Fun

Fractal ID postmortem ties breach to 2022 password hack

News Feed - 2024-07-21 04:07:17

Amaka Nwaokocha1 hour agoFractal ID postmortem ties breach to 2022 password hackThis breach highlights the ongoing challenges in maintaining data security, especially in today’s centralized storage systems.505 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksBlockchain identity platform Fractal ID has published a postmortem outlining the data breach that the company suffered on July 14. The breach has since been traced back to a 2022 incident where an employee reused a compromised password.


According to Fractal ID, the compromised account belonged to an operator with the platform for three years and had admin rights. This allowed the attacker to bypass internal data privacy systems, though system monitoring helped lock out the attacker within 29 minutes.Root cause of the breach


The operator’s failure to follow operational security policies and training, along with the reuse of credentials from past hacks, facilitated the breach.


On July 14, 2024, the crypto identity verification provider detected unusual activity in one of its back offices. This activity was quickly identified as a malicious attack, leading to data exfiltration for approximately 0.5% of its user base.Source: Fractal ID


However, Fractal ID noted in the postmortem report that it disabled all accounts in the compromised system in response and limited access to senior employees. The company also prioritized enhancing its security measures to prevent future incidents, such as implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.


Related:New ‘overlay attacks’ are a growing threat to crypto users — security CEO


In addition to internal efforts, Fractal ID contacted the pertinent data protection authorities and the cybercrime police division in Berlin. The company has also engaged with cybersecurity services to monitor for any potential distribution of stolen data on known data breach sites.Data breach impact


According to the report, the stolen data, which affected around 6,300 users, includes various levels of information, from proof-of-personhood checks to complete KYC checks. This data may include names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID also contacted affected users directly to inform them of the breach.


Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident and emphasized their commitment to protecting user data. They reiterated the company’s goal of moving toward a self-custody storage system to enhance data security.


This security lapse serves as a stark reminder of the difficulties in safeguarding data. Autix10, a crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, in this instance, the attacker seemingly did not gain access to any customer data.


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Business# Security# Technology# Identity# Identification# HacksAdd reaction

News Feed

Savannah Fortis14 minutes agoMusic with AI elements can win a Grammy, Recording Academy CEO says in reportThe CEO of the Recording Academy, known for its yearly Grammy awards, reportedly clarified that music with AI-crea
Swiss Regulator Approves First Crypto Fund: Asset Manager Says ‘It’s an Exceptional Achievement’
Swiss Regulator Approves First Crypto Fund: Asset Manager Says "It"s an Exceptional Achievement" Switzerland’s Financial Market Supervisory Authority (FINMA) has approved th
Elisha Owusu Akyaw11 hours agoHashing It Out podcast: What does the future hold for BNB Chain?Arno Bauer, the senior solution architect at BNB Chain, denies the “Ethereum killer” tag in a discussion highlighting new
Bahamas Corrections Commissioner Says FTX Co-Founder Bankman-Fried Is in ‘Good Spirits’ in the Prison Sick Bay
Bahamas Corrections Commissioner Says FTX Co-Founder Bankman-Fried Is in "Good Spirits" in the Prison Sick Bay According to local reports, former FTX CEO Sam Bankman-Fried (SBF) is
Tom Mitchelhill3 hours agoCrypto lender Delio warns normal operations in jeopardy after asset seizuresThe South Korean crypto lender has had to halt certain interest payments after a recent investigation resulted in the
Gift to Pope Francis Sold as NFT Raises $80,000 for Afghanistan
Gift to Pope Francis Sold as NFT Raises $80,000 for Afghanistan A carpet presented by the United Arab Emirates as a gift to the head of the Catholic Church a few years ago has been
Ana Paula Pereira7 hours agoEther Futures ETFs could all get approval at same time: ReportAt least 16 applications for Ether or Bitcoin-Ether futures ETFs are awaiting regulatory approval in the United States.1943 Total
Bitcoin Taker Buy/Sell Ratio Spikes On Major Exchanges — Time To Buy?
Este artículo también está disponible en español. The price of Bitcoin has not shown any serious momentum so far in 2025 besides briefly surpassing the $108,000 level in
Dead protocol leaks crypto funds from hacked pool
Arijit Sarkar14 hours agoDead protocol leaks crypto funds from hacked poolApproximately $181,000 worth of crypto assets was drained from Yield Protocol’s strategic contracts present on the Arbitrum blockchain.1670 Tota
Bitcoin oversold after German gov’t sell-off — ARK Invest
Alex O’Donnell7 hours agoBitcoin oversold after German gov’t sell-off — ARK InvestBitcoin miners seem to be capitulating, a harbinger of a bullish reversal, according to ARK.5138 Total views4 Total sharesListen to
Bitcoin price ATH in memes: ‘Same same, but different’
Helen Partz7 hours agoBitcoin price ATH in memes: ‘Same same, but different’Explore a collection of Bitcoin memes marking its latest all-time high (ATH) of $70,199.2056 Total views6 Total sharesListen to article 0:00
While BTC’s Hashrate Remains High, It’s More Difficult Than Ever Before to Mine Bitcoin
While BTC"s Hashrate Remains High, It"s More Difficult Than Ever Before to Mine Bitcoin At the end of January 2021, Bitcoin’s network mining difficulty, a