Duc App Data Breach: What You Need to Know

By Justin Giovannetti  |

Toronto-based fintech company Duales allegedly left an Amazon-hosted cloud storage server – containing sensitive customer data from its Duc money transfer app – publicly accessible on the internet for approximately five years.

Security researcher Anurag Sen discovered the misconfiguration and alerted TechCrunch, which notified Duales. The company resolved the exposure on April 2, 2026. The server allegedly contained over 360,000 files uploaded since September 2020, including passports, driver’s licences, selfies collected for identity verification, and spreadsheets with customer names, addresses, and transaction details.

What Should Duc App Users Do?

If you submitted identity documents or personal information through the Duc App, consider monitoring your credit and financial accounts for unusual activity, staying alert to phishing attempts, and placing a fraud alert with Equifax and TransUnion.

Slater Vecchio LLP Is Investigating

Slater Vecchio LLP is investigating this matter on behalf of individuals whose personal information may have been affected. If you have been contacted by Duales about this breach, please contact us at classactioninvestigations@slatervecchio.com.

This post is for informational purposes only and does not constitute legal advice. Allegations are drawn from publicly available reporting and have not been adjudicated.

Related Topics

Recent Stories
Justin Giovannetti
Associate
Justin practices in class action and personal injury litigation, driven by a commitment to advocate for individuals and consumers. His motivation in class action cases stems from a passion for redressing wrongs and ensuring fair representation. Justin represents clients in cases involving environmental law, consumer protection, and competition law.