Skip to main content

Company intelligence

Duc cybersecurity incidents and threat signals

duc.app

Duc logo

This company page brings together public reporting currently associated with Duc. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 26, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Duc. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Duc

Duc logoUse of stolen credentials or exploit
Medium

Money transfer app Duc exposes thousands of IDs and passports

Duc, a Toronto-based money transfer app, suffered a data breach due to an exposed Amazon server. The breach, reported in a roundup for March 27 - April 2, 2026, revealed hundreds of thousands of files dating back to 2020. Exposed data included government-issued IDs (such as driver's licenses or passports), selfies for know-your-customer (KYC) verification, and spreadsheets containing names, addresses, and transaction details. The data was stored unencrypted, allowing unauthorized access without a password.

Duc

FAQ

Questions about Duc cybersecurity reporting

What does the Duc page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Duc.

Does every mention of Duc appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.