LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › cashbackAPP Listed by malas Ransomware Group

HIGH severityUnverified claimHow we verify

cashbackAPP Listed by malas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 9, 2023
cashbackAPP Listed by malas Ransomware Group

Reported April 9, 2023.

HIGH
Severity
April 9, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The cashbackAPP Listed by malas Ransomware Group (reported April 9, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On April 09, 2023, the organisation cashbackAPP was listed by the ransomware group known as malas. Public reporting states that the incident involved the use of a Zimbra vulnerability and the exfiltration of internal files in a ransomware attack. The number of people affected remains unknown, and wider confirmed detail is limited.

Listings of this kind matter because they signal a claimed compromise that could place internal material and any associated personal or operational data at risk. Until more is verified, the core facts are the listing itself, the reported date, the named method, and the description of internal files taken.

Breaking down the breach

According to the available record, cashbackAPP appeared on a malas listing dated April 09, 2023. The reported summary indicates the attackers used a Zimbra vulnerability. Zimbra is widely deployed collaboration and email software; exploitation of known flaws in such platforms is a documented route into organisational networks, though the precise technical path, timing of initial access, and full scope of activity in this case are not publicly detailed beyond that summary.

The record describes internal files as having been exfiltrated in a ransomware attack. No figure is given for the volume of data, no file inventory is published in the facts, and the number of people affected is listed as unknown. Whether encryption was deployed alongside theft, whether systems were disrupted, and whether the organisation has confirmed or contested the claim are not stated in the available information. The incident is therefore known primarily through the group’s listing and the brief accompanying description rather than through a full independent technical disclosure.

The group behind it: malas

Malas is identified in the record as a ransomware group. Groups operating under this model typically gain access to networks, move laterally, exfiltrate data, and then threaten publication or further harm unless demands are met. They commonly advertise victims on leak sites to apply pressure. Public reporting on such actors often notes the use of known software vulnerabilities, stolen credentials, or other initial-access methods, followed by data theft framed as leverage.

In this instance, the group claims cashbackAPP as a victim and associates the activity with a Zimbra vulnerability and the exfiltration of internal files. That listing should be treated as a claim by the group rather than as independently confirmed fact unless and until the organisation or other authoritative sources verify it. No additional statements attributed to malas about this specific victim—such as ransom amounts, deadlines, or sample file releases—are included in the facts provided.

cashbackAPP and its sector

cashbackAPP operates in the cashback and consumer-rewards space. Organisations of this type typically provide users with rebates, points, or financial incentives tied to purchases, often through apps or web platforms linked to retail and payment activity. As a result they commonly hold account identifiers, contact details, transaction or redemption records, and related operational data needed to run rewards programmes.

A breach affecting such an organisation is consequential because the data environment sits at the intersection of consumer finance and everyday retail behaviour. Even when only “internal files” are named, those files can include materials that support customer operations, partner arrangements, or system configuration. Disruption or exposure in this sector can affect user trust, regulatory obligations around personal data, and the integrity of financial-incentive systems that people rely on for everyday spending.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as customer databases, credentials, financial records, or employee information—is supplied. The number of people affected is unknown, and exact contents remain unconfirmed.

Organisations in the cashback and rewards sector typically hold data that can include user account details, email addresses, phone numbers, transaction or cashback histories, payment-related tokens or references, and internal business documents. It is not established that any specific category beyond “internal files” was taken in this incident. Readers should therefore treat the precise composition of the stolen set as undisclosed rather than assume a full customer-data dump or any other particular inventory.

Why it matters

For individuals, the real-world risk depends on what the internal files actually contained. If personal or account data were included, possible outcomes include unwanted contact, phishing that references genuine account activity, or attempts to reuse credentials elsewhere. If the material was purely operational, direct consumer harm may be lower, yet secondary risks—such as attackers learning how systems work—can still arise. Because the affected population size is unknown, it is not possible to gauge how widely any personal impact extends.

For the organisation, a claimed ransomware incident with exfiltration raises issues of operational continuity, regulatory notification duties where personal data is involved, and reputational strain with users and partners. The reported use of a Zimbra vulnerability also underscores the broader exposure that internet-facing collaboration tools can create when patches or access controls lag. None of this establishes negligence as fact; it simply describes why such events carry weight for both the people whose data may be involved and the entity that holds it.

Were you affected?

If you have used cashbackAPP or related services, practical steps focus on reducing follow-on risk while public detail remains limited. Consider the following:

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it can help you see whether your address appears in previously compiled breach collections and prioritise further protections accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanycashbackAPP security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See cashbackAPP’s full breach history →

More recent breaches

Fraport Skyliners Listed by malas Ransomware GroupApril 9, 2023Mappy Italia Listed by malas Ransomware GroupApril 9, 2023Hardman’s Listed by malas Ransomware GroupApril 9, 2023Studio Papa Listed by malas Ransomware GroupApril 9, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the cashbackAPP Listed by malas Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by malas — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram