Cybernews reported that seven improperly authenticated Azure Blob Storage buckets exposed personal information tied to nearly 135,000 clients at seven financial institutions in Latin America. The publication linked the buckets to Bankingly, a fintech platform serving financial institutions in the region. It said the data had been secured after the company was contacted, but the report did not establish whether anyone accessed or copied it.
What happened in the reported data leak?
Cybernews said its research team identified seven Azure Blob Storage buckets without proper authentication on May 24. The available article text does not give the year of that discovery or the report’s publication date. Cybernews linked the buckets to Bankingly, a Uruguay-based fintech platform that provides web services and mobile applications to financial institutions in Latin America, including smaller banks, credit unions, and microfinance institutions.
The reported issue was an exposure caused by storage that lacked proper authentication. The report does not identify a confirmed attacker or establish that the incident involved a breach of Bankingly’s core systems.
How many people and institutions were affected?
Cybernews estimated that nearly 135,000 clients across seven financial institutions were affected. It said nearly 100,000 of those people were in the Dominican Republic. The report named institutions in the Dominican Republic, Mexico, Ecuador, El Salvador, Bolivia, and Costa Rica:
Recommended Free Tools
#1 Best Overall
- La Cooperativa de Ahorro y Crédito Abierta “San Martín de Porres” (COSMART)
- Asociación La Nacional de Ahorros y Préstamos (ALNAP)
- Caja Buenos Aires
- Caja Mitras
- Coac Puellaro
- Credecoop
- AMC
These figures and names are those reported by Cybernews; the available text does not establish independent confirmation by the institutions or regulators.
What data was leaked?
Cybernews listed the following information in the exposed buckets:
- Full names
- Financial application usernames
- Email addresses
- Phone numbers, including work phone numbers
The article did not list passwords, government-issued identification numbers, passport details, or payment-card numbers among the exposed fields. That does not rule out other risks: the combination of contact details and a financial-app username can help a scammer make a message or call sound credible.
What risks should customers watch for?
Phishing and impersonation
Cybernews warned that criminals could pose as a bank, credit union, or financial app and use the exposed details to persuade customers to share passwords, verification codes, or other information. Treat unexpected calls, texts, emails, and links with caution, even if the sender knows your name or app username.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Credential stuffing
If you reused a password on a financial app and another service, an attacker could try credentials exposed in an unrelated older breach. The Cybernews report did not say that passwords were in these buckets or that credential-stuffing attacks occurred in this incident. Using a unique password for each financial account reduces the risk that a password from one service will unlock another.
An unnamed Cybernews researcher said the listed data “might not be enough for cybercriminals to directly make financial transactions, such as applying for loans or opening new bank accounts.” This is not a guarantee that fraud is impossible; exposed information can still support attempts to obtain more sensitive data or gain access to accounts.
Rank #4
What did Bankingly and the institutions do?
Cybernews said it contacted Bankingly and that the data in the buckets had been secured. At the time of the report, the publication said Bankingly had not responded to its request for comment and that responses from affected institutions were still pending. The available article text does not establish whether customers were notified, whether regulators issued findings, or whether any later investigation confirmed unauthorized access.
What should affected customers do?
- Verify communications independently. If a message or caller claims to represent your financial institution, do not use its link or phone number to provide information. Contact the institution through its official app, website, or a number on your card or statement.
- Do not share authentication secrets. Never disclose your password or one-time verification code in response to an unsolicited call, message, or email.
- Change reused passwords. If you used the same password for a financial app and another service, replace it with a unique one. Use the institution’s official app or website rather than a link in an unexpected message.
- Review account activity. Check recent transactions, sign-in alerts, and contact details in your financial account. Contact the institution promptly through an official channel if you see activity you do not recognize.
- Ask the institution for incident-specific guidance. The report does not establish which customers were notified or what protective steps the institutions recommended, so ask your own provider whether your account was involved and what actions it advises.
What remains unconfirmed?
The available Cybernews article text does not state the year of the May 24 discovery, how long the buckets were exposed, whether anyone accessed or copied the data, or whether affected customers were notified. It also does not include later official findings from Bankingly, the named institutions, or regulators. The reported exposure should therefore be distinguished from confirmed downstream fraud or a confirmed theft of the data.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




