-
A threat actor is advertising 783,262 justETF user records for $600 on a dark web forum.
-
The alleged database includes names, birth dates, phone numbers, email addresses and countries, but the claim is unverified.
-
justETF’s public privacy notice confirms it handles some of these details, but that does not prove the forum data came from its systems.

A seller on an underground forum claims to have a database tied to justETF, a German platform for comparing ETFs and portfolio management.
The database reportedly holds nearly 790,000 entries. According to the listing, the dataset includes first and last names, date of birth, phone number, email address, and country. The entire haul is going for $600. It is a single-time sale with a guarantor available.
Currently, there’s no proof that the database is from justETF. There’s also no credible data breach notification report or information from the company. Underground vendors often claim massive databases from popular companies to attract buyers.
Details of the Forum Listing
The seller says this dataset comes from justETF’s customer or user base, and claims it holds about 783,262 records. That’s a big number, and honestly, the price seems low for something that size. Still, price doesn’t tell you if the records are real, up-to-date, or actually complete. Sellers sometimes recycle old data or mix info from a bunch of different places.
What really matters are the fields they offer. Names, birth dates, phone numbers, and email addresses all in one place can give an attacker a full profile on someone. It’s supposedly a one-time sale, and the seller says a guarantor is allowed. While this could make buyers feel safe, that reassurance doesn’t prove the data is actually real.
What Category of Data does justETF Jandle
justETF GmbH is the operator of the justETF website and app in Munich. Its current privacy policy confirms that users can create customer profiles during registration. And during that process, justETF collects a salutation, first name, last name, and email address. It stores the password for accessing accounts. From the privacy notice, it is evident that justETF maintains customers’ telephone numbers as well.
However, the public registration page doesn’t list date of birth as a requirement for creating a profile. This does not preclude the company from maintaining birth dates for any other purpose. It just means that registration information alone can’t confirm the field alleged in the latest forum listing.
JustETF also uses Amazon Web Services to store its database and website content. It maintains its data at a data center in Frankfurt, Germany. It is pretty popular across Europe.
The company says they’re aimed at both beginners and experienced ETF investors, offering portfolio tools, guides, and their own ETF database. But there’s nothing in that forum listing showing the seller can access financial accounts, brokerage logins, or portfolio balances.
No Confirmed Breach at this Point
The forum post doesn’t actually show that justETF experienced a data breach. There’s nothing public to confirm that those 783,262 records are real or from justETF. The actor didn’t release a sample to back their claims or show whether it’s a fresh database or not.
A lot of things could explain this. Maybe the data is legit, but old. It could be from a totally different incident, or someone just put the justETF label on random records from somewhere else. It might even be a mix of duplicates and incomplete records. So, the number of records alone doesn’t mean the database is real.
Why the Alleged Data Could Matter
Names, email addresses, and phone numbers can make scam messages more convincing. A date of birth can add another layer of personal detail. Other recent data-leak claims have involved even more sensitive identity documents, including a case where a hacker group allegedly threatened to leak passports and birth certificates of 120 Israelis.
The FTC warns that fraudsters rely on personal data in phishing attempts and identity fraud. The commission recommends individuals refrain from clicking on unsolicited links and contact organizations via official web pages or phone numbers.
If the alleged records are accurate and current, criminals could use them to pose as justETF, a broker, a bank or another financial service. The data could also help attackers build profiles for targeted scams. Still, there is no evidence that such activity has happened because of this listing.
What Users Should Watch for
For justETF users, beware of unsolicited messages about your account, investments, payments, or security. Don’t click on links in emails or texts you didn’t expect; stay cautious. Verify such communications by contacting justETF or checking the website for updates.
Using unique passwords could help reduce the risks associated with a compromised database. Using 2FA offers an extra layer of protection where available. The FTC recommends it since it makes accessing an account difficult even if the attacker has the password.
For now, the statement remains just a mere underground forum claim until an independent verification or notice from justETF comes through. Nevertheless, it is still necessary to keep watch.