LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Manipulated Caiman Data Breach (2023)

CRITICAL severityConfirmedHow we verify

Manipulated Caiman Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 16, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Manipulated Caiman Data Breach (2023)

Reported July 16, 2023. Approximately 39.9M people affected.

CRITICAL
Severity
39.9M
People affected
1
Data types exposed
July 16, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Manipulated Caiman Data Breach (2023) (reported July 16, 2023) exposed Email addresses belonging to roughly 39.9M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Manipulated Caiman Data Breach (2023) breach?
39.9M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Nearly 40 million email addresses were tied to a large-scale phishing campaign reported in mid-2023, leaving many people—especially in Mexico—facing a concrete risk that their inboxes could be used to push fraudulent banking messages. When researchers handed that list to a public breach-notification service, the practical question for ordinary users became simple: whether their address was among those targeted and what that exposure could mean for account security.

Public reporting describes the episode as a spear-phishing operation rather than a conventional corporate database theft. The known details centre on the volume of addresses collected, the stated aim of reaching bank accounts, and the decision to share the list so potential victims could be alerted. Exact technical methods beyond malicious attachments, full victim lists, and any later misuse remain limited in the public record.

Breaking down the breach

On 16 July 2023 the incident was reported under the headline Manipulated Caiman Data Breach. Perception Point described a phishing operation it dubbed “Manipulated Caiman.” According to the reported summary, the campaign primarily targeted citizens of Mexico and sought access to victims’ bank accounts through spear-phishing messages that carried malicious attachments. Researchers obtained almost 40 million email addresses that had been targeted in the campaign—public figures put the count at 39.9 million—and supplied that data to Have I Been Pwned so that people whose addresses appeared could be notified.

No further breakdown of how the addresses were originally assembled, whether additional personal data accompanied them, or the precise infrastructure used by the operators has been disclosed in the available facts. The record does not attribute the activity to a named criminal group beyond the campaign label itself, nor does it state that any single company’s internal systems were compromised. What is established is the scale of the address list, the geographic focus, the banking objective, and the researchers’ decision to place the addresses into a public alerting service.

How a breach like this happens

In general terms, large phishing campaigns of this type begin with the assembly of extensive email lists. Operators may buy, scrape, or reuse addresses from earlier leaks, then craft messages that appear to come from banks or familiar services. Spear-phishing variants personalise those messages and attach files designed to install malware or direct the recipient to a counterfeit login page. Once a victim opens the attachment or enters credentials, the attacker can attempt to take over online banking sessions or harvest further personal details.

Security researchers who intercept or obtain such lists sometimes publish or share them with breach-notification platforms. The goal is usually to warn the people whose addresses appear so they can watch for suspicious mail and harden their accounts. This pattern does not require a single corporate “breach” in the classic sense; the exposure arises from the weaponisation of contact data at scale. No specific threat actor is named in the facts for this incident, and none should be assumed.

Manipulated Caiman and its sector

Manipulated Caiman is the label given to the phishing operation itself rather than to a conventional company or public institution. In the cybersecurity field, researchers routinely assign codenames to campaigns so they can track tactics, infrastructure and victim sets over time. The sector context is therefore financial crime and social-engineering attacks aimed at retail banking customers.

Organisations and campaigns operating in this space typically traffic in email addresses and related contact data because those details are the entry point for fraudulent messages. A list numbering in the tens of millions is consequential simply because of its size: even a small success rate can produce thousands of compromised bank logins. The reported focus on Mexican citizens underscores that the operators appear to have concentrated on a national banking market, where phishing remains a persistent threat to ordinary account holders.

What was likely exposed

The facts name only one data type as exposed: email addresses. Approximately 39.9 million of them were obtained by researchers and provided to Have I Been Pwned. No other categories—names, phone numbers, government identifiers, passwords, or full banking credentials—are listed as confirmed contents of the shared data set.

Organisations and criminal campaigns that assemble large email lists for phishing often hold or seek additional fields that make messages more convincing, yet the public record for this incident does not confirm any such extras. Readers should treat the exact contents beyond email addresses as unconfirmed. The practical exposure that is known is the presence of those addresses on a list that was actively used, or intended for use, in banking-focused spear-phishing.

What's at stake

For individuals, the immediate risk is receiving tailored phishing messages that attempt to steal online-banking credentials or install malware. An email address alone does not open a bank account, but it is the channel through which attackers deliver the lure. People whose addresses appear may face elevated volumes of fraudulent mail for months or years, increasing the chance of a successful compromise if vigilance slips. Secondary risks include credential stuffing on other sites if the same address is reused as a username, and social-engineering follow-ups that reference the original campaign.

For the broader public and for financial institutions serving the targeted population, the episode illustrates how large contact lists can be turned into operational tools. Banks and customers both bear the cost of fraud monitoring, account recovery and lost trust. Because the facts do not describe a breach of any particular bank’s own systems, the organisational stake lies mainly in the continued effectiveness of customer education and anti-phishing controls rather than in a single internal incident response.

If your data was in this breach

Treat any unexpected email that claims to be from a bank with caution, especially messages that urge immediate action or carry attachments. Do not open those attachments or enter credentials on links supplied in the message; instead navigate to your bank’s site independently or use its official app. Enable multi-factor authentication on email and financial accounts where available, and consider a unique, strong password for each service. Monitor account statements for unfamiliar transactions and report anything suspicious promptly to your bank.

You can also run a free exposure scan of your email address with a reputable breach-notification service to check whether it has surfaced in this or other known data sets. That check does not remove the address from circulation, but it gives you a clearer picture of your exposure and a reminder to stay alert.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyManipulated Caiman security record
74/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Manipulated Caiman’s full breach history →

More recent breaches

GLAMIRA Data Breach (2023)December 16, 2023Welhof Data Breach (2023)December 1, 2023Zadig & Voltaire Data Breach (2023)November 16, 2023Blooms Today Data Breach (2023)November 11, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Manipulated Caiman Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram