Market Cap: $2.2274T 1.22%
Volume(24h): $43.1719B 13.79%
  • Market Cap: $2.2274T 1.22%
  • Volume(24h): $43.1719B 13.79%
  • Fear & Greed Index:
  • Market Cap: $2.2274T 1.22%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

Fractal ID Data Breach Affects 6,300 Users, Exposes KYC Checks

Jul 23, 2024 at 12:18 am

Blockchain identity platform Fractal ID revealed a significant data breach on July 14, 2024. Initially, the breach was traced back to a 2022 incident where an employee reused a compromised password.

Fractal ID Data Breach Affects 6,300 Users, Exposes KYC Checks

A significant data breach at blockchain identity platform Fractal ID has been traced back to a 2022 incident where an employee reused a compromised password, leading to the theft of user data, the company announced on July 14, 2024.

The compromised account belonged to a long-time operator with admin rights, which allowed the attacker to bypass internal data privacy systems. However, system monitoring helped lock out the attacker within 29 minutes.

“The attacker was able to gain access to a back office system, which contained a database of our users,” Fractal ID stated in a postmortem report.

The company added that the attacker did not gain access to any critical systems or the main user database, and all user funds and crypto assets remained safe.

The stolen data included proof-of-personhood checks, complete KYC checks, names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted the affected users to inform them of the breach.

“We deeply regret this incident and are committed to protecting our users’ data. We will continue to work closely with the authorities and take all necessary steps to ensure the safety and security of our users,” the company stated.

The incident highlights the importance of following operational security policies and training, as the reuse of credentials from past hacks can lead to devastating consequences. Fractal ID’s failure to adhere to these policies allowed the attacker to exploit the company’s vulnerabilities.

Fractal ID Takes Action After Data Breach, Enhances Security

Upon detecting unusual activity in its back office, Fractal ID quickly identified it as a malicious attack. This led to data exfiltration affecting approximately 0.5% of its user base. In response, the company disabled all accounts in the compromised system and limited access to senior employees.

Fractal ID’s postmortem report highlighted several measures to prevent future incidents. These include implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.

The company also contacted the pertinent data protection authorities and the cybercrime police division in Berlin.

Fractal ID Breach Exposes User Data, Affects 6,300 Users

The breach impacted around 6,300 users, with stolen data ranging from proof-of-personhood checks to complete KYC checks. This includes names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted affected users to inform them of the breach.

Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident. They emphasized their commitment to protecting user data and moving toward a self-custody storage system for enhanced security.

“We are deeply sorry for the inconvenience and distress this may have caused. We are committed to learning from this incident and making our platform even more secure,” the co-founders said in a joint statement.

Autix10, another crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, the attacker in that case did not gain access to any customer data.

Original source:coinchapter

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Jul 28, 2026