Supply chain ⛓ Supply Chain

Celcius Third-Party Breach (April 2021)

📅 2021-04-01 🏢 Not disclosed
Primary Source ↗

Incident Details

Celsius Suffers Third-Party Data Breach, Customers Report Phishing Texts, Emails. The crypto lender’s data leak comes almost a year to the date after a similar data leak hit BlockFi. Crypto lending service Celsius has discovered a data breach with one of its third-party service providers has exposed the personal information of its customers, an email sent to Celsius customers and shared with CoinDesk confirms. Hackers gained access to a “third-party email distribution system” Celsius uses, according to the email. The hackers have used this information to send fraudulent emails and text messages to Celsius to trick them into revealing the private keys to their funds.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Not disclosed
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-04-01 Breach occurred
  2. 2021-04-15 Publicly disclosed