The Israeli encryption broker Bits of Gold disclosed that the personal information of about 200,000 clients had been unauthorized access in a third-party service provider security incident. The company stated that it was the external data analysis network that was affected and that client funds and digital assets were not reached.
Disclosure of information including bank information
According to the company, the information interviewed included names, national identification numbers, e-mails, telephone numbers, IP addresses, bank account information and public wallet addresses. This means that the event primarily affects identity and contact information, rather than a certificate of direct control over the account assets.
Bits of Gold states that passwords, private keys, CVV Codes and ID scans were not leaked and therefore the incident did not directly affect the user ' s financial security.
The invasion came from a third party service provider.
According to the Tel Aviv-based company, hackers were granted access through a network of third-party data analysis services. The company stated that, following the discovery of the anomaly, access was blocked and the system was disconnected from the information source.
The company also stated that preliminary investigations had revealed that the incident could have been a wider global attack and that other companies had been affected at the same time. Its security team has initiated a comprehensive investigation and has introduced cybersecurity incident response agencies to assist in its handling.
There have been three similar incidents in a week.
This was the third data leak disclosed by the encryption industry in the past week. Previously, SafePal had stolen nearly 40,000 user order information as a result of an invasion of a third-party supplier; and on 13 August, the hardware wallet manufacturer Trezor also stated that his compliance partner, ShipMonk, had been attacked and nearly 14 million customer information had been leaked.
Bits of Gold at the same time reminds customers that the company does not require the user to provide the password, the authentication code, the private key or the transfer of funds. The security risks of the third-party service chain have again been exposed as a result of successive incidents targeting external suppliers.
