DZI Linked to an Offer of 3.1 Million Identity Records
**A post on a clandestine forum claims that 3,134,269 records attributed to DZI Insurance, containing national identity numbers, passports, and addresses, are for sale in Bulgaria. The information has not been independently verified, but the volume and nature of the data pose significant risks to digital identity and the security controls of financial institutions.
- A post attributes the alleged breach to an inadequately protected API from the DZI Insurance customer portal.
- The announced dataset would include national identity numbers, passports, dates of birth, names, addresses, emails, and phone numbers.
- The offer, observed on September 1, 2026, limits the sale to two buyers and does not yet have a public price.
DZI Linked to an Offer of 3.1 Million Identity Records
A post on a clandestine forum offers 3,134,269 records that, according to the seller's claim, belong to customers of DZI Insurance, a Bulgarian company linked to KBC Group. The announcement indicates that the data would have been extracted on May 21, 2026, through an inadequately protected API from the customer portal, although it does not identify an endpoint or a specific vulnerability. The information was observed on September 1, 2026, and remains unverified independently.
The announced dataset would include national identity numbers, dates of birth, passport numbers, issuance dates, and issuing authorities, as well as names written in Cyrillic and Latin. It would also contain complete postal addresses, emails, up to two phone numbers per record, and indicators related to SMS, nationality, residency, and type of person. The seller claims that raw JSON files exist and promises to deliver additional information to buyers.
The offer appears under the name of actor Intelligence, with a limit of two buyers and a price available only upon inquiry. Dark Web Informer described the post as an allegation that has not yet been confirmed, as it did not retrieve the data or link the offered files. Neither DZI nor its parent company had publicly addressed the claim at the time of reporting.
What the Announcement Claims About the Breach
The post attributes the initial access to an exposed interface of the customer portal, a description that could fit the exploitation of a public-facing application, but does not alone demonstrate how the incident occurred. The account does not provide names of endpoints, error messages, technical captures, or reproducible proof of the alleged failure. Therefore, the reference to a poorly secured API should be treated as a commercial statement from the actor, not as a forensic conclusion.
The seller claims to have extracted the records in volume and can deliver both a tabular dataset and raw JSON files. This combination would be compatible with information obtained through a query interface, although it could also be presented to enhance the credibility of a clandestine offer. The existence of plausible formats does not confirm that the data comes from DZI or that all records are current.
The post lists fields that would allow linking a civil identity with official documents and contact channels. Among them are the national identity number, passport details, and the issuing authority. The combination transforms the alleged dataset into something much more sensitive than a base of isolated emails or phone numbers.
The announcement also claims that there could be additional deliveries, a common promise in underground markets as it seeks to raise pressure on potential buyers. The limit of two buyers suggests a strategy of restricted circulation, either to increase the price or to reduce the public exposure of the material. However, the actor's new account, its only post, and the absence of a verifiable price hinder an accurate assessment of the authenticity or the real scope of the offer.
The Risk of Concentrating Permanent Identifiers
The national identity number occupies a central place in the relationships of Bulgarian citizens with banking, health, and government institutions, according to the report's description. Unlike a password or a phone number, it is not a piece of data that a person can easily change after exposure. When combined with name, date of birth, and address, it can facilitate impersonation attempts directed against services that still rely on basic verifications.
The alleged access to passport numbers adds another layer of sensitivity, especially since the announcement would include issuance dates and authorities responsible for each document. A record with those fields, along with phone numbers and email addresses, could serve to construct social engineering messages that appear legitimate. This consequence is potential and does not equate to claiming that fraud, bank access, or illicit uses of the information have already occurred.
The announced volume reaches 3,134,269 records and, if authentic and not containing significant duplicates, would represent a substantial proportion of Bulgaria's adult population. This scale shifts the question from identifying a few victims to reviewing how many institutions still accept a name and a national identifier as sufficient evidence of identity. It also increases the case's interest for insurers, banks, health providers, and public agencies that share verification processes.
The sale limited to two buyers could reduce immediate dissemination, but it does not eliminate the danger of deliberate exploitation by a small group. A database concentrated in few hands can be used to select targets, cross-reference information with other sets, or test highly personalized contact scripts. As there is no confirmation of access, sale, or subsequent use, these possibilities should be presented as risk scenarios and not as established facts.
What Is Known and What Remains Unconfirmed
The report indicates that the observed sample maintains Cyrillic and Latin transliterations that correspond, plausible identifier formats, and real Bulgarian localities. These elements may be difficult to fabricate on a large scale, but a consistent sample does not prove on its own that the source is DZI Insurance. The technical assessment also lacks direct validation with the company, a chain of custody of the files, and a public comparison with legitimate records.
There are also signals that advise caution before turning the offer into a confirmed leak. The seller's account is completely new, only records one post, shows no transaction history, and does not publish a price; moreover, the promise of new data is part of the usual tactics to attract buyers. These circumstances do not refute the announcement, but they do reduce the confidence that can be assigned to its commercial claims.
The date attributed to the extraction deserves special scrutiny, as May 21, 2026, precedes the public observation of the announcement by more than three months, which took place on September 1 of the same year. The delay could have various explanations, including a private sale or a publication after the data was obtained, but the report does not provide an answer. In a jurisdiction of the European Union, any eventual notification to the competent authority would also be an aspect that requires clarification.
For now, the case should be described as an unverified offer of data attributed to DZI Insurance, not as a confirmed breach against the company. Confirmation would require a response from DZI or KBC Group, analysis of legally obtained samples, technical evidence regarding the API, and an assessment of whether the records are authentic, recent, and exclusive. Until those elements appear, the most solid fact is the existence of the publication and not the truthfulness of everything the seller promises.
The episode illustrates why organizations that handle identity must apply stronger controls than just a password and a static identifier. It also reminds users that a clandestine offer can mix real data, outdated information, and invented material to appear convincing. Vigilance, timely notification, and additional authentication remain essential, although none of those measures alone can confirm that this dataset was extracted from DZI.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Fraud by Manipulation in France: +34% in 2025, €516 Million Diverted

