Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Cash App Owner Settles $45 Million Over Lax Verification and Fraud‑Prone User Support

Block, Inc. will pay $45 M to 46 states after regulators said Cash App misled users about security, lacked real‑person support, and allowed unlimited account creation, exposing users to fraud. The incident underscores the need for robust SOC 2 access‑control evidence and continuous monitoring.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Cash App Owner Settles $45 Million Over Lax Verification and Fraud‑Prone User Support

What Happened — Block, Inc., the parent of Cash App, agreed to pay $45 M to 46 U.S. states after regulators said the company misled users about the app’s security, failed to provide adequate fraud‑prevention, and operated with weak identity‑verification standards. Investigators highlighted the absence of a real‑person phone support line, no requirement for Social Security numbers or birth dates, and unlimited account creation that enabled scammers to run large fraud networks.

Why It Matters for Compliance & Audit Readiness

  • The case illustrates a classic SOC 2 access‑control failure: insufficient user‑identity verification and inadequate monitoring of account‑creation processes.
  • Continuous evidence of verification controls, incident‑response timelines, and real‑person support coverage are essential audit artifacts to demonstrate compliance with CC6.1 (Logical Access) and CC7 (Incident Management).
  • Verisq’s SOC2 Access Controls capability can automate collection of verification logs, support‑channel metrics, and fraud‑investigation timelines, giving you a defensible audit trail.

Who Is Affected — Financial services / payments platforms, digital wallets, and any SaaS that onboards users with minimal identity checks.

Recommended Actions

  • Map your onboarding workflow to SOC 2 CC6.1 and CC6.2 controls; enforce minimum identity attributes (SSN, DOB) and limit account‑creation rates per user.
  • Implement 24/7 live‑person support or verified chat bots; log all support‑interaction timestamps as audit evidence.
  • Deploy continuous monitoring of fraud‑alert triggers and document investigation response times for SOC 2 CC7 compliance.

Source: The Record

Technical Notes

  • Attack vector: misconfiguration of verification policies and lack of real‑person support, enabling social‑engineering fraud.
  • No specific CVE; the weakness is procedural rather than software‑based.
  • Data types exposed: user account credentials, transaction histories, and personal identifiers (when voluntarily provided).

Source: The Record

📰 Original Source
https://therecord.media/cash-app-owner-to-pay-45-million-security-allegations ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →