Fun

Fractal ID postmortem ties breach to 2022 password hack

News Feed - 2024-07-21 04:07:17

Amaka Nwaokocha1 hour agoFractal ID postmortem ties breach to 2022 password hackThis breach highlights the ongoing challenges in maintaining data security, especially in today’s centralized storage systems.505 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksBlockchain identity platform Fractal ID has published a postmortem outlining the data breach that the company suffered on July 14. The breach has since been traced back to a 2022 incident where an employee reused a compromised password.


According to Fractal ID, the compromised account belonged to an operator with the platform for three years and had admin rights. This allowed the attacker to bypass internal data privacy systems, though system monitoring helped lock out the attacker within 29 minutes.Root cause of the breach


The operator’s failure to follow operational security policies and training, along with the reuse of credentials from past hacks, facilitated the breach.


On July 14, 2024, the crypto identity verification provider detected unusual activity in one of its back offices. This activity was quickly identified as a malicious attack, leading to data exfiltration for approximately 0.5% of its user base.Source: Fractal ID


However, Fractal ID noted in the postmortem report that it disabled all accounts in the compromised system in response and limited access to senior employees. The company also prioritized enhancing its security measures to prevent future incidents, such as implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.


Related:New ‘overlay attacks’ are a growing threat to crypto users — security CEO


In addition to internal efforts, Fractal ID contacted the pertinent data protection authorities and the cybercrime police division in Berlin. The company has also engaged with cybersecurity services to monitor for any potential distribution of stolen data on known data breach sites.Data breach impact


According to the report, the stolen data, which affected around 6,300 users, includes various levels of information, from proof-of-personhood checks to complete KYC checks. This data may include names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID also contacted affected users directly to inform them of the breach.


Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident and emphasized their commitment to protecting user data. They reiterated the company’s goal of moving toward a self-custody storage system to enhance data security.


This security lapse serves as a stark reminder of the difficulties in safeguarding data. Autix10, a crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, in this instance, the attacker seemingly did not gain access to any customer data.


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Business# Security# Technology# Identity# Identification# HacksAdd reaction

News Feed

Solana Is Not Dead? This Upper Boundary Retest Could Set The Stage For $268
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
US Bitcoin miner Giga Energy to launch facility in Argentina
Brayden Lindrea4 hours agoUS Bitcoin miner Giga Energy to launch facility in ArgentinaGiga"s new site harnesses otherwise wasted energy from natural gas flaring and has already mined between $200,000 and $250,000 worth o
Zhiyuan Sun8 hours agoNear Foundation treasury drops to $900M as token price plungesThe $200 million decline was mostly due to a drop in the price of Near tokens, in line with the crypto bear market.2553 Total viewsListe
Study Identifies the Top 10 States in America Most Interested in Bitcoin, Ethereum
Study Identifies the Top 10 States in America Most Interested in Bitcoin, Ethereum On September 2, the crypto market aggregation web portal Coingecko.com published a study that ide
Making Bitcoin Go Viral: Could Endless Printing Trigger a Hyperbitcoinization Event?
Making Bitcoin Go Viral: Could Endless Printing Trigger a Hyperbitcoinization Event? Hyperbitcoinization has been defined as “a state where bitcoin becomes the world’
Blockchain Association and crypto activist group sue SEC over ‘Dealer Rule’
Savannah Fortis9 hours agoBlockchain Association and crypto activist group sue SEC over ‘Dealer Rule’The Blockchain Association and a Texas-based crypto activist group are suing the SEC over its controversial “Deal
Hackers Donate Bitcoin From Ransomware Attacks to Charities
Hackers Donate Bitcoin From Ransomware Attacks to Charities A group of hackers has donated some of the bitcoin it extorted via ransomware attacks to charities, c
BONK, POPCAT and Solana memecoins stay green even as Bitcoin price drops
Nancy Lubale2 hours agoBONK, POPCAT and Solana memecoins stay green even as Bitcoin price dropsMemecoins in the Solana ecosystem defy the recent bearish downtrend in the crypto market by managing to generate double-digit
Up to 30% of Bitcoin Miners Close Shop as Business Turns Unprofitable After Halving
Up to 30% of Bitcoin Miners Close Shop as Business Turns Unprofitable After HalvingAbout a third of Bitcoin (BTC) mining firms may already be switching off their machines as the bus
Brian Quarmby1 hour agoNifty News: NFT restaurant crumbles, Binance NFT ends Polygon support and moreThe restaurant was being built alongside a private members lounge that was only open to people who bought NFTs, but ris
Goldman Sachs Sees Bitcoin Market Becoming More Mature
Goldman Sachs Sees Bitcoin Market Becoming More Mature Goldman Sachs’ global head of commodities research sees the bitcoin market becoming more mature. &ld
US Financial Regulators Join UK FCA’s ‘Global Sandbox’
Four U.S. regulators joined the Global Financial Innovation Network, an international alliance of government regulators led by the UK’s Financial Conduct Authority seeking to bolster the future of fintech.