Kroll Sim swap leading to crypto firm data leakage

FTX, BlockFi and Genesis suffer Data Breach After Kroll’s SIM Swap Incident

2 Mins Read

PUREVPNNewsFTX, BlockFi and Genesis suffer Data Breach After Kroll’s SIM Swap Incident

Three cryptocurrency firms — FTX, BlockFi, and Genesis — encountered data breaches following a SIM-swapping assault directed at Kroll, a risk and financial advisory company.

What happened?

Kroll revealed in a recent statement that on August 19, it became aware of a highly sophisticated attack where a cybercriminal utilized SIM swapping to transfer control of an employee’s T-Mobile number to their own SIM card. 

Subsequently, the attacker used the compromised phone number to gain entry to systems containing the personal data of individuals making bankruptcy claims in the cases of FTX, BlockFi, and Genesis.

In response to this incident, Kroll promptly secured the affected accounts of its three clients and informed the impacted individuals via email. 

The company stressed that it’s collaborating with the FBI, and a comprehensive investigation is underway. Kroll affirmed that there’s no evidence of other systems or accounts being compromised.

Did we get any prompt from the Crypto firms?

FTX, in its communications to customers, disclosed that the intruder accessed files containing details such as names, addresses, email addresses, and FTX account balances. 

It clarified that Kroll does not store FTX account passwords, and the security of FTX systems and digital assets remains intact. 

Customers were cautioned to stay vigilant against fraudulent attempts masquerading as parties linked to the bankruptcy process.

Following the notifications by Kroll and the cryptocurrency firms, reports surfaced of FTX users receiving phishing emails falsely claiming eligibility for withdrawing funds from their FTX accounts.

Genesis also informed its customers that their personal information, including names, addresses, email addresses, and claims against Genesis debtors, had been compromised in the Kroll breach. The company alerted customers to the potential misuse of this information for phishing scams and other fraudulent activities.

BlockFi also released a statement, cautioning its customers about the likelihood of increased phishing efforts and unsolicited phone calls due to the incident.

Don’t think, act to be safe!

The aftermath of these data breaches and the SIM swapping attack is a reminder of the evolving threats. 

In response, businesses in the cryptocurrency sector must remain proactive in enhancing their security measures, such as multi-factor authentication and employee training, to fight such attacks. 

Also, collaborations between companies, advisory firms like Kroll, and law enforcement agencies are essential to detect, mitigate, and investigate such incidents promptly. 

author

Marrium Akhtar

date

August 29, 2023

time

8 months ago

Marrium is a dedicated digital Marketer and an SEO enthusiast who is skilled in cracking SEO codes. Other than work, she loves to stream, eat, and repeat.

Have Your Say!!

Join 3 million+ users to embrace internet freedom

Signup for PureVPN to get complete online security and privacy with a hidden IP address and encrypted internet traffic.