,000+ Nubank Colombia customers leaked via third-party vendor and sold on dark web

In late March 2026, data belonging to more than 30,000 Nubank Colombia customers -- including full names, national ID (cedula) numbers, phone numbers, overdue amounts, payment histories and internal collection notes -- was exposed and offered for sale on a dark web forum (asking price ~$200 USD) by a seller using the handle 'Petro_Escobar.' Nubank confirmed the breach occurred not in its own systems but at two third-party debt-collection vendors it contracted with, EmergiaCC and Conalcreditos, and stated no passwords, encryption keys, or account/deposit information were exposed. The same threat actor reportedly also compromised BBVA Colombia collections data, suggesting a wider campaign against financial-sector collection vendors in Colombia.

Scoring Impact

TopicDirectionRelevanceContribution
Consumer Protection-againstsecondary-0.50
Data Security-againstprimary-1.00
Overall incident score =-0.214

Score = avg(topic contributions) × significance (medium ×1) × confidence (0.57)× agency (negligent ×0.5)

Evidence (1 signal)

Confirms Statement Mar 27, 2026 documented

Nubank confirmed collections data of 30,000+ Colombian customers breached at third-party vendor, offered for sale on dark web

Colombian outlets reported that data on more than 30,000 Nubank Colombia customers -- names, national ID numbers, phone numbers, debt and payment histories -- was put up for sale on a dark web forum after a breach at Nubank's contracted debt-collection vendors EmergiaCC and Conalcreditos. Nubank issued a statement confirming the incident originated at the external vendor platform, not its own infrastructure, and said it activated its security protocols and was investigating jointly with authorities.

Related: Same Topics