時価総額: $2.2391T 1.66%
ボリューム(24時間): $47.003B 22.54%
  • 時価総額: $2.2391T 1.66%
  • ボリューム(24時間): $47.003B 22.54%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2391T 1.66%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

Fractal ID のデータ侵害で 6,300 人のユーザーが影響、KYC チェックが暴露

2024/07/23 00:18

ブロックチェーン ID プラットフォーム Fractal ID は、2024 年 7 月 14 日に重大なデータ侵害を明らかにしました。当初、侵害は従業員が侵害されたパスワードを再利用した 2022 年のインシデントまで遡りました。

Fractal ID のデータ侵害で 6,300 人のユーザーが影響、KYC チェックが暴露

A significant data breach at blockchain identity platform Fractal ID has been traced back to a 2022 incident where an employee reused a compromised password, leading to the theft of user data, the company announced on July 14, 2024.

ブロックチェーン ID プラットフォーム Fractal ID における重大なデータ侵害は、従業員が侵害されたパスワードを再利用し、ユーザー データの盗難につながった 2022 年のインシデントにまで遡ることが、同社は 2024 年 7 月 14 日に発表しました。

The compromised account belonged to a long-time operator with admin rights, which allowed the attacker to bypass internal data privacy systems. However, system monitoring helped lock out the attacker within 29 minutes.

侵害されたアカウントは管理者権限を持つ長年のオペレーターのものであったため、攻撃者は内部のデータ プライバシー システムをバイパスすることができました。しかし、システム監視により、攻撃者は 29 分以内にロックアウトされました。

“The attacker was able to gain access to a back office system, which contained a database of our users,” Fractal ID stated in a postmortem report.

「攻撃者は、当社のユーザーのデータベースが含まれるバックオフィス システムにアクセスすることができました」と Fractal ID は事後報告書で述べています。

The company added that the attacker did not gain access to any critical systems or the main user database, and all user funds and crypto assets remained safe.

同社は、攻撃者は重要なシステムや主要なユーザーデータベースにはアクセスできず、すべてのユーザーの資金と暗号資産は安全に保たれたと付け加えた。

The stolen data included proof-of-personhood checks, complete KYC checks, names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted the affected users to inform them of the breach.

盗まれたデータには、本人確認チェック、完全な KYC チェック、名前、電子メール アドレス、電話番号、ウォレット アドレス、物理的住所、アップロードされた文書の画像が含まれていました。 Fractal ID は影響を受けたユーザーに直接連絡し、侵害について通知しました。

“We deeply regret this incident and are committed to protecting our users’ data. We will continue to work closely with the authorities and take all necessary steps to ensure the safety and security of our users,” the company stated.

「私たちはこの事件を深く遺憾に思っており、ユーザーのデータの保護に全力で取り組んでいます。当社は今後も当局と緊密に連携し、ユーザーの安全と安心を確保するために必要なあらゆる措置を講じてまいります」と同社は述べた。

The incident highlights the importance of following operational security policies and training, as the reuse of credentials from past hacks can lead to devastating consequences. Fractal ID’s failure to adhere to these policies allowed the attacker to exploit the company’s vulnerabilities.

このインシデントは、過去のハッキングによる認証情報の再利用が壊滅的な結果を招く可能性があるため、運用上のセキュリティ ポリシーとトレーニングに従うことの重要性を浮き彫りにしました。 Fractal ID がこれらのポリシーに従わなかったため、攻撃者が同社の脆弱性を悪用する可能性がありました。

Fractal ID Takes Action After Data Breach, Enhances Security

Fractal ID はデータ侵害後に対処し、セキュリティを強化します

Upon detecting unusual activity in its back office, Fractal ID quickly identified it as a malicious attack. This led to data exfiltration affecting approximately 0.5% of its user base. In response, the company disabled all accounts in the compromised system and limited access to senior employees.

Fractal ID は、バック オフィスで異常なアクティビティを検出すると、すぐにそれを悪意のある攻撃であると特定しました。これにより、データの漏洩が発生し、ユーザー ベースの約 0.5% が影響を受けました。これに応じて、同社は侵害されたシステム内のすべてのアカウントを無効にし、上級従業員へのアクセスを制限しました。

Fractal ID’s postmortem report highlighted several measures to prevent future incidents. These include implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.

Fractal ID の事後レポートでは、将来のインシデントを防ぐためのいくつかの対策が強調されています。これには、リクエストのスロットルの実装、よりきめ細かい認可、失敗した認証試行のより厳密な監視、およびより厳格な IP 制御が含まれます。

The company also contacted the pertinent data protection authorities and the cybercrime police division in Berlin.

同社はまた、関連するデータ保護当局とベルリンのサイバー犯罪警察部門にも連絡した。

Fractal ID Breach Exposes User Data, Affects 6,300 Users

Fractal ID侵害でユーザーデータが流出、6,300ユーザーに影響

The breach impacted around 6,300 users, with stolen data ranging from proof-of-personhood checks to complete KYC checks. This includes names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted affected users to inform them of the breach.

この侵害は約 6,300 人のユーザーに影響を及ぼし、盗まれたデータは本人確認の確認から完全な KYC チェックに至るまで多岐にわたりました。これには、名前、電子メール アドレス、電話番号、ウォレット アドレス、物理的な住所、アップロードされたドキュメントの画像が含まれます。 Fractal ID は影響を受けたユーザーに直接連絡し、侵害について通知しました。

Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident. They emphasized their commitment to protecting user data and moving toward a self-custody storage system for enhanced security.

Fractal ID の共同創設者である Julian、Julio、Lluis、Anna は、この事件について遺憾の意を表明しました。彼らは、ユーザーデータの保護とセキュリティ強化のための自己保管ストレージシステムへの移行への取り組みを強調しました。

“We are deeply sorry for the inconvenience and distress this may have caused. We are committed to learning from this incident and making our platform even more secure,” the co-founders said in a joint statement.

「この件によりご迷惑とご迷惑をおかけしたことを深くお詫び申し上げます。私たちはこの事件から学び、プラットフォームをさらに安全にすることに全力で取り組んでいます」と共同創設者は共同声明で述べた。

Autix10, another crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, the attacker in that case did not gain access to any customer data.

別の暗号化 ID プロバイダーである Autix10 は 6 月 27 日、オンライン管理ログインの詳細が漏洩したことを明らかにしました。ただし、この場合、攻撃者は顧客データにアクセスすることはできませんでした。

オリジナルソース:coinchapter

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年07月28日 に掲載されたその他の記事