Fun

Fractal ID postmortem ties breach to 2022 password hack

News Feed - 2024-07-21 04:07:17

Amaka Nwaokocha1 hour agoFractal ID postmortem ties breach to 2022 password hackThis breach highlights the ongoing challenges in maintaining data security, especially in today’s centralized storage systems.505 Total views5 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksBlockchain identity platform Fractal ID has published a postmortem outlining the data breach that the company suffered on July 14. The breach has since been traced back to a 2022 incident where an employee reused a compromised password.


According to Fractal ID, the compromised account belonged to an operator with the platform for three years and had admin rights. This allowed the attacker to bypass internal data privacy systems, though system monitoring helped lock out the attacker within 29 minutes.Root cause of the breach


The operator’s failure to follow operational security policies and training, along with the reuse of credentials from past hacks, facilitated the breach.


On July 14, 2024, the crypto identity verification provider detected unusual activity in one of its back offices. This activity was quickly identified as a malicious attack, leading to data exfiltration for approximately 0.5% of its user base.Source: Fractal ID


However, Fractal ID noted in the postmortem report that it disabled all accounts in the compromised system in response and limited access to senior employees. The company also prioritized enhancing its security measures to prevent future incidents, such as implementing request throttling, finer-grained authorization, tighter monitoring of failed authentication attempts, and stricter IP control.


Related:New ‘overlay attacks’ are a growing threat to crypto users — security CEO


In addition to internal efforts, Fractal ID contacted the pertinent data protection authorities and the cybercrime police division in Berlin. The company has also engaged with cybersecurity services to monitor for any potential distribution of stolen data on known data breach sites.Data breach impact


According to the report, the stolen data, which affected around 6,300 users, includes various levels of information, from proof-of-personhood checks to complete KYC checks. This data may include names, email addresses, phone numbers, wallet addresses, physical addresses, and images of uploaded documents. Fractal ID also contacted affected users directly to inform them of the breach.


Fractal ID co-founders Julian, Julio, Lluis, and Anna expressed regret over the incident and emphasized their commitment to protecting user data. They reiterated the company’s goal of moving toward a self-custody storage system to enhance data security.


This security lapse serves as a stark reminder of the difficulties in safeguarding data. Autix10, a crypto ID provider, revealed on June 27 that their online administrative login details were exposed. However, in this instance, the attacker seemingly did not gain access to any customer data.


Magazine:Crypto-Sec: Evolve Bank suffers data breach, Turbo Toad enthusiast loses $3.6K# Blockchain# Business# Security# Technology# Identity# Identification# HacksAdd reaction

News Feed

FTX class action lawyers move to block Sullivan & Cromwell’s dismissal motion
Ana Paula Pereira7 hours agoFTX class action lawyers move to block Sullivan & Cromwell’s dismissal motionLawyers for FTX class action are challenging Sullivan & Cromwell’s dismissal request, claiming the law
US Treasury and White House to Hold Regular Meetings on CBDCs and Payment Innovations
US Treasury and White House to Hold Regular Meetings on CBDCs and Payment Innovations On March 1, 2023, Nellie Liang, undersecretary for domestic finance at the U.S. Treasury, deli
Michael Saylor to forever buy Bitcoin — ‘No reason to sell the winner’
Jesse Coghlan2 hours agoMichael Saylor to forever buy Bitcoin — ‘No reason to sell the winner’The MicroStrategy executive chair claimed Bitcoin was superior to gold and real estate and predicted that capital from t
The Mysterious FTX Debacle, Tim Draper’s BTC Price Prediction, More Support for Ripple in SEC Lawsuit — Week in Review
The Mysterious FTX Debacle, Tim Draper"s BTC Price Prediction, More Support for Ripple in SEC Lawsuit — Week in Review As theories proliferate wildly about the true nature of wha
Veteran Trader Peter Brandt Warns Bitcoin’s Price Corrections Can Be Lengthy
Veteran Trader Peter Brandt Warns Bitcoin"s Price Corrections Can Be Lengthy Veteran trader Peter Brandt has warned that bitcoin’s price corrections have taken many months i
SEC pushes back decision to open up options trading on spot Bitcoin ETFs
Jesse Coghlan3 hours agoSEC pushes back decision to open up options trading on spot Bitcoin ETFsThe SEC will again decide on whether to greenlight derivatives trading on spot Bitcoin ETFs on April 24.2615 Total views8 To
Tom Mitchelhill6 hours agoCaroline Ellison’s list of ‘Things Sam Is Freaking Out About’ could be used in trialThe prosecution intends to use Caroline Ellison"s personal memos alongside a trove of other evidence aga
Virtual coaches unite as The Voice enters the metaverse
Savannah Fortis12 hours agoVirtual coaches unite as The Voice enters the metaverseThe Voice debuts its first metaverse gamified experiences that let fans coach singers on virtual stages, win NFTs for their predictions fo
The Runes protocol will ignite a new season for Bitcoin after the halving
Lugui Tillier2 hours agoThe Runes protocol will ignite a new season for Bitcoin after the halvingThe Runes protocol will launch when Bitcoin"s halving takes place, and a wave of new tokens will ignite a new season for th
Ripple Partners With Africa-Focused Remittances and Payments Firm MSF Africa
Ripple Partners With Africa-Focused Remittances and Payments Firm MSF Africa Ripple, the United States-based tech firm, has said its crypto solution known as “on-demand liqui
Genso’s ROND Token to Be Listed on Bybit
Genso’s ROND Token to Be Listed on Bybit press release PRESS RELEASE.GensoKishi Online is excited to announce that on September 29th, 2022 10AM(UTC), their in-game token ROND will
Chinese Banking Giant CCB Expands Blockchain Platform as Volume Breaks $53 Billion
China Construction Bank, one of the largest Chinese commercial banks, has expanded its trade finance blockchain platform with new abilities, including cross-chain and inter-bank transactions, as trading volume surpasses