Affirm Data Breach Allegedly Exposes 26.7 Million User Records on Dark Web

Share
Affirm Data Breach Allegedly Exposes 26.7 Million User Records on Dark Web

A threat actor is allegedly selling a database containing 26.7 million user records from Affirm, the popular buy-now-pay-later financial services platform operating in the United States and Canada.

The listing appeared on the Exploit cybercrime forum on January 23, 2026, posted by a threat actor using the handle "renn." The seller claims the 1.9GB database was obtained the same day and is offering the complete dataset for $14,000 or $700 per million records with a minimum purchase of one million lines.

Sale Details

According to the forum post, the database contains over 26.7 million records. The threat actor notes that some phone numbers in the dataset may contain placeholder values. The listing emphasizes the data will only be sold once, with records updated after any sale.

Affirm provides installment payment services to consumers making purchases at major retailers and e-commerce platforms. The company went public in 2021 and serves millions of customers across North America.

Unverified Claims

The authenticity of the alleged breach has not been independently verified. Affirm has not publicly confirmed any security incident. Organizations monitoring dark web forums have flagged the listing, but the claims remain unsubstantiated until further evidence emerges.

Affirm users concerned about potential exposure should monitor their accounts for suspicious activity and consider enabling additional security measures where available.

This story will be updated if Affirm releases a statement or additional details emerge.

Read more

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire