|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
區塊鏈身分平台 Fractal ID 於 2024 年 7 月 14 日披露了一起重大資料外洩事件。

A significant data breach at blockchain identity platform Fractal ID has been traced back to a 2022 incident where an employee reused a compromised password, leading to the theft of user data, the company announced on July 14, 2024.
該公司於 2024 年 7 月 14 日宣布,區塊鏈身分平台 Fractal ID 發生的重大資料外洩事件可以追溯到 2022 年的一起事件,當時一名員工重複使用了洩漏的密碼,導致用戶資料被盜。
The compromised account belonged to a long-time operator with admin rights, which allowed the attacker to bypass internal data privacy systems. However, system monitoring helped lock out the attacker within 29 minutes.
受損帳戶屬於具有管理員權限的長期操作員,這使得攻擊者能夠繞過內部資料隱私系統。然而,系統監控在 29 分鐘內幫助鎖定了攻擊者。
“The attacker was able to gain access to a back office system, which contained a database of our users,” Fractal ID stated in a postmortem report.
Fractal ID 在事後報告中表示:“攻擊者能夠訪問後台系統,其中包含我們用戶的資料庫。”
The company added that the attacker did not gain access to any critical systems or the main user database, and all user funds and crypto assets remained safe.
該公司補充說,攻擊者沒有訪問任何關鍵系統或主要用戶資料庫,所有用戶資金和加密資產仍然安全。
The stolen data included proof-of-personhood checks, complete KYC checks, names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted the affected users to inform them of the breach.
被盜資料包括身分證明檢查、完整的 KYC 檢查、姓名、電子郵件地址、電話號碼、錢包地址、實際地址和上傳文件的圖像。 Fractal ID 已直接聯繫受影響的用戶,告知他們此次違規事件。
“We deeply regret this incident and are committed to protecting our users’ data. We will continue to work closely with the authorities and take all necessary steps to ensure the safety and security of our users,” the company stated.
「我們對這一事件深感遺憾,並致力於保護我們用戶的資料。我們將繼續與當局密切合作,並採取一切必要措施確保用戶的安全。
The incident highlights the importance of following operational security policies and training, as the reuse of credentials from past hacks can lead to devastating consequences. Fractal ID’s failure to adhere to these policies allowed the attacker to exploit the company’s vulnerabilities.
該事件凸顯了遵循操作安全政策和培訓的重要性,因為重複使用過去駭客攻擊的憑證可能會導致災難性後果。 Fractal ID 未能遵守這些政策,導致攻擊者可以利用該公司的漏洞。
Fractal ID Takes Action After Data Breach, Enhances Security
Fractal ID 在資料外洩後採取行動,增強安全性
Upon detecting unusual activity in its back office, Fractal ID quickly identified it as a malicious attack. This led to data exfiltration affecting approximately 0.5% of its user base. In response, the company disabled all accounts in the compromised system and limited access to senior employees.
在偵測到背景的異常活動後,Fractal ID 很快就將其識別為惡意攻擊。這導致資料外洩影響了大約 0.5% 的用戶群。作為回應,該公司禁用了受感染系統中的所有帳戶,並限制了高級員工的存取權限。
Fractal ID’s postmortem report highlighted several measures to prevent future incidents. These include implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.
Fractal ID 的事後分析報告強調了預防未來事件發生的多項措施。其中包括實施請求限制、更細粒度的授權、對失敗的身份驗證嘗試進行更嚴格的監控以及更嚴格的 IP 控制。
The company also contacted the pertinent data protection authorities and the cybercrime police division in Berlin.
該公司也聯繫了相關資料保護機構和柏林網路犯罪警察部門。
Fractal ID Breach Exposes User Data, Affects 6,300 Users
Fractal ID 洩漏導致用戶資料洩露,影響 6,300 名用戶
The breach impacted around 6,300 users, with stolen data ranging from proof-of-personhood checks to complete KYC checks. This includes names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted affected users to inform them of the breach.
此次洩漏影響了約 6,300 名用戶,被盜資料範圍從身分證明檢查到完整的 KYC 檢查。這包括姓名、電子郵件地址、電話號碼、錢包地址、實際地址和上傳文件的圖像。 Fractal ID 已直接聯繫受影響的用戶,告知他們此次洩漏事件。
Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident. They emphasized their commitment to protecting user data and moving toward a self-custody storage system for enhanced security.
Fractal ID 共同創辦人 Julian、Julio、Lluis 和 Anna 對此事件表示遺憾。他們強調了對保護用戶資料並轉向自我託管儲存系統以增強安全性的承諾。
“We are deeply sorry for the inconvenience and distress this may have caused. We are committed to learning from this incident and making our platform even more secure,” the co-founders said in a joint statement.
「對於由此造成的不便和困擾,我們深表歉意。我們致力於從這次事件中吸取教訓,使我們的平台更加安全。
Autix10, another crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, the attacker in that case did not gain access to any customer data.
另一家加密 ID 提供商 Autix10 於 6 月 27 日透露,他們的線上管理登入詳細資訊被洩露。然而,在這種情況下,攻擊者無法存取任何客戶資料。
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
- 比特幣、eCash 分叉和空投動態:深入探討加密貨幣的最新爭議
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作為高風險空投的分類,以及對比特幣和加密生態系統的更廣泛影響。
-
-
- 聯準會維持利率穩定,地緣政治緊張局勢引發比特幣價格下跌
- 2026-05-01 04:04:38
- 聯準會維持利率的決定,加上中東衝突,影響了比特幣的價格。分析近期趨勢和市場反應。
-
-
-
-
-
-

































