Supply chain
⛓ Supply Chain
Celcius Third-Party Breach (April 2021)
Primary Source ↗Incident Details
Celsius Suffers Third-Party Data Breach, Customers Report Phishing Texts, Emails. The crypto lender’s data leak comes almost a year to the date after a similar data leak hit BlockFi. Crypto lending service Celsius has discovered a data breach with one of its third-party service providers has exposed the personal information of its customers, an email sent to Celsius customers and shared with CoinDesk confirms. Hackers gained access to a “third-party email distribution system” Celsius uses, according to the email. The hackers have used this information to send fraudulent emails and text messages to Celsius to trick them into revealing the private keys to their funds.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2021-04-01 Breach occurred
- 2021-04-15 Publicly disclosed