Fun

Fractal ID postmortem ties breach to 2022 password hack

News Feed - 2024-07-21 04:07:17

Amaka Nwaokocha1 hour agoFractal ID postmortem ties breach to 2022 password hackThis breach highlights the ongoing challenges in maintaining data security, especially in today’s centralized storage systems.505 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksBlockchain identity platform Fractal ID has published a postmortem outlining the data breach that the company suffered on July 14. The breach has since been traced back to a 2022 incident where an employee reused a compromised password.


According to Fractal ID, the compromised account belonged to an operator with the platform for three years and had admin rights. This allowed the attacker to bypass internal data privacy systems, though system monitoring helped lock out the attacker within 29 minutes.Root cause of the breach


The operator’s failure to follow operational security policies and training, along with the reuse of credentials from past hacks, facilitated the breach.


On July 14, 2024, the crypto identity verification provider detected unusual activity in one of its back offices. This activity was quickly identified as a malicious attack, leading to data exfiltration for approximately 0.5% of its user base.Source: Fractal ID


However, Fractal ID noted in the postmortem report that it disabled all accounts in the compromised system in response and limited access to senior employees. The company also prioritized enhancing its security measures to prevent future incidents, such as implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.


Related:New ‘overlay attacks’ are a growing threat to crypto users — security CEO


In addition to internal efforts, Fractal ID contacted the pertinent data protection authorities and the cybercrime police division in Berlin. The company has also engaged with cybersecurity services to monitor for any potential distribution of stolen data on known data breach sites.Data breach impact


According to the report, the stolen data, which affected around 6,300 users, includes various levels of information, from proof-of-personhood checks to complete KYC checks. This data may include names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID also contacted affected users directly to inform them of the breach.


Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident and emphasized their commitment to protecting user data. They reiterated the company’s goal of moving toward a self-custody storage system to enhance data security.


This security lapse serves as a stark reminder of the difficulties in safeguarding data. Autix10, a crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, in this instance, the attacker seemingly did not gain access to any customer data.


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Business# Security# Technology# Identity# Identification# HacksAdd reaction

News Feed

Turner Wright8 hours agoSam Bankman-Fried’s lawyers argue previous FTX legal team led him to act ‘in good faith’The filing surrounding the legal strategy followed an all-day session between SBF and his lawyers on A
Bitcoin price to ‘sustain’ $265K level once boring consolidation ends — Analysts
Nancy Lubale6 hours agoBitcoin price to ‘sustain’ $265K level once boring consolidation ends — AnalystsAnalysts forecast a Bitcoin run to $265,000, but it could take longer than investors expect.5697 Total views3 T
SV-Based Taraxa Revolutionizes Legacy Data Auditing With Mathematically Provable Audit Trails
SV-Based Taraxa Revolutionizes Legacy Data Auditing With Mathematically Provable Audit Trails PRESS RELEASE. Santa-Clara, CA – Taraxa’s newly release
Helen Partz12 hours agoSomalia bans Telegram and TikTok over misinformationSomalia has shut down crypto-friendly messaging app Telegram and gambling site 1XBet, while cryptocurrency investments aren’t banned.1413 Total
Grayscale Commences Diversified Large Cap Fund Trading
Grayscale Commences Diversified Large Cap Fund Trading In February 2018, Grayscale Investments, the sponsor of the Bitcoin Trust (OTCQX: GBTC) announced the Grayscale Digital Lar
Vitalik Buterin has an open-source solution to Elon Musk’s Microsoft OS issues
Prashant Jha46 minutes agoVitalik Buterin has an open-source solution to Elon Musk’s Microsoft OS issuesA few users on X lauded Buterin for promoting open-source software; however, a few others also pointed out that Li
Coinbase Could Be a Material ‘Beneficiary’ of Ethereum’s Merge Transition, JPMorgan Analyst Says
Coinbase Could Be a Material "Beneficiary" of Ethereum"s Merge Transition, JPMorgan Analyst Says JPMorgan analyst Kenneth Worthington says digital currency exchanges like Coinbase
Bitcoin Will Not Become Legal Tender in Uzbekistan, Central Bank Official Insists
Bitcoin Will Not Become Legal Tender in Uzbekistan, Central Bank Official Insists Cryptocurrency cannot be adopted as a means of payment in Uzbekistan, a high-ranking official from
Partner of ex-FTX exec hit with campaign finance charges
Turner Wright5 hours agoPartner of ex-FTX exec hit with campaign finance chargesMichelle Bond, who ran for a seat in the US House of Representatives in 2022, faces four charges related to violations of campaign finance l
Chainlink Whales Waking Up – Data Shows Signs Of Accumulation
Este artículo también está disponible en español. Chainlink (LINK) has seen a whirlwind of price activity, surging 50% before experiencing a sharp 15% retracement within
William Suberg14 hours ago70% of BTC dormant for a year — 5 things to know in Bitcoin this weekBitcoin faces a slow grind after earlier brisk BTC price gains, but the ingredients for a sustained rally are there, market
Decentralized Lending Protocol Adalend Listing On: ADAPad, BSCPad, ETHPad, VelasPad, PulsePad Launchpads
Decentralized Lending Protocol Adalend Listing On: ADAPad, BSCPad, ETHPad, VelasPad, PulsePad Launchpads sponsored While cryptocurrency and blockchain technology is still relatively