Israeli cryptocurrency broker Bits of Gold has disclosed a major data breach that potentially exposed personal and financial information belonging to approximately 200,000 customers. The incident involved unauthorized access to a system used for support analysis, while the company’s cryptocurrency holdings and customer funds were not affected.

 

 

Bits of Gold said it detected unauthorized access and began investigating the incident with assistance from an external cybersecurity company. The investigation remains ongoing, but preliminary findings indicate that the attacker likely succeeded in extracting customer information from the affected system.

The potentially compromised records include names, email addresses, telephone numbers and identification numbers. IP addresses, bank account information and customers’ public cryptocurrency wallet addresses may also have been exposed.

However, several particularly sensitive categories of information were not involved. Bits of Gold said customer account passwords and photographs of identification documents were not disclosed. The company also does not hold customers’ cryptocurrency private keys, complete credit card numbers, or CVV security codes, meaning this information could not have been obtained from the compromised system.

Most importantly, the breach did not involve customers’ cryptocurrency holdings or other funds. Bits of Gold said its digital asset infrastructure was unaffected by the security incident.

The company has also said that it has found no indication so far that the exposed information has been used to conduct fraudulent transactions. Nevertheless, the combination of contact, identification, banking and cryptocurrency-related information could make affected customers attractive targets for convincing phishing and impersonation attempts.

Bits of Gold is consequently advising customers to treat unexpected communications claiming to originate from the company with caution. It stressed that legitimate representatives will not request passwords, verification codes or cryptocurrency private keys. Customers will also not be instructed to transfer money or digital assets to another cryptocurrency wallet as part of a security procedure.

The company described the breach as part of a broader cyberattack that affected other organizations internationally, although it has not publicly identified the attacker responsible for accessing its support analysis system.

The incident comes during a period in which several cryptocurrency-related companies have disclosed breaches affecting customer information. Hardware wallet provider SafePal recently notified 39,798 customers after a vulnerability involving an order-tracking plugin exposed customer information. Separately, Trezor disclosed an incident affecting nearly 14,000 customers after unauthorized access occurred at fulfillment partner ShipMonk.

Those incidents are separate from the Bits of Gold breach and involved different systems and circumstances. In the Bits of Gold case, the currently confirmed investigation centers specifically on unauthorized access to its support analysis environment.

The precise scope of the stolen information is still being established. For now, Bits of Gold says approximately 200,000 customers may be affected, while account passwords, ID photographs, complete card information, CVV codes, private keys, and customer digital assets were not compromised.

Leave a Reply