Hackers access some customer data at FTX, Genesis, and BlockFi by SIM swapping an employee of Kroll, which manages creditor claims for the bankrupt companies
We were recently informed that on Saturday, August 19, 2023 … Bill Toulas / BleepingComputer : Kroll data breach exposes info of FTX, BlockFi, Genesis creditors Pierluigi Paganini / Security Affairs : Crypto investor data exposed by a SIM swapping attack against a Kroll employee The Hacker News : Kroll Suffers Data Breach: Employee Falls Victim to SIM Swapping Attack Jonathan Greig / The Record : Bankrupt crypto platforms FTX and BlockFi warn customers of data breach Patrick Jennings / Inside Bitcoins : Data Breach Reported by FTX Exchange Involving Claims Agent Kroll Jonathan Randles / Bloomberg : FTX, Genesis, BlockFi Customer Data At Risk in Bankruptcy Hack Threads: Dare Obasanjo / @carnage4life : After all the legal drama around whether the names of FTX's customers should be released unredacted, the customer info ended up getting hacked from the company that handles the customer data for a bunch of bankrupt crypto firms. 🤦🏾♂️ Mastodon: BrianKrebs / @briankrebs@infosec.exchange : tl;dr: “Kroll's website says it employs “elite cyber risk leaders uniquely positioned to deliver end-to-end cyber security services worldwide. ” Apparently, these elite cyber risk leaders did not consider the increased attack surface presented by their employees using T-Mobile for wireless service.” … X: @blockfi : Regarding recent third-party data incident: [image] @ftx_official : (1/3) FTX learned that Kroll, the claims agent in the bankruptcy, experienced a cybersecurity incident that compromised non-sensitive customer data of certain claimants in the pending bankruptcy case. @bantg : client data of everyone who used blockfi and ftx has leaked from kroll. this is the exact consequence of kyc. kyc stands for amassing lucrative datasets for hackers. Bennett Tomlin / @bennetttomlin : There's a lot of bankruptcies that use Kroll, going to be a lot of data floating around @davidgerard : this is the same creditor data that FTX previously argued to the court was so not “non-sensitive” that they wanted it all sealed permanently Laurence / @functi0nzer0 : I signed up to FTX three months before it collapsed only to find out that I couldn't trade what I wanted there as a UK resident, so never used it and they still leaked my details lmao I'm gonna get back more from Kroll from a class action than I am from the liquidators Molly White / @molly0xfff : it's a little rich for FTX to describe names, addresses, and account balances as “non-sensitive customer data” after arguing at great length in court that that very same data was so sensitive it needed to be filed under seal @cryptoparadyme : What customer data is non-sensitive? @angelclarksays : and this explains why i got a bunch of emails today telling me i could pull out funds finally. so not only has ftx stolen from us, they now gave our data to scammers. @corpseinorbit : The Kroll Corporation “losing” FTX's customer database is the best evidence yet that I'm right and crypto is primarily an intelligence scheme Forums: r/CryptoCurrency : Kroll Employee SIM-Swapped for Crypto Investor Data r/ThePPShow : Looks like Kroll got hacked 🔥😬🔥
Context & Ripple Effects
The exposure adds a new vulnerability to the insolvency process around three failed crypto firms: the claims administrator became a route to creditor information. FTX’s earlier bankruptcy effort to keep client names and addresses redacted underscored how sensitive that claimant data was during its early bankruptcy hearings.
It also lands after reporting on FTX’s weak recordkeeping and control failures had already complicated the recovery process. The breach shifts attention from the exchanges’ internal failures to the security practices of the third parties handling their creditor claims.
First-order effects
- Affected FTX, Genesis, and BlockFi customers face a heightened risk of targeted phishing or impersonation using data obtained through Kroll’s compromised employee account.
- Kroll must contain the incident and preserve trust with bankruptcy estates whose claims workflows depend on it; the exchanges’ creditor communications now carry an added security burden.
Second-order effects
- Claims agents and bankruptcy advisers handling crypto-customer records will face pressure to reduce reliance on phone-number-based account recovery and strengthen access controls for staff with claimant-data access.
- Creditors may become harder to reach safely, forcing estates to distinguish legitimate case communications from scam attempts and potentially slowing claimant engagement.
Third-order effects
- If similar breaches recur, digital-asset bankruptcies could make third-party claims administration a more prominent operational and governance risk, not merely a legal back-office function.
- The episode reinforces the crypto legitimacy gap: failures at an exchange can leave customers exposed through the long recovery chain, including the service providers entrusted with their data.
The trend: Crypto insolvencies are extending customer risk beyond platform failure itself, making the security and accountability of recovery intermediaries increasingly consequential.