Desk live·
ForensicPost
Breaches/Insider/File 22-0404

Cash App Investing Breach Traced to a Former Employee Who Still Had Access

A former Block employee downloaded Cash App Investing reports on 10 December 2021 — reports they had been entitled to read while employed. Around 8.2 million customers were contacted, in April 2022.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBlock — Cash App Investing
ActorSingle operator
S. Rosler10 min readConfidence: high2 sources reviewed

On 4 April 2022 Block disclosed that a former employee had downloaded reports belonging to its subsidiary Cash App Investing on 10 December 2021. The company said the employee had had routine access to those reports as part of their job, and that this access was used without permission after their employment ended.

Around 8.2 million current and former customers were contacted. Reported contents were full name and brokerage account number, and for some customers portfolio value, holdings and one trading day’s activity. Block stated the reports did not contain usernames, passwords, social security numbers, dates of birth, card or bank details, or addresses.

Offboarding Is A Security Control

There is no exploit here, no phishing page, no malware. Someone who had been allowed to read something continued to be able to read it after the reason for allowing it stopped.

We have recorded the same shape at 26-0713, where the support relationship was the exposure, and at 22-0120, where a contractor’s session was the way in. Access removal is administrative work that produces nothing visible when done correctly, which is precisely why it is the control most reliably skipped.

Four Months, And What Was Not Taken

The download was in December and the notification was in April. We filed that interval repeatedly — 289 days at 26-0721b, two months at 22-0120 — and argues the clock that matters starts when the data leaves, not when the organisation finishes deciding.

Block’s disclosure is unusually precise about what was not in the reports, and this desk records that as a credit rather than a hedge. A notification that enumerates the categories excluded lets a customer reason about their exposure; most say only what was included and leave the rest to imagination.

A Portfolio Is A Profile

No identity document was taken and no credential was exposed, so by the usual measures this is a mild incident. It is worth noting what a brokerage holdings list actually is: a statement of what someone owns and how much of it.

That is targeting material for social engineering rather than fraud material — a category the corpus keeps meeting at 26-0712 in deepfake-assisted business email compromise. Knowing what a person holds is knowing what a plausible message to them looks like.

How we reported this

Compiled from Block’s own disclosure and contemporaneous reporting of it, listed below. That the reports were within the employee’s prior job responsibilities is the company’s characterisation. No individual is named and no motive is asserted — none was established publicly. The observation about holdings data as targeting material is this desk’s reasoning, presented as such. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Block confirms Cash App breach after former employee accessed US customer dataTechCrunch
  2. More than 8 million Cash App Investing customers potentially impacted by data breach linked to former employeeCNN Business
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary