GCash is under investigation for the alleged breach of data on estimated 8 million users, which the leading e-wallet platform has strongly denied.
Amid a probe launched by the National Privacy Commission (NPC), Gcash refuted allegations of data breach even as it said it would work with regulators to clear up the issue.
In a dark web forum on Oct 25, 2025, a post under the user handle ‘Oversleep8351’ caught the attention of Deepweb Konek, a Philippine-based cybersecurity advocacy organization. The forum ‘G-Xchange/GCash (GXCHPHM2XXX) User Infos by ???????’ alleged that GCash user data were up for sale.
The dark web post claimed that the data set included:
Merchant and basic GCash user accounts
G-Xchange/GCash account numbers
Linked accounts, including virtual cards and bank connections
Know Your Customer (KYC) records such as names, addresses and employment details
According to the post, information was being sold in bundles covering estimated 7 to 8 million user data, coming from transactions and account registration from 2019 to October 2025. It also alleged that the mandatory KYC submitted by the users during account verification had contained valid Philippine identification documents.
NPC takes action
In a statement, NPC immediately started an investigation, ordering a Notice to Explain to the e-wallet platform operator G-Xchange Inc. It has also scheduled an online clarificatory conference.
The NPC assured that it would take regulatory and enforcement action upon confirmation of the alleged personal Gcash user data breach under the Data Privacy Act of 2012.
For its part, Gcash, in an advisory posted on Facebook, said there was ‘no evidence of any breach in Gcash systems.’
‘Upon swift investigation of our cybersecurity experts, the alleged dataset does not match data from GCash systems. Additionally, many entries are incomplete, invalid, or do not belong to GCash users,’ said Gcash.
To ensure cooperation, Gcash said it is working closely with the government agencies.