Money Bookers Data Breach (2009): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Money Bookers Data Breach (2009) (reported January 1, 2009) exposed Dates of birth, Email addresses, IP addresses and Names belonging to roughly 4.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Breaking down the breach
The available facts state that the intrusion took place sometime in 2009 and affected roughly 4.5 million customer records. No information has been released about the method of access, the duration of unauthorised presence inside the network, or any files that may have been copied. The breach was not identified until October 2015. No dollar figures, attacker claims or internal investigation findings have been made public.
How a breach like this happens
Incidents involving large customer databases at payment or financial-service companies often begin with the compromise of an internet-facing server or an internal system that holds user records. Attackers may exploit unpatched software, weak authentication, or stolen credentials to reach the data store. Once inside, they can copy tables containing names, contact details and account metadata without immediately triggering detection. In many cases the organisation only learns of the event when the data later appears on public forums or when external researchers notify the company.
Who is Money Bookers?
Money Bookers operated an electronic wallet service that allowed users to send and receive payments online. Such platforms routinely collect and retain personal identifiers, contact information and transaction metadata to comply with regulatory requirements and to manage accounts. The company was later renamed Skrill. A breach at an organisation of this type is consequential because the data it holds can be used for targeted phishing, identity misuse or further attacks against the same individuals at other services.
What data was at risk
The records listed in connection with the incident include names, email addresses, dates of birth, phone numbers, physical addresses and IP addresses. It is not confirmed whether additional categories such as passwords, payment card details or transaction histories were also exposed. Organisations in this sector typically store enough information to verify customer identity and process payments; however, the precise contents of the 2009 dataset remain unconfirmed beyond the fields already named.
What's at stake
Individuals whose records were involved face the possibility that their contact details and identifiers could be used for unsolicited messages or more targeted attempts to compromise other accounts. For the organisation, the incident created long-term reputational and regulatory exposure once it became public years after the event. Because the breach went unnoticed for an extended period, it is difficult to determine how the data may have been used in the intervening years.
Were you affected?
Anyone who held a Money Bookers account before or during 2009 may wish to review statements from Skrill and monitor their email and postal addresses for unusual activity. A practical first step is to change passwords on that account and any other services that reuse the same credentials. Readers can also run a free exposure scan of their email address against known breach data to check whether their information appears in publicly discussed datasets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Moody Bible Institute Data Breach (2026)Sysco Data Breach (2026)JCPenney Data Breach (2026)American Tower Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Money Bookers Data Breach (2009) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.