Jump to content
  • Hackers leak personal info allegedly stolen from 5.7M Gemini users

    alf9872000

    • 418 views
    • 3 minutes
     Share


    • 418 views
    • 3 minutes

    Gemini crypto exchange announced this week that customers were targeted in phishing campaigns after a threat actor collected their personal information from a third-party vendor.

     

    The notification comes after multiple posts on hacker forums seen by BleepingComputer offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.

    Funds and account data secure

    The Gemini product security team published a short notice that an unnamed third-party vendor suffered an "incident" that allowed an unauthorized actor to collect email addresses and incomplete phone numbers belonging to some Gemini customers.

     

    As a result of the breach, customers of the crypto exchange received phishing emails. The goal of the attacker has not been disclosed but such access to accounts and financial information is typically what threat actors are after.

     

    In its short report, Gemini underlines that account information and its systems have not been impacted and that funds and customer accounts "remain secure."

    Hackers advertise Gemini database

    The notification comes after multiple posts on a hacker forum offered to sell a database allegedly from Gemini containing phone numbers and email addresses of 5.7 million users.

     

    An early attempt to monetize the database was in September. The author did not mention how fresh the info was but asked for 30 bitcoins (about $520,000 at the current exchange rate).

     

    GeminiDB_30BTC.png

    Post on hacker forum asking for 30 bitcoins for Gemini database with 5.7 million emails
    source: KELA

     

    In October, another post was published from a different alias claiming that the data was from September.

     

    Yet another post under a different username (now banned on the forum) appeared in mid-November, offering databases from multiple crypto exchanges, including one from Gemini that supposedly had the same type of information for 5.7 million users.

     

    It appears that none of the attempts to monetize the database worked as yet another announcement appeared on a different forum offering the information for free.

     

    The author of the post shared the format of the phone numbers, specifying that the three digits in the middle are missing.

     

    GeminiDB_leak.jpg

    Post allegedly leaking Gemini database with 5.7 million emails and partial phone numbers
    source: BleepingComputer

     

    Gemini advises its customers to rely on strong authentication methods and recommends activating two-factor authentication (2FA) protection and/or the use of hardware security keys to access their accounts.

     

    The company also provides the steps necessary for changing the email address associated with the Gemini account.

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...