On 4 April 2022 Block disclosed that a former employee had downloaded reports belonging to its subsidiary Cash App Investing on 10 December 2021. The company said the employee had had routine access to those reports as part of their job, and that this access was used without permission after their employment ended.
Around 8.2 million current and former customers were contacted. Reported contents were full name and brokerage account number, and for some customers portfolio value, holdings and one trading day’s activity. Block stated the reports did not contain usernames, passwords, social security numbers, dates of birth, card or bank details, or addresses.
Offboarding Is A Security Control
There is no exploit here, no phishing page, no malware. Someone who had been allowed to read something continued to be able to read it after the reason for allowing it stopped.
We have recorded the same shape at 26-0713, where the support relationship was the exposure, and at 22-0120, where a contractor’s session was the way in. Access removal is administrative work that produces nothing visible when done correctly, which is precisely why it is the control most reliably skipped.
Four Months, And What Was Not Taken
The download was in December and the notification was in April. We filed that interval repeatedly — 289 days at 26-0721b, two months at 22-0120 — and argues the clock that matters starts when the data leaves, not when the organisation finishes deciding.
Block’s disclosure is unusually precise about what was not in the reports, and this desk records that as a credit rather than a hedge. A notification that enumerates the categories excluded lets a customer reason about their exposure; most say only what was included and leave the rest to imagination.
A Portfolio Is A Profile
No identity document was taken and no credential was exposed, so by the usual measures this is a mild incident. It is worth noting what a brokerage holdings list actually is: a statement of what someone owns and how much of it.
That is targeting material for social engineering rather than fraud material — a category the corpus keeps meeting at 26-0712 in deepfake-assisted business email compromise. Knowing what a person holds is knowing what a plausible message to them looks like.
Compiled from Block’s own disclosure and contemporaneous reporting of it, listed below. That the reports were within the employee’s prior job responsibilities is the company’s characterisation. No individual is named and no motive is asserted — none was established publicly. The observation about holdings data as targeting material is this desk’s reasoning, presented as such. Graded high. Corrections: corrections@forensicpost.com.