Fun

Fractal ID postmortem ties breach to 2022 password hack

News Feed - 2024-07-21 04:07:17

Amaka Nwaokocha1 hour agoFractal ID postmortem ties breach to 2022 password hackThis breach highlights the ongoing challenges in maintaining data security, especially in today’s centralized storage systems.505 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksBlockchain identity platform Fractal ID has published a postmortem outlining the data breach that the company suffered on July 14. The breach has since been traced back to a 2022 incident where an employee reused a compromised password.


According to Fractal ID, the compromised account belonged to an operator with the platform for three years and had admin rights. This allowed the attacker to bypass internal data privacy systems, though system monitoring helped lock out the attacker within 29 minutes.Root cause of the breach


The operator’s failure to follow operational security policies and training, along with the reuse of credentials from past hacks, facilitated the breach.


On July 14, 2024, the crypto identity verification provider detected unusual activity in one of its back offices. This activity was quickly identified as a malicious attack, leading to data exfiltration for approximately 0.5% of its user base.Source: Fractal ID


However, Fractal ID noted in the postmortem report that it disabled all accounts in the compromised system in response and limited access to senior employees. The company also prioritized enhancing its security measures to prevent future incidents, such as implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.


Related:New ‘overlay attacks’ are a growing threat to crypto users — security CEO


In addition to internal efforts, Fractal ID contacted the pertinent data protection authorities and the cybercrime police division in Berlin. The company has also engaged with cybersecurity services to monitor for any potential distribution of stolen data on known data breach sites.Data breach impact


According to the report, the stolen data, which affected around 6,300 users, includes various levels of information, from proof-of-personhood checks to complete KYC checks. This data may include names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID also contacted affected users directly to inform them of the breach.


Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident and emphasized their commitment to protecting user data. They reiterated the company’s goal of moving toward a self-custody storage system to enhance data security.


This security lapse serves as a stark reminder of the difficulties in safeguarding data. Autix10, a crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, in this instance, the attacker seemingly did not gain access to any customer data.


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Business# Security# Technology# Identity# Identification# HacksAdd reaction

News Feed

Volt Inu is Ready to Launch VoltiEco the AI-Powered Ecosystem
Volt Inu is Ready to Launch VoltiEco the AI-Powered Ecosystem press release PRESS RELEASE.Volt Inuannounced on Twitteron April 18, 2023, that it would launch VoltiEco within the fol
Biggest Movers: UNI, BCH Surge by Over 20%, Hitting Multi-Month Highs
Biggest Movers: UNI, BCH Surge by Over 20%, Hitting Multi-Month Highs Uniswap was trading over 20% higher in Thursday’s session as the token rose to its highest point since
Video: Tesla Model 3 Bursts Into Flames TWICE After Autopilot Crash
TwitterFacebookLinkedInThis shocking video shows a Tesla Model 3 burst into flames - TWICE - after a Moscow crash. That won"t help Tesla"s "explosive" reputation. | Source: AP Photo / Jae C. Hong
Not Dogecoin But This Altcoin Is the Best Pick Post-Trump Win, Says Crypto CEO
Este artículo también está disponible en español. Andrew Kang, founder and CEO of Mechanism Capital, has shifted his bullish outlook from Dogecoin (DOGE) to First Neiro O
Bitcoin Mining Firm Cleanspark Purchases 10,000 Bitmain Miners for $28 Million
Bitcoin Mining Firm Cleanspark Purchases 10,000 Bitmain Miners for $28 Million The bitcoin mining company Cleanspark revealed on Wednesday that the company has signed a purchase ag
3AC wallet buys NFT with 3-year-old offer, zkSync denies insider minting claims: Nifty Newsletter
Ezra Reguerra5 hours ago3AC wallet buys NFT with 3-year-old offer, zkSync denies insider minting claims: Nifty NewsletterA wallet owned by the bankrupt hedge fund Three Arrows Capital purchased an NFT via a three-year-ol
Biggest Movers: MATIC, SOL Fall to Lowest Point Since January
Biggest Movers: MATIC, SOL Fall to Lowest Point Since January Polygon fell to its lowest point since January earlier in today’s session, as overall sentiment in crypto markets re
Chinese Government Launching National Blockchain Innovation Center
Chinese Government Launching National Blockchain Innovation Center The Chinese government is setting up a national blockchain innovation center in Beijing to focus on industrial ap
Tristan Greene12 hours agoXRP bucks trend as crypto assets experience 4th straight week of outflowsSolana slid into the outflow column this week as Bitcoin’s outflows streak continued.4138 Total views32 Total sharesLis
UwU Lend hit by $20M crypto hack
Zoltan Vardai11 hours agoUwU Lend hit by $20M crypto hackThe ongoing exploit has already netted the attacker nearly $20 million in digital assets.2228 Total views16 Total sharesListen to article 0:00NewsOwn this piece of
Bitcoin Hashrate Down 45% – Miners Witness Second-Largest Difficulty Drop in History
Bitcoin Hashrate Down 45% - Miners Witness Second-Largest Difficulty Drop in History Bitcoin’s hashrate has plummeted 45% since the record-breaking levels it saw on Feb. 29
Spencer Dinwiddie Could Decentralize Pro Sports – If Accredited Investors Want In
Accredited investors can soon indulge their hoop dreams. In partnership with crypto firm Paxos, NBA guard Spencer Dinwiddie is looking to raise $13.5 million by tokenizing the first