市值: $2.2269T 1.08%
成交额(24h): $51.7314B 36.39%
  • 市值: $2.2269T 1.08%
  • 成交额(24h): $51.7314B 36.39%
  • 恐惧与贪婪指数:
  • 市值: $2.2269T 1.08%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密货币新闻

Fractal ID 数据泄露影响 6,300 名用户,暴露 KYC 检查

2024/07/23 00:18

区块链身份平台 Fractal ID 于 2024 年 7 月 14 日披露了一起重大数据泄露事件。最初,该泄露事件可追溯到 2022 年的一起事件,当时一名员工重复使用了泄露的密码。

Fractal ID 数据泄露影响 6,300 名用户,暴露 KYC 检查

A significant data breach at blockchain identity platform Fractal ID has been traced back to a 2022 incident where an employee reused a compromised password, leading to the theft of user data, the company announced on July 14, 2024.

该公司于 2024 年 7 月 14 日宣布,区块链身份平台 Fractal ID 发生的重大数据泄露事件可以追溯到 2022 年的一起事件,当时一名员工重复使用了泄露的密码,导致用户数据被盗。

The compromised account belonged to a long-time operator with admin rights, which allowed the attacker to bypass internal data privacy systems. However, system monitoring helped lock out the attacker within 29 minutes.

受损帐户属于具有管理员权限的长期操作员,这使得攻击者能够绕过内部数据隐私系统。然而,系统监控在 29 分钟内帮助锁定了攻击者。

“The attacker was able to gain access to a back office system, which contained a database of our users,” Fractal ID stated in a postmortem report.

Fractal ID 在事后报告中表示:“攻击者能够访问后台系统,其中包含我们用户的数据库。”

The company added that the attacker did not gain access to any critical systems or the main user database, and all user funds and crypto assets remained safe.

该公司补充说,攻击者没有访问任何关键系统或主要用户数据库,所有用户资金和加密资产仍然安全。

The stolen data included proof-of-personhood checks, complete KYC checks, names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted the affected users to inform them of the breach.

被盗数据包括身份证明检查、完整的 KYC 检查、姓名、电子邮件地址、电话号码、钱包地址、实际地址和上传文档的图像。 Fractal ID 已直接联系受影响的用户,告知他们此次违规事件。

“We deeply regret this incident and are committed to protecting our users’ data. We will continue to work closely with the authorities and take all necessary steps to ensure the safety and security of our users,” the company stated.

“我们对这一事件深感遗憾,并致力于保护我们用户的数据。我们将继续与当局密切合作,并采取一切必要措施确保用户的安全。”

The incident highlights the importance of following operational security policies and training, as the reuse of credentials from past hacks can lead to devastating consequences. Fractal ID’s failure to adhere to these policies allowed the attacker to exploit the company’s vulnerabilities.

该事件凸显了遵循操作安全政策和培训的重要性,因为重复使用过去黑客攻击的凭据可能会导致灾难性后果。 Fractal ID 未能遵守这些政策,导致攻击者可以利用该公司的漏洞。

Fractal ID Takes Action After Data Breach, Enhances Security

Fractal ID 在数据泄露后采取行动,增强安全性

Upon detecting unusual activity in its back office, Fractal ID quickly identified it as a malicious attack. This led to data exfiltration affecting approximately 0.5% of its user base. In response, the company disabled all accounts in the compromised system and limited access to senior employees.

在检测到后台的异常活动后,Fractal ID 很快将其识别为恶意攻击。这导致数据泄露影响了大约 0.5% 的用户群。作为回应,该公司禁用了受感染系统中的所有帐户,并限制了高级员工的访问权限。

Fractal ID’s postmortem report highlighted several measures to prevent future incidents. These include implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.

Fractal ID 的事后分析报告强调了预防未来事件发生的多项措施。其中包括实施请求限制、更细粒度的授权、对失败的身份验证尝试进行更严格的监控以及更严格的 IP 控制。

The company also contacted the pertinent data protection authorities and the cybercrime police division in Berlin.

该公司还联系了相关数据保护机构和柏林网络犯罪警察部门。

Fractal ID Breach Exposes User Data, Affects 6,300 Users

Fractal ID 泄露导致用户数据泄露,影响 6,300 名用户

The breach impacted around 6,300 users, with stolen data ranging from proof-of-personhood checks to complete KYC checks. This includes names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID has directly contacted affected users to inform them of the breach.

此次泄露影响了约 6,300 名用户,被盗数据范围从身份证明检查到完整的 KYC 检查。这包括姓名、电子邮件地址、电话号码、钱包地址、实际地址和上传文档的图像。 Fractal ID 已直接联系受影响的用户,告知他们此次泄露事件。

Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident. They emphasized their commitment to protecting user data and moving toward a self-custody storage system for enhanced security.

Fractal ID 联合创始人 Julian、Julio、Lluis 和 Anna 对这一事件表示遗憾。他们强调了对保护用户数据并转向自我托管存储系统以增强安全性的承诺。

“We are deeply sorry for the inconvenience and distress this may have caused. We are committed to learning from this incident and making our platform even more secure,” the co-founders said in a joint statement.

“对于由此造成的不便和困扰,我们深表歉意。我们致力于从这次事件中吸取教训,使我们的平台更加安全。”联合创始人在一份联合声明中表示。

Autix10, another crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, the attacker in that case did not gain access to any customer data.

另一家加密 ID 提供商 Autix10 于 6 月 27 日透露,他们的在线管理登录详细信息被泄露。然而,在这种情况下,攻击者无法访问任何客户数据。

原文来源:coinchapter

免责声明:info@kdj.com

所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!

如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。

2026年07月28日 发表的其他文章