HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Cash App Owner Settles $45 Million Over Lax Verification and Fraud‑Prone User Support

Block, Inc. will pay $45 M to 46 states after regulators said Cash App misled users about security, lacked real‑person support, and allowed unlimited account creation, exposing users to fraud. The incident underscores the need for robust SOC 2 access‑control evidence and continuous monitoring.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Cash App Owner Settles $45 Million Over Lax Verification and Fraud‑Prone User Support

What Happened — Block, Inc., the parent of Cash App, agreed to pay $45 M to 46 U.S. states after regulators said the company misled users about the app’s security, failed to provide adequate fraud‑prevention, and operated with weak identity‑verification standards. Investigators highlighted the absence of a real‑person phone support line, no requirement for Social Security numbers or birth dates, and unlimited account creation that enabled scammers to run large fraud networks.

Why It Matters for Compliance & Audit Readiness

  • The case illustrates a classic SOC 2 access‑control failure: insufficient user‑identity verification and inadequate monitoring of account‑creation processes.
  • Continuous evidence of verification controls, incident‑response timelines, and real‑person support coverage are essential audit artifacts to demonstrate compliance with CC6.1 (Logical Access) and CC7 (Incident Management).
  • Verisq’s SOC2 Access Controls capability can automate collection of verification logs, support‑channel metrics, and fraud‑investigation timelines, giving you a defensible audit trail.

Who Is Affected — Financial services / payments platforms, digital wallets, and any SaaS that onboards users with minimal identity checks.

Recommended Actions

  • Map your onboarding workflow to SOC 2 CC6.1 and CC6.2 controls; enforce minimum identity attributes (SSN, DOB) and limit account‑creation rates per user.
  • Implement 24/7 live‑person support or verified chat bots; log all support‑interaction timestamps as audit evidence.
  • Deploy continuous monitoring of fraud‑alert triggers and document investigation response times for SOC 2 CC7 compliance.

Source: The Record

Technical Notes

  • Attack vector: misconfiguration of verification policies and lack of real‑person support, enabling social‑engineering fraud.
  • No specific CVE; the weakness is procedural rather than software‑based.
  • Data types exposed: user account credentials, transaction histories, and personal identifiers (when voluntarily provided).

Source: The Record

📰 Original Source
https://therecord.media/cash-app-owner-to-pay-45-million-security-allegations

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →