|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
블록체인 ID 플랫폼 Fractal ID는 2024년 7월 14일에 심각한 데이터 유출을 폭로했습니다. 처음에는 직원이 유출된 비밀번호를 재사용한 2022년 사건으로 유출이 추적되었습니다.

A significant data breach at blockchain identity platform Fractal ID has been traced back to a 2022 incident where an employee reused a compromised password, leading to the theft of user data, the company announced on July 14, 2024.
블록체인 ID 플랫폼인 Fractal ID에서 발생한 심각한 데이터 침해는 직원이 유출된 비밀번호를 재사용하여 사용자 데이터를 도난당했던 2022년 사건으로 거슬러 올라간다고 회사는 2024년 7월 14일에 발표했습니다.
The compromised account belonged to a long-time operator with admin rights, which allowed the attacker to bypass internal data privacy systems. However, system monitoring helped lock out the attacker within 29 minutes.
손상된 계정은 관리자 권한을 가진 오랜 운영자의 소유였으며, 이로 인해 공격자는 내부 데이터 개인 정보 보호 시스템을 우회할 수 있었습니다. 그러나 시스템 모니터링을 통해 29분 이내에 공격자를 차단할 수 있었습니다.
“The attacker was able to gain access to a back office system, which contained a database of our users,” Fractal ID stated in a postmortem report.
Fractal ID는 사후 보고서에서 “공격자는 우리 사용자 데이터베이스가 포함된 백오피스 시스템에 액세스할 수 있었습니다.”라고 밝혔습니다.
The company added that the attacker did not gain access to any critical systems or the main user database, and all user funds and crypto assets remained safe.
회사는 공격자가 중요한 시스템이나 주요 사용자 데이터베이스에 접근할 수 없었으며 모든 사용자 자금과 암호화폐 자산은 안전하게 유지되었다고 덧붙였습니다.
The stolen data included proof-of-personhood checks, complete KYC checks, names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted the affected users to inform them of the breach.
도난당한 데이터에는 신원 증명 확인, 전체 KYC 확인, 이름, 이메일 주소, 전화번호, 지갑 주소, 실제 주소, 업로드된 문서 이미지가 포함되었습니다. Fractal ID는 영향을 받은 사용자에게 직접 연락하여 위반 사실을 알렸습니다.
“We deeply regret this incident and are committed to protecting our users’ data. We will continue to work closely with the authorities and take all necessary steps to ensure the safety and security of our users,” the company stated.
“우리는 이번 사건을 깊이 후회하며 사용자 데이터를 보호하기 위해 최선을 다하고 있습니다. 앞으로도 당국과 긴밀히 협력해 사용자의 안전과 보안을 보장하기 위해 필요한 모든 조치를 취할 것”이라고 밝혔다.
The incident highlights the importance of following operational security policies and training, as the reuse of credentials from past hacks can lead to devastating consequences. Fractal ID’s failure to adhere to these policies allowed the attacker to exploit the company’s vulnerabilities.
이 사건은 과거 해킹의 자격 증명을 재사용하면 치명적인 결과를 초래할 수 있으므로 운영 보안 정책 및 교육을 따르는 것이 중요하다는 점을 강조합니다. Fractal ID가 이러한 정책을 준수하지 못하여 공격자는 회사의 취약점을 악용할 수 있었습니다.
Fractal ID Takes Action After Data Breach, Enhances Security
Fractal ID는 데이터 침해 후 조치를 취하고 보안을 강화합니다.
Upon detecting unusual activity in its back office, Fractal ID quickly identified it as a malicious attack. This led to data exfiltration affecting approximately 0.5% of its user base. In response, the company disabled all accounts in the compromised system and limited access to senior employees.
백오피스에서 비정상적인 활동을 감지한 Fractal ID는 이를 악성 공격으로 신속하게 식별했습니다. 이로 인해 사용자 기반의 약 0.5%에 영향을 미치는 데이터 유출이 발생했습니다. 이에 대응하여 회사는 손상된 시스템의 모든 계정을 비활성화하고 고위 직원의 액세스를 제한했습니다.
Fractal ID’s postmortem report highlighted several measures to prevent future incidents. These include implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.
Fractal ID의 사후 보고서에서는 향후 사고를 예방하기 위한 몇 가지 조치를 강조했습니다. 여기에는 요청 제한 구현, 보다 세분화된 권한 부여, 실패한 인증 시도에 대한 보다 엄격한 모니터링, 보다 엄격한 IP 제어가 포함됩니다.
The company also contacted the pertinent data protection authorities and the cybercrime police division in Berlin.
회사는 또한 관련 데이터 보호 당국과 베를린의 사이버 범죄 경찰 부서에 연락했습니다.
Fractal ID Breach Exposes User Data, Affects 6,300 Users
프랙탈 ID 위반으로 사용자 데이터가 노출되어 6,300명의 사용자에게 영향을 미침
The breach impacted around 6,300 users, with stolen data ranging from proof-of-personhood checks to complete KYC checks. This includes names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted affected users to inform them of the breach.
이 침해 사고는 약 6,300명의 사용자에게 영향을 미쳤으며 신원 증명 확인부터 완전한 KYC 확인까지 다양한 데이터가 도난당했습니다. 여기에는 이름, 이메일 주소, 전화번호, 지갑 주소, 실제 주소, 업로드된 문서 이미지가 포함됩니다. Fractal ID는 영향을 받은 사용자에게 직접 연락하여 위반 사실을 알렸습니다.
Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident. They emphasized their commitment to protecting user data and moving toward a self-custody storage system for enhanced security.
Fractal ID의 공동 창업자인 Julian, Julio, Lluis 및 Anna는 이번 사건에 대해 유감을 표시했습니다. 그들은 사용자 데이터를 보호하고 보안 강화를 위해 자체 관리형 스토리지 시스템으로 전환하려는 노력을 강조했습니다.
“We are deeply sorry for the inconvenience and distress this may have caused. We are committed to learning from this incident and making our platform even more secure,” the co-founders said in a joint statement.
“이로 인해 불편과 고통을 겪게 되어 진심으로 사과드립니다. 우리는 이번 사건으로부터 교훈을 얻고 플랫폼을 더욱 안전하게 만들기 위해 최선을 다하고 있습니다.”라고 공동 창립자들은 공동 성명에서 말했습니다.
Autix10, another crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, the attacker in that case did not gain access to any customer data.
또 다른 암호화폐 ID 제공업체인 Autix10은 6월 27일 온라인 관리 로그인 세부 정보가 노출되었다고 밝혔습니다. 그러나 이 경우 공격자는 고객 데이터에 대한 액세스 권한을 얻지 못했습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