Bitcoin time-delay locks could prevent bridge bugs from causing total losses: Rootstock co-founder

U.S. announces $500 refunds for nearly one million Obamacare enrollees

Dark energy may be changing, according to a study of 3,000 supernovae

This Guy Cloned Sam Altman, Elon Musk, and Zuckerberg Into AI Bots. They Immediately Started Fighting

How to Travel the World with Free Accommodation through House Swapping

MIT Tests Magnetic Nanoantennas Against Drug-Resistant Glioblastoma

Circle to Withdraw USDC Support on Noble and Shut Down CCTP V1

Meet Kute, the New Bitcoin Wallet for Generation Z

Cosmos says bank tokenization is moving beyond pilots

Rising Oil Prices Recalibrate the Landscape for Argentine Investors: Which Alternatives Are Gaining Ground

How Will Apple's New Product Launch Event Impact AAPL Stock and Stock Tokens?

Oil Above $100: What Changes for Petrobras and the Ibovespa

After the failure of Web3 games, memecoins target old video games

Benjamin Cowen's Analysis of Bitcoin's Current Situation: Higher Probability of a New Bottom!

For the IMF, delinquency does not pose a risk to financial stability

Hunter Biden: No Internal Sell-Off Amid LAPTOP Meme Coin Crash

Find out now if your congressman votes in favor of Bitcoin

Nobel Laureate Daron Acemoğlu to Speak at Istanbul Fintech Week on October 6

Brent Price Forecasts Soar to $90, HSBC Warns: Risk of $120

RBC Crypto Forum: Key Topics Currently Discussed by the Crypto Community

BIS Warns of Financial Stability Risks Amid AI Investment Boom and Increased Reliance on Debt and Private Credit

Snapchat Launches Plans to Compete with Partiful in Event Organization

BCRA expects a $4.4 billion offer from companies and provinces to support dollar purchases

The Journey to Agentic Payment: The Real Challenge Lies in the Middle Path

Comparison of Four US Stock Tokens: BNB Chain, Robinhood Chain, Base, Solana

Crypto Stops Being a "Separate World": How It Is Merging with Traditional Finance

SEC gives Bitcoin-heavy trusts a new 15% window to venture beyond existing listing rules

Schools During 'Yellow' Alert: Changes for Students, Parents, and Teachers
