Remita: KYC documents and databases claimed stolen
Remita (SystemSpecs)
Overview
On March 31, 2026, GOD-ranked DarkForums user ByteToBreach claimed a breach of Remita, the Nigerian electronic payment platform operated by SystemSpecs. The post states that around 3 TB of S3 storage was accessed, including over 800 GB of KYC-related documents, MySQL and Postgres databases, logs and docker registries, and that source code, over 35,000 password hashes and three databases were released.

What was published
The post claims the following were exposed:
- KYC documents including IDs, passports, photos, bank statements and utility bills
- More than 35,000 password hashes
- Three databases and application source code
- Docker registries, logs and secrets including HSM keys
The poster provided screenshots of passports, database restores, source code and secrets, plus VPS and cloud backup links.
Risks for affected individuals
Nigerians who used Remita for payments may have KYC documents such as passports and bank statements exposed. Identity documents combined with bank statements enable identity theft and financial fraud, and the release of password hashes increases account takeover risk.
What remains unknown
- SystemSpecs and Remita have not publicly confirmed the breach
- The number of affected individuals is not disclosed
- The authenticity of the download links could not be verified at capture time
What affected people should do
Nigerians who used Remita should change passwords on linked accounts and enable two-factor authentication where available. Anyone who submitted KYC documents through Remita should monitor bank accounts and report suspicious activity, and watch for fraudulent loan or credit applications in their name.
Sources
- https://darkforums.ru/Thread-NG-Remita-Payments-Full-Data--71798